Facebook has a hidden tool to delete your phone number, email
businessinsider.com
businessinsider.com
I wouldn't doubt if they remove your information from their "address book database" and add it to one or more others where they keep it forever. There's zero oversight, and zero accountability. It makes no sense at all to just assume that facebook will do anything they aren't forced to when not doing that thing could make them money. Facebook doesn't care about you, your privacy, or even the law. Facebook cares only about facebook.
Hashes of emails is not quite as useless, but not far off (consider 90+% of emails are at like ~3 domains, and also that lists of vaguely ~valid email addresses aren't hard to get).
(Assuming a GPU takes .001s to do a sha3 hash, which is more than double the actual benchmarks).
I would estimate that a single, high end GPU from the last or current generation could probably chew through it in under a week.
For a company operating at Facebook's scale, with their kind of scrutiny around handling PII, this is unfortunately functionally useless.
For some data types where hashing isn't super effective, and where associative identifying information is attached (such as a user id), a more effective mechanism might be to encrypt the data with a strong random value appended, and decrypt to do the lookup. This would require a correctly provisioned HSM to do properly - the private key secrets should NEVER be exported.
While hashing seems like a good idea, it's actually particularly and deceptively tricky for these kinds of use cases.
It's just not hard enough to guess a potentially valid phone number. With passwords, hashing only helps because the probability of a valid password is _very_ low, and because you don't need to look up a password, only check if it's the right one for joeblow (so you can salt them individually).
Well yes and no. What exactly is your understanding of a phone number 8)
Not everyone is blessed with the NANP. I'm a Brit and we have an eye wateringly complicated nonsense of a numbering plan and our's isn't the worst.
What do you hash? Perhaps the standardised international representation or one of them (no that is not a joke - telephony is weird). For a laugh you could try one of the many colloquialisms. For example a UK number might be 00441395112233 or 441395112233 or +44 (0)1395 112233 - the final part might be displayed as 112 233 or 112-233. Imagine if the database works by operating on all numbers in locally correct colloquial mode and hashes that!
Now let's really get silly: There are hashes that are nasty to compute but easy to check and vv. We'll use whatever is indicated.
Anyway this is all a very well researched problem, there is no need for silly games: passwords.
So at _best_ the security analysis is: "okay, all US phone numbers and a bunch from other places might as well be in cleartext", which is already broken enough that it's basically useless.
You cannot send an sms to "+44 (0)1395 112-233", so they remove the stuff in parenthesis, the dashes, spaces, etc. first, and then store.
Will the re-used number be blacklisted forever with a hash scheme?
https://tools.google.com/dlpage/gaoptout/index.html
License prohibits sharing its code so I won't - setting a good example for our artificially intelligent friends :)
Confused, are you saying they inject a unique ID or something? Do you have an example of what they insert?
/* Copyright 2010 Google Inc. All Rights Reserved. http://tools.google.com/dlpage/gaoptout/intl/en/eula_text.html */ (function () {
var a = document.createElement("script");
a.type = "text/javascript";
a.innerText =
'window["_gaUserPrefs"] = { ioo : function() { return true; } }';
document.documentElement.insertBefore(a, document.documentElement.firstChild);
})();Exactly. If you don’t want it shared, then don’t inject it in the first place.
What if the person sharing it is not a licensee. License terms would only bind licensees, assuming the purported licensee has properly assented to the license terms.
also, fair use would definitely apply in this case as it's not the entire work and is a small sample. nothing different than playing a small clip/scene from a movie in a review write up. and commentary is definitely being had around said snippet
Just Googs being dicks to everyone, essentially
http://www.businessinsider.com/facebook-uses-10000-blu-rays-...
the difference between the "address book" and the "block list" is that one can be used for marketing/targeting purpose. the other one presumably is on the other side of a chinese wall (could easily be so under FTC condition) where FB can't use it for said purpose. this would generally serve the intended purpose of "removing" your phone number.
your other contacts that felt they should upload an address book in the first place may find surprise or random inconvenience that they can't upload your number.
Deperately-needed, long overdue "regulation" will come in the form of liability for mega-sized websites like Facebook that choose to algorithmically curate and use other web users' content to generate profits.
People who develop free, open source alternatives for communicating directly over the internet should be ready for a possible mass exodus away from using so-called social media websites for communication.
The Twitter mess is only going to make it more clear to everyone, including Supreme Court justices, that "social media" is a moral hazard, not a legitimate business model.
Granted, I could be wrong. Time will tell.
Don't they know hashing at facebook?
If only there was a function that was deterministic, but somehow incredibly difficult to invert, that would sure make a hash of this requirement to store things you're required not to store.
You can imagine the headaches this causes.
I was hoping to start over with a fresh account and instead ended up having to create a new email alias in Outlook to use to create a new Apple account - luckily I used an alias the first time as well so the impact wasn't as bad.
Signal has spent some time thinking about this problem, see https://signal.org/blog/private-contact-discovery/
There is no rainbow table entry for 0123456789+=i=i_fy82dnuf720g%2+70)(k$0@*qsijyn9&19n@1r0-l4ee) with 10000 scrypt rounds.
We are not in 2005 anymore, and we have better tools than md5, or even sha1 to do the job.
However, this is facebook. It's not too expensive for them.
a salt for a password is when we know the username and the salt so can combine the salt and provided password to compare against the generated hash value.
in this case all we know is the phone number, how does a salt help us look up a given phone number in a set of salted / hashes if we dont know what salt to combine it with?
For GDPR you need to legally prove that you have taken reasonable steps to remove and keep out of your system, the data the user has requested. This means that you need to be able to legally prove you've got a system in place.
Keeping a hash is fine technically, but its a pain in the dick to defend in court, especially as its really simple to shower a jury/judge with FUD to make it look like its not a reasonable step.
In the devil’s defense, the explanation was probably written by a computer illiterate person.
Then again, there may very well have been this one meeting, where a dev went “hold on, I got an idea to avoid storing the number!”, before being politely but briskly advised to stfu. Not impossible.
[1] littera : illiteracy :: numera : innumeracy :: digita : ildigitacy? Iddigitacy?
Digital Markets Act will start going into enforcement next year.
So, if you do that, Whatsapp will stop working.
Not really.
Whatsapp should access your contacts on your local devices without sending them to servers. There is no valid reason to do it any differently. It is up to the users to make sure their contacts are in sync on all their devices.
In all seriousness: Society had an advertising industry for well over a century that didn't require jamming a porkoscope up your ass and everyone got along just fine. Just because one can invade the privacy of billions with impunity nowadays does not by any means imply that you should.
Targeted advertising exists, it is legal everywhere, and we are way past the point it could be put back in the bottle. What still can (and should) be regulated is privately identifying information management, and so far things are improving in this direction.
This is the same thing as when people install the LinkedIn app on their phone and allow it to trawl through their entire contacts list. Even if you have no relationship with LinkedIn at all and refuse to use on general principles, surprise, now they know who you are.
> We were unable to process your request. Please try again.
{
"data": {
"xfb_contact_removal_send_confirmation_code": "VERIFY_NOTIFICATION_SENT_ERROR"
},
"extensions": {
"is_final": true
}
}
I'm guessing this is not a service they planned on scaling.you don't need to. they probably got your number by scraping your friends/acquaintance's contact lists.
>Someone may have uploaded their address book to Facebook, Messenger or Instagram with your contact information in it. You can ask us to confirm whether we have your phone number or email address.
Most of the world sees this: https://imgur.com/a/gGw9nOD
EU sees this (same empty nothing under this): https://imgur.com/a/iJhdgmD
And the US sees this (at least from all AWS regions): https://imgur.com/a/2DCrNFd
I'd love to see a website that details what you can do, and step-by-step how to do it.
https://github.com/InteractiveAdvertisingBureau/USPrivacy/bl...
There's also a requirement that you have to delete data from downstream vendors that you've shared customer data with. That being said, I wouldn't trust for a minute that companies are complying with 3rd party deletions
Advertisers can upload a list of mobile phones, email address and names to Facebook to ask them not to target these people (for example, existing customers).
Is there an independent audit verifying that the phone number is gone for good from their servers?
A bit like a potential usage for HaveYouBeenPwned...
But it got deleted shortly afterward about 2 years ago due to adding a virtual landline phone number.
Read the text carefully - https://www.facebook.com/contacts/removal
Why would they, if they didn't have to?
Deleting stuff is complicated work :-)