For example should people be advised to rotate phone numbers every N amount of time?
For example should people be advised to rotate phone numbers every N amount of time?
Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you can blackhole one that gets leaked, and you can know where it got leaked from.
If you can, have a separate setup (completely separate email account(s), not just aliases, and even separate hardware to access them if you can) for very important accounts, the ones that would ~ruin your life for a good bit if they got taken over (bank, retirement, etc.)
There's also credit monitoring type stuff, which I've never been clear how useful it is, but might be worthwhile. You also may get it free if some company you use has a leak and they try to PR it away that way.
I think there's some way to basically lock your credit against new accounts, I need to look into that someday, don't know the details or if it even exists.
Note to myself: change the combination on my luggage.
If you pay for ProtonMail, you get a SimpleLogin Premium for free, which makes the creation of dummy/alias emails a lot easier. They're owned by the same company.
There still is the chance that some spammer will figure out that "blah+any-random-string" works for my email, but I'll deal with that if someone bothers someday. I'd just need to add an allow-list or something probably.
Someone can look at joe+spam@joeschmo.com and figure out Joe's "real" email address. Something like SimpleLogin (sorry, not a shill for them, I swear) gives you a completely new email/domain (and lets you set up your OWN domains), which then forwards to your proper inbox.
These are free for all-
Someone on HN will invariably point out that this is how it was for the last hundred years, and it was only when we made computers powerful enough to abuse the information that this level of privacy became a concern.
I remember the days when your name, address, and phone number were public information. I paid something like $15/month to keep it out of the phone book.
What I recently learned, browsing through old books that a local library was throwing away, is that sometimes those phone book listings would also include things like a woman's maiden name, and the name of her husband, and/or marital status. Something like:
Smith, Margaret C (nee Jones, widow of George): 202-555-1212
That part was new to me.We do like secrecy, though, and opening up the tax reports and addresses would be a 12 on the Richter scale of earthquakes. I do not know whether that would be good or bad but it would lead to all sorts of social unrest.
Eventually the bulk of the world will probably end up with some sort of government-managed crypto-ID, but it's sure going to take the US a long time to get there.
The reality is that the data is useless trash, and there is no indication that this has actually leaked from Facebook or is showing any kind of security problem in their systems.
That remains to be seen. People are fairly ingenious when it comes to abusing information and information runs the world now. I will offer an unrelated example, partially because I do not want to give ideas on how to benefit from this. Do you remember when certain entrepreneurial billionaire offered a checkmark for sale, which resulted in people impersonating companies and manipulating their stock price[1]?
Like with most things, any tool is worth what one is able to do with it.
<< The advise is to do literally nothing about it.
I would not advise to panic, but doing nothing is not exactly great advice either. Some re-assessment of one's current security posture may be warranted.
[1]https://www.fiercepharma.com/marketing/eli-lilly-hit-new-twi...
Yes, and given an attacker will not get new capabilities from this data, it is worth nothing.
Any attack that could be feasibly run with a list of nothing but phone numbers associated with some (unknown) WhatsApp account could be done without that list just as easily. That's because of two things: a) phone numbers within a given country are easy to enumerate, b) the WhatsApp account space is dense, i.e. the odds of any legit phone number being used for WhatsApp is high.
> I would not advise to panic, but doing nothing is not exactly great advice either. Some re-assessment of one's current security posture may be warranted.
If you can't formulate a realistic threat from this data, how can you possibly re-evalate your security posture in light of it? You need a threat model for that. Pondering about the security of one's digital life can of course be worthwhile in general, but advising anyone to do so in the context of this linkbait is just advising them to waste their time.
In your Twitter example, the impersonation did not come as a surprise. People were predicting that outcome within minutes of Musk announcing it. Can you make a prediction about what bad things will happen to the people whose phone number is in this dump, compared to people whose phone number isn't there?
You do have a point and it is possible I misunderstood the 'value proposition' from this data set.
From the forum referenced in the article:
"Name / Whatsapp Number - Country Wise "
What I see in that post is name field ( or potentially just a number ) and country field. If I was a person buying it, the main benefit would be "being able to reach a seemingly random ( unless it is separately checked against some other available list/s ) individual in a desired geographic location". As you correctly assessed, by itself it is not a terrible security threat.
<< Can you make a prediction about what bad things will happen to the people whose phone number is in this dump, compared to people whose phone number isn't there?
Yes ( although admittedly, mostly because "bad things" is sufficiently generic to allow for it and I already admitted I think you are right on the security aspect ).
Fraud-wise this is a perfectly sufficient set of information ( current valid numbers likely corresponding with real phone numbers ) as those tend to be number games anyway ( one out of how many answers a spam email type of deal ). In that area, the most common scam lately is grandson scam[1] or romance scam[2]( those having extra benefit of less likely being reported even if others point it out to the victim ). Seniors do seem to use Whatsapp in the old country partially due to price and reliability ( dunno how common it is in US though ) so they fit that target demographic, but that assumes fraudster can reliably identify a victim set of seniors ( or burn existing set with a more generic pitch ). For non-seniors, crypto scams seemed very common lately ( and how many people just click yes, when an invitation pops up ) although recent crash likely made it less desirable.
In other words, I think you are right about not doing anything specific security-wise, but it may be worthwhile talking with your social circle if they use Whatsapp since they may now see an increase in unsolicited calls/messages/invites and benefit from a conversation about about safety online in general.
[1]https://www.aarp.org/money/scams-fraud/info-2019/grandparent... [2]https://www.fbi.gov/how-we-can-help-you/safety-resources/sca...
There was a joke "all phone numbers leaked" list that just listed everything from 000-000-0000 to 999-999-9999. If there is no other information associated (names, pictures, emails, anything) then this leak is of almost comparable severity.
We didn't call those leaks.
Pointing out that we used to put all the phone numbers in a book published by the phone company and now we don't is historically true but practically unimportant, just as "hey, sorry to hear your house got broken into, but you know, people in IDYLLIC_RURAL_HAMLET don't even lock their front doors like you BIG_CITY folks do" isn't useful unless giving up living and working in BIG_CITY and moving to IDYLLIC_RURAL_HAMLET is actually a practical option, which most likely it isn't (and if that were to happen en masse, IDYLLIC_RURAL_HAMLET would suddenly find they'd also need to lock their front doors if their population increased by a factor or two).
Who could have predicted that technological change might lead to shifts in social attitudes? Or, indeed, that the rules, principles and institutions we collectively create to make society bearable have to adapt to said changes?