For us it was really really good that he rejected the offer! Because otherwise we would see the trade market crash $3bn, guess who would have to pay loss.. we..
well, if he saw that coming, which I doubt, he would be a hero.
I don't know about that. Their dismissal was (at least framed as) "well that's a lot of data, so it's not going to happen!"
Actual excerpt from their blog, on the 27th: "Theoretically, if someone were able to upload a huge set of phone numbers, like every number in an area code, or every possible number in the U.S., they could create a database of the results and match usernames to phone numbers that way."
This is kind of a joke.
Did they really claim phone numbers are hashed? If so, why has nobody else touched on this subject?
No idea on the downvotes. I guess because, like I said, telling users you hash the phone numbers doesn't matter if you're using them to search for an unhashed userid. But they're implying to users that their phone numbers are secure because they're hashed, when it really doesn't matter.