3 ms·
I think it's important to put this into context. They're stating that a malicious user could crawl public info of other users, thereby building (over time) a be
by nbadg 6y ago
I think it's important to put this into context. They're stating that a malicious user could crawl public info of other users, thereby building (over time) a behavioral model of those users. The theory that you could protect users from that by hashing phone numbers and using the hash for contact discovery, turns out not to be accurate, because there are few enough phone numbers in existence that you can just brute force the hash.
I do think it's important for people using these kinds of services (and I'm one of them!) to understand their limitations, but I also kinda find this a bit self-evident, if you think about how contact discovery works. There's simply no way around it (unless you stop using phone numbers to exchange contacts). So in the sense that studies like these help educate non-technical users of the technical limitations of services, this is great!
However, to say they "threaten privacy"... That feels like a gross mischaracterization of what's going on here. Every social technology site, app, etc, has this problem, and it's something that could be, to an extent, mitigated for (detection of scanning attempts, rate limiting, etc). Meanwhile, these are the apps that are bringing E2EE to the masses. It feels like missing the forest for the trees.
- thimkerbell 6y agoWhat companies are offering to do behavioral modeling as a service?