Researcher says he can link Facebook accounts to 5M email addresses per day
arstechnica.com
arstechnica.com
They have such a dense branching network of advertisers and auxiliary services which have easy access to this kind of identifying data that I can't see how Facebook can conduct their same kind of grey area dealings without leaking this stuff all over the place.
Discussion: https://news.ycombinator.com/item?id=26879315
Facebook are incompetent to protect the data they've collected, so they want you accept criminal misuse of it.
If these two are not related it's an amazing coincidence.
What are current best practices for large B2C apps like FB, regarding storage of prior values that are replaced by the user? Specifically in relation to key account information (email / phone / 2FA ). Are prior entries effectively wiped... or stored ?
And was such practice always in place, or when did it change?
FB is an advertising firm, and the identifiability of their audience is a major value driver of their ad inventory[1]. They explicitly leverage the PII stored on their consumer users to enable advertising offerings such as Custom Audiences[2][3][4] and Advanced Matching[5][6].
Best practice for any B2C app like FB would be to retain those prior values indefinitely, since prior values still provide valid utility for their advertising services as additional data points for matching.
That likely differs from best practices for large B2C apps that aren't like Facebook and don't have similar incentives for indefinite data retention.
[1] https://www.adexchanger.com/mobile/facebook-could-take-a-mul...
[2] https://www.facebook.com/business/help/341425252616329
[3] https://www.facebook.com/business/help/2082575038703844
[4] https://www.facebook.com/business/help/2082575038703844
The only prepaid SIM cards you can get without the full procedure are data only
Increasing amount of services do either/or of country restriction and detecting and blacklisting virtual numbers.
You could use a fake phone number service, but ultimately somebody else could just use this to login to your account. You also can't guarantee you are able to use that phone number again when you need to get back in.
The only real option is to not use the service at all, which is easier said than done when your family, friends and even employers use (and require you to use) the service.
I should not be required to have a mobile phone and even if they do they shouldn't need my phone number.
Pick a different 2FA method.
Define "services". In the last decade I have signed up for exactly 1 service that required a phone number (Telegram), and somewhere in the region of 8,000 that didn't.
All major IM platforms (WhatsApp, Signal, LINE)
Any dating app I ever tried to use
It almost seems like those online services should be nationalized, or at least be very thoroughly regulated when they have more than 100k users.
I mean what is the difference between a surveillance network and facebook? None. Which is why it should be regulated or controlled by a state body that can be accountable to voters.
In a way, it can easily be argued that facebook is a "front" so that the government can spy on people. As long as libertarians argue that it should not be part of the government...