13 ms·
Look Up Unknown Phone Numbers Using Facebook Reset Password
- searchableguy 6y agoYou can also use one of spam blocking spyware apps. https://www.truecaller.com/ https://www.truecaller.com/
- zenincognito 6y agoThis is gross violation of user privacy but if you file a bug with FB they will say - "won't fix" ; is working as intended.
- wyattpeak 6y agoHave they said that? They've previously removed the ability to search for users by phone number, so they recognise the problem. I can see why someone would have unthinkingly added the profile picture to the recovery screen, but since the downside of resetting the wrong account is so low (an SMS that can be ignored by the rightful user), it seems easily fixable.
- chris_wot 6y agoA guy called Brian had his personal contact information (including phone number) plastered all over Facebook's promotional pages. https://gimletmedia.com/shows/reply-all/76hdrj https://gimletmedia.com/shows/reply-all/76hdrj I don't think Facebook ever actually apologised for doing this.
- wyxuan 6y agoFacebook profile stuff is public info anyway, I don't really see the privacy issue here.
- nrmitchi 6y agoPhone numbers that are meant for account recovery and/or two-factor security only are most definitely not public info.
- wyxuan 6y agoThis method isn't a way of finding out phone numbers from Facebook accounts, so I don't see what you mean here
- MrRiddle 6y agoPhone number meant to be private shouldn’t be associated with any other info whatsoever.
- wyxuan 6y agoWhats the rationale behind this? Outside of prank calling, I don't see what the benefit of having a private phone number. When I hit someone's voice mail I can get their name, so it's not like most people consider it to be private.
- Aerroon 6y ago>I don't see what the benefit of having a private phone number. What's the benefit of having a public phone number? You get more advertisements and spam. With a private phone number only people you've given the number to will call you. You can limit who can bother you.
- throwaway201103 6y agoI don't think this is really true, because spammers call numbers at random (or perhaps, in sequence). They are not working through the published phone book.
- throwaway201103 6y agoThen you probably shouldn't be announcing it in your caller ID when you call random people.
- awinter-py 6y agopassword reset flows are generally a privacy leak if you use email as some kind of account key, you can generally find out whether that email has signed up (if not the username) automatic password reset and email verification are good for businesses and users in a lot of ways so this is a tradeoff if FB is showing the specific account linked to an SMS that's IMO negligent but shrug, they employ more lawyers than I do and they've never been investigated by the FTC for privacy issues
- 52-6F-62 6y agoI’ve seen this obfuscated by some systems by always just throwing the user a message saying the reset email has been sent so that there’s no indication whether or not the email is associated with an account or not. Of course, that doesn’t help someone who can’t remember if they’d signed up or not but it’s probably the safer way to go in general.
- awinter-py 6y agoyup, need to do it in the signup case as well but it solves the problem
- contravariant 6y agoThere's typically a system that forbids you from adding an additional account with the same email though.
- MattGaiser 6y agoCan't you just say that a password reset email has been sent? That is what we did when I worked in banking as a way to prevent this. Whether or not you have an account, the system says a reset email has been sent.
- dasb 6y agoBut then you confuse legitimate users that don't remember what email they signed up with.
- georgiecasey 6y agoThis was great in my single days to look up random numbers you'd taken down in your phone after a night of drinking
- blue_box 6y agoThis is a GDPR violation. I hope the author already complained to the authorities. (Since there is a German phone number is used in the example, I assume that the authors is from Germany)
- deleted 6y ago[deleted]
- rendx 6y agoI don't understand why this was downvoted. It is a GDPR violation. That's a fact.
- colejohnson66 6y agoBecause it’s not. The author of the post is mistaken. Doesn’t stop people from claiming “big bad Facebook caught yet again” though. If you try to search someone’s phone number, Facebook will only indicate that there’s an account with that number with steps to recover (reset) your password. Nothing else. Go ahead. Find some random number in your contact book and search it. If there’s an account, you’ll see the email is almost completely masked out and that there’s no name given. If it didn’t work, try another number. Facebook does show you the name if you’ve previously logged into that account on that computer. Basically, there’s no GDPR violation because there’s no PII to get. A phone number by itself is not PII as it is not “personally identifiable information”; you can’t link it back to the person.
- rendx 6y agoI will not test this, as I don't want to give valid phone numbers to Facebook. If what you are saying is true, then OK. I was making my statement under the assumption that Facebook would indeed show profile picture and name, which then would be a violation of GDPR confidentiality and consent principles.
- blue_box 6y agoBut you see the profile picture.
- jsnell 6y agoBefore gathering up the mob and handing out the torches and pitchforks, you should probably establish what the facts actually are. I don't think the author of this post has really done that. The way these systems should work, and appear to work in Facebook's case, is that the amount of information revealed depends on risk analysis. For example, I just tried recovery from an IP I've used Facebook from, and from a fresh IP from a low reputation hosting provider located in a country unrelated to the account. The first case reveals the user's name, but that's pretty reasonable since the request has a decent amount of affinity for the account. The risky looking recovey does not reveal the name, Both logins show the first letter of the local part of the email address, which is basically no information leakage at all. (Though honestly, if you show just one letter even for non-risky recovery attempts, why bother? It can't possibly be of any significant help to the users.) I can't tell whether the profile picture changes based on the risk analysis outcome or not, since I don't have a test account with one. (It's still possible that this is a bad implementation; e.g. if it were to be revealing my username for any recovery attempt from the correct country, that'd be unreasonable since it's trivial to figure out the country from the phone number. But even so one should still establish what the relevant parameters are, so that we can figure out whether the behavior is reasonable.)
- dn3500 6y agoIt actually says right there on the screenshot "You can see your name and profile picture because you're using a computer network you've logged in on before." So this is only working because the author has used this computer (or one on the same subnet) to log in to his FB account before (private browsing mode does not obscure the IP address). It will not work in the general case.
- epmaybe 6y agoAre large organization subnets sufficiently masked that this would not work? For example, a university network.
- pcthrowaway 6y ago
- scotty79 6y agoTried this with my friends phone number. Facebook didn't show her picture or name. Just first letter of the email.
- dheera 6y agoI don't post my real phone number on Facebook, and I don't know why anyone would.
- thatguy0900 6y agoIf anyone with you as a contact uses Facebook then Facebook probably knows it anyway
- Buge 6y agoThey probably know it in some database, but won't let you log in with it. So this password recovery thing won't work on dheera.
- dheera 6y agoMost people I know don't have me as a phone contact either, typically just e-mail and Facebook or WeChat, but not phone. I don't use phone calls much, and I block all unscheduled calls anyway.
- shakkhar 6y agoHow about parents / siblings / spouse / significant other? Nobody has you as a contact? None of them have installed Facebook / Messenger / Instagram / Whatsapp? Do you use any app / website on your phone that uses Facebook for ads? Is there anyone else in your home who shares your IP and uses Facebook? Feel free to believe what you want, but I don't think you have the privacy you think you do.
- ChrisMarshallNY 6y agoThose will work (maybe), but their usefulness is limited, as just about every bad call I get, is spoofed. I have a canned response txt, that I send, when declining the call. I often get “message failed to send,” but I sometimes get a confused text from someone, telling me they didn’t call.
- Igelau 6y agoTFA is terribly irresponsible advice due to how many calls are spoofed. I don't need someone tracking me down and raining hellfire down on me over a spoofed number that happened to be mine.
- jokethrowaway 6y agoWhen I still had a social life, Facebook was returning the account simply by searching the phone number or email. So useful. I also loved the first release of graph search (not the dumbed down version they released shortly after) which was letting you specify very specific queries. I managed to find a girl I met on a train (whose number I stupidly didn't ask) just with her first name, university and knowing something she liked. Later on, trying to replace graph search, I had to write some hacky scripts to scrape data across a network of friends (likes, groups, friends, who interacted with you on your public profile + recursively scrape data from friends of friends) to find people.
- kumarvvr 6y agoI think the whatsapp profile doesnt work until the other party messages you or gives you a reply.
- bamboleo 6y agoIt depends on their settings. I usually can see photo and name as soon as I add them. For my own number however people can’t see either piece of information until I add the number to my contacts.
- zwog 6y agoIt depends on the user's privacy settings. You can set who can see the profile photo: everyone, your contacts or no one. But I don't know what is the default setting.
- hulahoof 6y agoA number of years ago I trialled a reverse look-up using this method (for both mobile numbers and email) as a grey hat project for a data aggregator I contracted to validate existing email / phone pairings (bad email and numbers gets you banned quickly by dispatch partners). It worked because the returned "is this you" image at the time returned a filename that was a base64 encoding of the users ID for the graph interface, which at the time pulled back a surprising amount of info if you query the key directly (obtaining the key generally required you to be a friend-of-friend or closer). I got hit rates of about 70% for a sample of ~100,000 email/mobile pairs (that were already suspected to be valid). Sounds like the trick to get the key has been resolved (I was too early in my career to feel comfortable disclosing my research) but I am surprised a similar vector exists almost a decade on - especially after the whole Cambridge Analytica fiasco.
- rsync 6y agoI have a shell script named 'lookup' that lets me know (through twilio) the location, mobile carrier, and registered name of a phone number. I wrote it to quickly identify mobile vs. non-mobile numbers that I might text - also from the command line. I won't paste the entire script here (mostly authentication and argument parsing) but the meat of it is: /usr/local/bin/curl -X GET "https://lookups.twilio.com/v1/PhoneNumbers/$number?Type=carrier&Type=caller-name" -u $accountsid:$authtoken I use this several times weekly. EDIT: by "location" I mean their mobile country code - not their actual location which, of course, you cannot get without (ab)using SS7 which is beyond the scope of twilio ...
- Merman_Mike 6y agoWhat does a few lookups a week cost you? Just a few cents per?
- janzer 6y agoAccording to https://www.twilio.com/lookup https://www.twilio.com/lookup 1.5 cents per lookup, would be 1 cent without the carrier information.
- Merman_Mike 6y agoThanks. I've wanted to do this. Didn't know if there was some account overhead or other fees.
- fy20 6y agoIn countries which have number portability this may not always be right. For example my phone number returns Vodafone, which was the carrier it was originally assigned to 15 years ago, but I've been on other networks for over a decade.
- usr1106 6y agoWhen Finland got number portability some 15 years ago it also got a free look-up service to see the real operator of every number. This was required for price transparency. Calling within your own network can be cheaper than to a competitor and you should be able to know so before making the call. Not sure how other countries have handled that. The US had the different approach, callee pays for the mobile part. Have not looked into the issue for a decade...
- eyeareque 6y agoI once tracked down a Craigslist scammer by looking up their phone number (it was a groove number) within google voice. It showed his name, google profile, and photo. Their name helped me find their Facebook and Instagram. Long story short, I got my money back. Iirc: Google used to enable allowing people to look you up by your phone number (it was something along the lines of: help your friends find your account). This used to be on by default, it doesn’t seem to be anymore. Try looking up your friend’s google voice numbers in google voice and see if they have the option enabled.
- eyeareque 6y agogroove == gvoice
- deleted 6y ago[deleted]
- actuator 6y agoThis doesn't seem like something which is of concern but on a tangential note, I wanted to check how you guys maintain your phone number privacy. Consider the cases: - I absolutely hate giving phone number to new ecommerce sites as it is just a database that will eventually get leaked. The only one I can trust here is Amazon probably. - Phone number on packages. A person can read your name, address and phone number from a package which seems like a lot of info. Address is required but phone number shouldn't be as you can very well redirect the call using custom pins. - Talking to new people on dating apps. I don't use IG, so phone number is something I have to exchange. Now I would never give my number to an anon on internet but on dating apps I have to for my own benefit. Do you guys maintain burner phone numbers for these cases?
- vmception 6y agoI maintain dual sims in my iphone. For dates this means that my "burner number" also has blue text messages, revealing to them it is an iphone and that other features are available like facetime and airdrop in the future. I also maintain google voice numbers to set up additional accounts on places and more easily filter spam. Right now, my one device has three numbers on it. (2x sim, 1x google voice).
- actuator 6y agoI need to upgrade my Pixel 2 to a dual sim phone too. I think this seems like the easiest way. Not sure how WhatsApp etc support dual sim though.
- vmception 6y agoWhatsApp is the only one that makes it inconvenient. Perhaps Signal is one identity too, and therefore less convenient. But you can always at the very least set up the accounts, using your browser on a PC. You just won't get chat notifications for multiple numbers on one device. Telegram app lets you have 3 accounts logged in, the only similarity being that setting up a Telegram account requires phone number authentication. But the similarity ends because a Telegram account on your device doesn't need to be linked with a phone number accessible from your device.
- kristopolous 6y agoY'all know we used to publish everybody's phone number in a book along with their address and then distribute copies to every household, right? We did it for many decades and it was fine. Every pay phone, which was a phone anyone with a couple coins could make anonymous calls from, had this giant book right there for your reference. Everyone knows this, right? If you didn't know someone's number you could look it up and call them. They wouldn't have caller ID so you'd identify yourself and then you could talk to them. This was 99.99% of the time not a problem. We need to stop freaking out about a "security vulnerability" that does 1/50th of a system that everyone used mostly without incident for decades. Besides, none of this information is actually private now, it's all still for sale. These companies freak out about this stuff because your data is their product, it's not supposed to be free.
- aembleton 6y agoCould I easily look up a name for a given phone number with this book? Or did I have to go through the whole book to find a match?
- kristopolous 6y agoOf course. It was called the greypages. https://en.wikipedia.org/wiki/Reverse_telephone_directory https://en.wikipedia.org/wiki/Reverse_telephone_directory In old movies you sometimes see people ask the operator to do a reverse search as well so I assume it wasn't a big deal.
- Rygian 6y agoI get it that the right to privacy has not been such a priority in the past, especially outside Europe, but there's nothing wrong in trying to strengthen it. What was maybe fine a couple decades ago is no longer fine in a world where anyone from any jurisdiction in the world can abuse your privacy for fun and profit.
- kristopolous 6y ago30 years ago things were far more ripe for fraud and abuse. Things couldn't be verified in the slightest. In the 1800s a famous fraudster invented an entirely fictitious country and then sold fraudulent land grants and bonds for it - really, https://en.wikipedia.org/wiki/Gregor_MacGregor https://en.wikipedia.org/wiki/Gregor_MacGregor There's a reason why the most famous confidence tricks have names that go back hundreds of years (eg, spanish prisoner) and there's fun named people like Soapy Smith that mastered things like mock auctions https://en.wikipedia.org/wiki/Soapy_Smith https://en.wikipedia.org/wiki/Soapy_Smith or "Kid Dropper" named after his love of the "drop swindle" scam: https://en.wikipedia.org/wiki/Nathan_Kaplan https://en.wikipedia.org/wiki/Nathan_Kaplan Charles Ponzi did his stuff 100 years ago and he just lifted it from earlier con artists like Adele Spitzeder https://en.wikipedia.org/wiki/Adele_Spitzeder https://en.wikipedia.org/wiki/Adele_Spitzeder The idea that we need to "lockdown" things because we live in unprecedented times relies on someone not really reading any history. Things are relatively pretty safe these days.
- scottmcdot 6y agoSometimes people will change their Facebook name to be more anonymous however their Facebook url stil has their full name on it.
- TeMPOraL 6y agoIt's funny to see, but I guess it works against non-tech-savvy people. Not sure if that's still the case, but Facebook used to leak one's maiden name via URL for people who changed their surname after getting married.
- teekert 6y agoI do this all the time: Don't recognize number, add to contacts, check Whatsapp picture. Doing this I found out an old aunt I hadn't talked to in a long time was pocket calling me recently :)
- silver_quiver 6y agoI once caught a thief who stole my Nokia MS Windows phone using this feature. Apparently they didn't reset the phone in the start, but put their sim in, and some of their SMS started syncing to my other phone before it occurred to them to reset. One of the message was a Facebook password reset helper message, which had the clear phone number and link to a page which had instructions on how to reset the password. Clicking on that link, also set a cookie IIRC on my laptop, Facebook started showing their DP as one of the options to login (it would still ask for their password so I was not able to log in to their account). Their DP URL has their user ID embedded in it which was enough to find their profile. Turns out they were friend with another person who was in my college (and where my phone was stolen from). We caught that person, involved the university administration, and made him give us the phone back. It was the whole scandal for a while. University expelled that person later on. (Going to police was not really an option since this was in India, I wanted to resolve matter on my own if possible even when I had phone number).
- Jon_Lowtek 6y agoSo called "Identity Graph" or "Identity Resolution" providers integrate with thousands of CRM systems and harvest the customer data in bulk, then sell the combined profiles back to the companies integrating them. Get an API access, provide one piece, like a phone number, and they resolve it to names, home addresses, email addresses, social media usernames and so on. I mean i don't like facebook, but this topic is small fish
- tomp 6y agoOr you could just do a search on Facebook?! I don't know if it still works, but some time ago I used that to find the real name of someone just using their phone number. However, that person wasn't really trying to keep their identity secret.
- Magicstatic 6y agoIs this a security problem? Depends on who you ask - but I'm willing to bet it would fall into the "accepted risk" category for the Facebook security team if they had to evaluate this. The reality is that phone number lookup services are available all over the web which provide even more information (first+last name, address, zip code, social media profile links, etc etc etc) for free (https://www.bestfreephonelookup.com/phone-number/ https://www.bestfreephonelookup.com/phone-number/ as an example) - these services get their info from data aggregators and usually - your carrier! I don't see how Facebook exposing (in _limited_, very specific circumstances) the first name of a persons phone number being a security issue. All the people in this thread screaming GDPR violation don't understand that if someone decides to stop using Facebook and delete their account, this method to lookup someone will not work. Sidenote: If you're really paranoid about having your phone number expose your real name when you're using any type of service online, just sign up for a Google Voice (voice.google.com) account and link it to your cell phone - I use this whenever I sign up for anything online and it saves me a ton of spam and scam calls. EDIT: Facebook removed the ability to use the in-app search box in Facebook to find people based on just a phone number, this has been removed for at least 2 years.
- jomaorfe 6y agoNobody ever got fired for buying IBM.
- bitlevel 6y agoOr just use this? https://www.unknownphone.com/ https://www.unknownphone.com/ In the UK...