4 ms·
There's a good discussion on this by Troy Hunt[1]. > But for spam based on using phone number alone, it's gold. Not just SMS, there are heaps of services that
by ben509 6y ago
There's a good discussion on this by Troy Hunt[1].
> But for spam based on using phone number alone, it's gold. Not just SMS, there are heaps of services that just require a phone number these days and now there's hundreds of millions of them conveniently categorised by country with nice mail merge fields like name and gender.[2]
> Another general observation on this incident: I'm seeing extensive sharing of the data, both the entire corpus of countries and individual country files. Not just in hacking circles, but very broadly on social media too. This data is everywhere already.[3]
> New breach: Facebook had 2.5M addresses exposed in an incident that impacted 533M subscribers' phone numbers. Most records contained name and gender, many also included DoB, location, relationship status and employer. 65% were already in @haveibeenpwned[4]
> If we look at the data, email is rare, DoB is rare so the greatest impact here is the phone numbers. Even though it’s “only” 20% of FB users, the number is obviously substantial thus so is the impact[5]
[1]: https://twitter.com/troyhunt https://twitter.com/troyhunt
[2]: https://twitter.com/troyhunt/status/1378485999781613569 https://twitter.com/troyhunt/status/1378485999781613569
[3]: https://twitter.com/troyhunt/status/1378513457209696256 https://twitter.com/troyhunt/status/1378513457209696256
[4]: https://twitter.com/haveibeenpwned/status/1378554902100635659 https://twitter.com/haveibeenpwned/status/137855490210063565...
[5]: https://twitter.com/troyhunt/status/1378474534760685568 https://twitter.com/troyhunt/status/1378474534760685568
- adkadskhj 6y agoAnyone know if Haveibeenpwned will have this type of info? I'm super curious to search my name, warn people i know, etc - but i'm not sure i want to search for and/or download the data. What's a good way to know if myself or my loved ones are in it?
- sbuk 6y agohttps://twitter.com/troyhunt/status/1378463581604220931 https://twitter.com/troyhunt/status/1378463581604220931 "I’ve had a heap of queries about this. I’m looking into it and yes, if it’s legit and suitable for @haveibeenpwned it’ll be searchable there shortly." I'm sure it will be.
- ginko 6y agoSeems he'll only add the records with email addresses and not phone numbers: > And no, I have no intention of adding phone number search in the foreseeable future. There's a User Voice suggestion for that and a comment from me which boils down to "much higher work and much lower value"
- dktalks 6y agoNot sure how this is too much work unless everything is tightly coupled with relating an email address to everything in their database and not a keyword to search for.
- Waterluvian 6y agoImpossible to have an informed opinion while lacking all information about how the back end is designed and what the author does with their time.
- dave5104 6y agoSeems the difficult work is normalizing all of the data and making it easily searchable for all: > I also can’t parse the, out with a regex like I can an email address as they don’t adhere to a consistent format. Further, the inconsistencies in format make searching difficult as they’d have to be “normalised” and that’s something that’s very country (and even region) specific. https://haveibeenpwned.uservoice.com/forums/275398-general/suggestions/10395684-search-by-phone-number https://haveibeenpwned.uservoice.com/forums/275398-general/s...
- davidjohnstone 6y agoI created https://www.thenewseachday.com/facebook-phone-numbers-us https://www.thenewseachday.com/facebook-phone-numbers-us and https://www.thenewseachday.com/facebook-phone-numbers-australia https://www.thenewseachday.com/facebook-phone-numbers-austra... to check if phone numbers are in the data. So far I've only made them for US and Australian numbers.
- Osiris 6y agoThank you very much for this. Confirmed my number wasn't leaked. I appreciate the peace of mind.
- adkadskhj 6y agoOr this is a honeypot for phone numbers .. hmm
- Lhd 6y agothat's a very nice tool... would it be possible to provide details how you did this tool? (i'd like to implement the same to my country)
- usr1106 6y ago> Another general observation on this incident: I'm seeing extensive sharing of the data, both the entire corpus of countries and individual country files. Not just in hacking circles, but very broadly on social media too. I made a Google search 8 hours ago. There were 10 pages hits of link spammers where you have won an Iphone, but they don't have the data. So, yes public interest seems big. I wonder why Google cannot catch those, after opening the first one I could recognize the rest from the address and the snippet. Google did not have a correct link that still had the data. Maybe they are not publishing those, getting bad reputation to big data is not exactly in their interest.
- th3h4mm3r 6y agoMaybe in the dark net? Anyone check this?
- CGamesPlay 6y agohttps://news.ycombinator.com/item?id=26682774 https://news.ycombinator.com/item?id=26682774
- perl4ever 6y ago>65% were already in @haveibeenpwned So is this breach related to reusing or having a weak password? Or is it completely independent?
- ben509 6y agoFrom my read of it, it's completely independent. The same passwords frequently show up in other breaches.