From email to phone number, a new OSINT approach (2019)
martinvigo.com
martinvigo.com
-not a lawyer, just work with too many of them
CNAM is the database that carriers use to give you alphanumeric caller ID ("SMITH JOHN" instead of "+1 (555) 123-4567"). Many carriers don't display this data as far as I believe, but most of them make it available.
Querying that database isn't free, but you could probably find a way to do it for a few hundred numbers relatively cheaply. People's names and emails are often similar, so you could probably figure out an algorithm to give you the most likely candidates.
The data is often wrong in interesting ways (I've seen everything from deadnames to people's exes they still share a plan with), but it is still pretty useful.
[1] https://www.t-mobile.com/support/tutorials/device/app/ios/to...
The point of that database is to display a recognizable name to the people you call, so that they know it's you. A recognizable name isn't always the one on your birth certificate (particularly in the US). There are also businesses, who want their business name there.
Also, many postpaid plans (like my home ISP) require SSN because they are providing you service on credit. Postpaid cell paone plans have been the "default" in the US for a long time, though prepaid seems to be gaining market share.
They require a SSN because people don't care and it makes it cheaper to offer the accounts, not because it would actually be a big problem to sell internet service without credit checks.
Now, as for why they still do the same credit checks when you bring your own phone, I suspect "Because F you, that's why" is the gist of it.
As Brit-expat+US-resident (since 2012) T-Mobile got my SSN when I signed-up for my pre-paid first mobile phone plan in 2012. Paying $50/mo was quite a shock when equivalent (or rather: far superior) service was available in the UK on a PAYG (not even pre-paid!) basis for £10/mo.
...and now I'm on a $110/mo postpaid plan because eventually you get tired of the limitations and just grin-and-bear-it.
/usr/local/bin/curl -s -X GET "https://lookups.twilio.com/v1/PhoneNumbers/$number?Type=carrier&Type=caller-name" -u $accountsid:$authtoken | /usr/local/bin/jq '.'
I don't even know what it costs ... maybe a penny per lookup ? I forget ...It also shows carrier and whether it is a mobile or landline, etc.
$0.01/lookup: https://www.twilio.com/en-us/trusted-activation/pricing/look...
But one of the really positive things about having so much "public PII" (SSNs, Addresses, phone numbers, birth days) is that people don't have to treat this information as some sort of secret. Everyone needs proper ID and eID because knowing someones digits doesn't make it any easier to impersonate them.
If someone wants my phone number, they take my email which has first- and last name, go to any of the N search sites and they find 100 people sharing my first and last name. If they know a city and approximate age (Which they can easily get from a social platform) they can narrow it down to just a couple of people. Public records then shows my birthdays, my cars, my income, who's also registered on the address, and so on. It's not difficult doing OSINT in Sweden...
> Paypal, which displays five digits including area code to anyone knowing the email address (but only three if the attacker knows the target’s password), decided this is working as designed and will not take action.
Wild.
Does anyone know how scammers are getting numbers off of LinkedIn? Or correlating them to numbers from elsewhere? I know a company whose employees are constantly getting fake CEO texts.
I once called PayPal to report an "your account is suspended" phishing email and they angrily told me to follow the directions in the email.
I can’t for the life of me figure out why, or why they would do that without notifying me. At least no good reason. It’s the strangest thing.
I haven’t even fixed it. I just stopped using PayPal because I don’t trust them any more.
It gets worse: there's a lot of web-apps out there (both SSRs and SPAs) with <form> elements for personal details which are in the DOM, but "hidden" by doing tricks like `position: absolute; left: -99999px` inside a div with `overflow: hidden` (instead of doing something like `display: none;`) - or have the form hidden by using a z-index behind some curtain/cover element - and I've seen browsers auto-fill those fields and they get POSTed and cause a data overwrite on the server without the user being aware.
It's a fun way to steal PII from people: have a random public webpage that contains a registration form with all kinds of personal details, but has HTML+CSS such that it's visually obscured from the user, but the browser thinks it's a fully visible form, and simply yet the browser autofill it and submit it using JS (getting around the "user must interact with the page" filter by binding it to a big pink button that says "click here to see dancing bunnies!").
Browser auto-fill is dangerous.
Its strange that Paypal would even consider our accounts associated in any way. I wonder if she put a support ticket in to change her name and they changed mine too because we shared the same surname? Does paypal know we're related somehow, or did they just change another random account with our surname when they changed her name, and happened to get her brother? The more I think about it the more questions I have.
They probably have their phone number visible on their profile or they have an email and the scammer found the number on another platform (like facebook)
For the second SIM option, that requires a dual-SIM device, which are still fairly niche in the US.
When it comes to VOIP numbers, unfortunately, many sites look up phone numbers and block VOIP providers, which sucks because Android still has no good way of sending/receiving carrier texts on the desktop (and before someone suggests the Google Messages web interface, it "forgets" my device too often for me to take it seriously). Occasionally, this can create a catch 22, where the VOIP blocking is implemented after the fact and prevents you from ever using the account again because the VOIP blocking was also implemented on the SMS 2FA.
And then there's services which don't even bother to check if they can actually reach a number before accepting it. Harris Teeter pharmacies, for example, will happily accept a VOIP number, but their system is unable to call or text VOIP numbers, so you never get your prescription notices. (And I'd bet this applies to all Kroger brands since they share a lot of systems.)
Or a device that supports an eSIM, which is every iPhone since 2018, for starters.
But regardless: using your existing 5 year old iPhone with an eSIM that isn't "cheap" is still going to be cheaper than buying a new dual-sim phone.
My girlfriend could keep her home phone line enabled while using the eSIM but I couldn’t, even though we have the same model of phone! Turns out her home line uses a physical sim, but mine is set up using an eSIM and the iPhone 12 can only have 1 eSIM enabled at a time. You can do 1 physical + 1 eSIM, but not 2 esims.
I couldn’t get texts or calls from home without noodling with my phone settings each time. And FaceTime kept enrolling and unenrolling my number.
(I used the Airalo app. No association. It worked great.)
IIRC this is a limitation that only applies to iPhone <=12.
I am pretty sure that newer iPhone models all support dual-active eSIM, irrespective of whether or not you have a physical SIM slot model or not.
I would love to turn off my US eSIM when not in use (I think it uses more power connected to two cellular networks) but that would require unenrolling my US iMessage number and I can’t do that. Definitely the most annoying part of the whole thing.
I considered using a spare iPhone to host a physical SIM with my US number because that would allow the number to stay bonded with my Apple ID and potentially forward SMS over iCloud, but I decided not to because in my experience the SMS part is too flaky to be relied on.
It nags you but you don't have to agree to remove the number. I routinely replace my SIM card when traveling outside the EU and my iMessage number still works for green-bubble people. I ignore/refuse the phone's occasional suggestions to "update" the number.
Personally I prefer to use a non-obvious dedicated email per account e.g. ebpnw@mydomain.com, so the attacker has to guess the email as well.
Should I stop doing my obvious, ie hackernews@mydomain.com, account emails?
If you are using a password manager, then this shouldn't be too difficult.
It can be a hassle when registering for something in person, though.
Also possible to create 2-3 fake Personas in app (Name, DOB, address,…) to scatter your online footprint. Fills forms with the right one at button push.
And for dual SIM phones:
> An iPhone XS, iPhone XS Max, iPhone XR,
Source: https://support.apple.com/en-us/HT209044
That's 6 generations of iPhone that have dual SIM, in which there is at least 1 eSIM.
(Total guess but how cool would it be if I was right?)
https://www.quora.com/What-are-the-odds-that-your-birthday-i...
http://web.archive.org/web/20070203124309rn_1/www.cpsr.org/p...
And their mothers, assuming they were between 13 and 50 when they gave birth, would therefore have been born between 1850 and 2010.
So that's 161 out of 9999 available last-4's (0000 is not used) that could possibly be someone's mother's birth year.
And then, of course, it has to be the right year within that space.
I am guessing this was something that happened to a few folks by chance and then was blown up by people who don't understand how many coincidences can occur across a population of millions.
We have all the worst parts of a proper national ID system—tracking and data gathering by government and other large organizations isn’t hindered a bit, and we’re required to engage with our ad-hoc national ID system all the time for anything important—but none of the benefits.
Tons of suffering and wasted time, for no damn reason.
What's nice is that I completely control the mapping of ids, so if I can make multiple random addresses go to a "one-time" inbox that automatically sends emails to spam after a while.
Obviously, it's not like anything can or should be done to change this, as it's mostly just human nature, and keeping the security industry capable of operating legally and in the open is paramount. But sometimes people just wanna brag. And they get big mad about it and sputter about how literally any possible end justifies literally any actual means if you point it out (see: the other person responding to the top level comment lol)
Meanwhile, I can almost certainly say that the number of ways to bury your head in the sand instead of simply facing an uncomfortable problem massively outweighs the good reasons for doing so anyway.
A person who is in need of money and lacking in empathy will not fail to use any technique available and it is thus good to know the defenses of that or at least be aware of it.
"Creepy" arguments (appeals to shame or disgust) are fallacies.
Security researcher types are well aware of the good-actor motivations behind white-hat-hackerdom. Is it wrong that I can buy a book on lockpicking? Would I be seen by some as a bad parent if I taught it to my kid when he expressed curiosity about it?
I mean creepy as in a violation of a right to privacy. I don't consent to you knowing my phone number or any PII I put into private websites.
It's a lot easier to get caught lockpicking and it has some legitimate uses. This is like more like an autopicking machine imo.
A GREAT example of this was when Firesheep forced Facebook (and countless other sites) into embracing https. Firesheep was a firefox plugin that anyone could run on a public wifi (e.g. coffee shop) and instantly start getting the passwords of anyone on the same network that logged in to anything over http. At the time Facebook was http by default. So, it made the news and forced Facebook to make https required basically overnight. Many other companies followed suit, and it's likely fair to say that the release of that plugin single-handedly accelerated https adoption by a considerable margin.
I don't know that this release will be that impactful, but its certainly better than having this be a technique that only black hats know about.
It was released in 2019 and it is still going on, so unfortunately it wasn't.
From my perspective, I'm happy that Martin Vigo released this information (in 2019) as it helped me inform my employers (and now my clients) to additional threat model vectors to consider before deciding how to best perform password resets.
Also in his defense: 1) He originally released a rather crippled form of the PoC 2) It requires a Twilio account, which raises the barrier to entry and provides a data point for analysts were the tool to be used criminally.
That method leads to the worst evils in the world. Many have concluded, or used it to justify everything from, 'it's ok to take these poor people's land and give it to megacorp, because we'll get a factory' to 'it's ok to silence these journalists because it's for the public good' to 'it's ok to kill my enemies because I think they are bad' to 'it's ok to commit genocide against this group because the world will be better off without them'.
Who am I, or who are you, to decide what is good or bad, or how good or bad, or to weigh those things for others? Beyond our obvious cognitive limitations (as humans, we are too flawed cognitively and morally to make judgments for others) and lack of legitimacy (who elected us?), there is our obvious bias - 'good' is what is good from our perspective, based on our biases, subject to our ignorance of others.
That's why human rights exist: It's their right and you can't make that decision for them; it's up to the person involved. If you think their land, etc. is so important, then ask them - it's up to them whether they want to do it. They have property rights, speech rights, etc. and nobody can abridge them, and in the limited circumstances where they can be abridged, there is a whole infrastructure of legitimacy (democracy), protection from corruption (separation of powers, juries, etc.), process (law, due process).
>>> One way of assessing these decisions is answering the question "Is more harm done than good by releasing information this to the public?"
It's interesting to see that this being posted here on Hacker News is presumably enough to push the GitHub repo to the trending page for Python.
Email to Phone Number Osint Tool - https://news.ycombinator.com/item?id=30476792 - Feb 2022 (2 comments)
Paypal here again
I think the site is struggling with traffic and I'm getting 503'd...
Thx!
So what he then did was essentially merge/correlate that data along with the area code and "exchange" (the part of number after area code) from sources like https://www.nationalnanpa.com/
Then he has a python script the queries (not sure how I didn't read the code, I'm assuming NOT through an API but who knows) the aforementioned services and somehow determines the likelihood of a number out of several hundreds being registered to an email or not. I kind of dozed off at the end so I can't explain that part very well.
edit: Why am I getting downvoted? This is literally what the blog is. My other comment is at the top.. lol. What a waste of my time giving an explanation. Ya'll like that low detail TechBrunch ChatGPT explanation more? Wild.
Next: Signal app, method