13 ms·
A database with 3.8B phone numbers from Clubhouse is up for sale
- mam3 5y agoBilions ?? On clubhouse ?
- chovybizzass 5y agoIt includes every users' contact list from their phone. So likely damn near everyone on the planet with a cell phone.
- coldcode 5y agoAre people really that stupid to give some mobile app company access to their contact list? On iPhone you have to explicitly give permission, I presume on Android as well. I find that hard to believe everyone is doing it.
- FabianBeiner 5y agoThat was what made Clubhouse so famous: "After registering, the clubhouse app asks for access to your address book. This must be granted if you want to invite friends."
- jbverschoor 5y agoI have no idea how that went through the Apple checks
- codetrotter 5y agoIt must be granted to invite friends but you can deny it access and still use Clubhouse, just that until you grant access you can’t invite others.
- codetrotter 5y agoActually now that I look into it again, it looks like since the middle of March of this year it's even possible to invite others without sharing your phonebook. https://www.blogher.com/social-media/clubhouse-invite-without-sharing-contacts-17723/ https://www.blogher.com/social-media/clubhouse-invite-withou... https://www.gizchina.com/2021/03/16/clubhouse-new-update-users-can-now-invite-friends-without-opening-their-contacts/ https://www.gizchina.com/2021/03/16/clubhouse-new-update-use...
- CapitalistCartr 5y agoEveryone doesn't have to. If one person with your number gives up their contact list, they have yours. I'd guess about 10-12% of the populace would have to cooperate.
- hdjjhhvvhga 5y agoMany apps will refuse to work if you don't allow access to your contacts, so people just give in and allow it. Google is the biggest abuser in this area just grabbing all your contacts and linking them to your Google account once you add any Google account (like Gmail or Youtube) to your Android device.
- user-the-name 5y agoI do not think you are allowed on the Apple App Store if you do that.
- capableweb 5y agoMaybe not for smaller apps but apps with large user bases are under different rules than the rest.
- deleted 5y ago[deleted]
- user-the-name 5y agoI work for a fairly large app and that certainly is not the case for us.
- alisonkisk 5y agoWhat are you talking about?
- flemhans 5y agoIt's extremely annoying to add a number to Telegram without adding it as a contact first, and allowing Telegram access to the contact list.
- noxer 5y agoWhats the point of that? You dont need to exchange phone numbers for telegram just the @username and only one side needs to know the others username. And once you have a chat with someone both can share their own contact directly in the chat with 2 clicks and add it with 2 clicks as well. (which is still rather useless because there is no real benefit from adding someone as contact. But I guess if you want to store number then this is easy)
- sneak 5y agoYes.
- alpaca128 5y agoAfaik WhatsApp (on Android at least) requires you giving access to your contacts. So roughly speaking a huge chunk, probably the majority, of smartphone users shared their contact list to at least one company, which strictly speaking might not even be legal in many cases. After all that's how WhatsApp populates its contact list, it looks which users have each other's phone numbers. That way it doesn't need a user login and friend/contact requests, but in return you give up your privacy.
- wngr 5y agoNot true. It'll work without, it's just very inconvenient.
- deleted 5y ago[deleted]
- patja 5y agoBased on the popularity of WhatsApp, yes most people don't give it a second thought.
- Bjartr 5y agoYes, constantly.
- nemothekid 5y ago>Are people really that stupid to give some mobile app company access to their contact list? Almost every social media startup in the last 15 years was bootstrapped this way.
- ipaddr 5y agoI keep no contacts on my phone and gladly give that info away. I'm surprised people don't use multiple phones for privacy.
- eclipxe 5y agoMost people don’t care about privacy.
- FabianBeiner 5y agoAccording to the screenshot: All members plus every single number in each of their phone books.
- oliv__ 5y agoEven if they had 10M users (which I doubt), at 100 contacts per user that's 1B contacts.
- mcintyre1994 5y agoClubhouse does the classic “share your contacts with us to find your friends here” thing, but it sounds like they just upload your entire list into their database instead of doing anything remotely privacy aware. I’m mostly curious how much else they uploaded with the numbers - is this name + number + email etc? And if this dump is just numbers, do Clubhouse have the rest somewhere else?
- justinclift 5y agoYeah, not sure either. Suspecting it's some other Clubhouse, not the main (project planning) one (https://clubhouse.io https://clubhouse.io).
- SahAssar 5y agoIt's the audio chat one: https://www.joinclubhouse.com/ https://www.joinclubhouse.com/
- justinclift 5y agoThanks, that makes more sense. :)
- BatteryMountain 5y agoThey forgot to "select distinct"?
- ttam 5y agohttps://twitter.com/UnderTheBreach/status/1418889649708208137 https://twitter.com/UnderTheBreach/status/141888964970820813... this tweet says it's BS (they validated the japan sample)
- FabianBeiner 5y agohttps://zerforschung.org/posts/clubhouse-telefonnummern-en/ https://zerforschung.org/posts/clubhouse-telefonnummern-en/
- PragmaticPulp 5y agoAccording to the Tweet, the leaker provides a claimed data sample that is a list of phone numbers without any additional information. A list of 3.8 billion phone numbers that simply exist is useless. The leak would only have value if the numbers were associated with some identifying information. If it’s really only phone numbers, I wonder if it’s a leak or if someone brute-forced all possible phone numbers against a ClubHouse API that leaked information about whether or not the number existed in their database.
- sebmellen 5y agoIf Clubhouse can’t detect >3.8B erroneous requests and shut down that API/microservice, that destroys my confidence more than a data breach.
- mohanmcgeek 5y agoClubhouse didn't have 3.8B users.. why would they have 3.8B phone numbers? This whole thing seems made up.
- mcintyre1994 5y agoBecause they encourage users to upload their contacts so they can connect them on the platform. At one point when it was invite-only these uploaded contacts were the only way to invite friends.
- robertwt7 5y agoHow does it work for the seller when the FBI is the one who ends up buying that list and then busted him in the auction? Genuinely asking.. might be dumb question
- unnouinceput 5y agoLet's play devil's advocate here and assume I am the dude selling the list. I would ask for monero and would not care if the FBI is the buyer. The most they can do is to watch exchanges where monero is exchanged versus dollars or other cryptocoins. Then do this a few times over and start buying goods with those then sell the goods on Amazon/eBay for hard $$$. Small amounts and even with 50 cents at a dollar is still worth it for one person.
- ptr2voidStar 5y agoCheck mate.
- sennight 5y agoI've wondered about the feasibility of using state run lotteries for laundering in a cash based criminal enterprise. The known odds of low cost/return scratch-offs and the need to only account for claimed winnings would make it tempting... if it wasn't so labor intensive.
- Aeolun 5y agoIsn’t it great that a lot of high-tech crime is prevented by the people capable of it being too lazy to bother?
- sennight 5y agoI learned a long time ago that the most effective way to correct a vice is to play it against another vice, sloth being an easy goto. But in this case... I'm not a drug dealer, so I don't need to launder large amounts of small bills. But... if I wanted to launder a bunch of public ledger based crypto: instead of a using a loud and proud "bitcoin tumbler", I'd use something like satoshibet. Of course, that is likely why the original no longer exists - and I imagine anyone standing up a replacement (without a sufficiently invasive KYC implementation) would face similar hostility. Anyway, I expect that'll change when a state run satoshibet eventually emerges.
- mm983 5y agoThey are done for this time. Leaking peoples' number who haven't even signed up yet because of their economy flame approach for literally anything, oh boy...
- astatine 5y agoThe 3.8B numbers is really meaningless, in isolation. This is the problem of plenty - 10K numbers with a very specific profile might be a lot more valuable. The real worry would be the info on the relationships between the numbers (which number is connected to whom). This leak seems to have a count of relations rather than the actual connections.
- axegon_ 5y agoWell the facebook data that was published everywhere earlier this year could hold some value when combined with this one: While the facebook data is somewhat outdated, I'm pretty sure you'd get millions of people with relevant and up to date information.
- koolba 5y agoThey should combine it with that zero click remote iMessage bug. That’d be some serious black hat marketing synergy.
- qpiox 5y agoIf you have enough cash and time you can legally create your own list of all possible numbers on the world. Pick a number, dial and see if it exists. Hang up to prevent further charges.
- jsjohnst 5y ago> create your own list of all possible numbers on the world. Pick a number, dial and see if it exists. Let’s say you had the ability to do that 1,000x a minute using an automated dialer. Just in the US alone that would take you over a year to complete and how many of those numbers you verified changed active/disconnected status during that time? (PS, I didn’t downvote you, just pointing out a problem with your theory)
- riffic 5y agoYou've invented wardialing https://en.wikipedia.org/wiki/Wardialing https://en.wikipedia.org/wiki/Wardialing
- deliberateJack 5y agoI am selling a database with ten billion phone numbers. 1.25 GB file with each number compressed to a single bit. You can compare the clubhouse database against mine to determine which numbers are not in their set.
- fisherjeff 5y agoGreat. It’s the weekend and I can theoretically now stop thinking about software, and yet here I am thinking of ways to efficiently compress lists of phone numbers
- quchen 5y agoJust enumerate them all, if none is missing it's fairly easy to compress. (And 1b per number is really inefficient) ;-) main = traverse print [1..99999999]
- luckman212 5y agoWhat language is that?
- WJW 5y agoHaskell
- WJW 5y agoThe Kolmogorov complexity of the set of all phone numbers is pretty low. All phone numbers with a few missing is also pretty low. In fact, I now wonder if you can even compress the 3.8b phone number set to less than 1 bit per phone number. It should be pretty doable since a significant chunk of the number space is not valid.
- dillondoyle 5y agoBut not all numbers are valid? 911. Not all area codes exist.
- 5y ago
- agumonkey 5y agoAh I wonder if that's related to the bot flood I got recently.
- TechBro8615 5y agoI’ve been getting this since the FB hack (by “hack” I mean the recent bulk enumeration of 500m phone numbers that Facebook facilitated for an unknown party).
- michelb 5y agoHow realistic would it be to send (anonymous) mass sms messages with phishing or other malicious links to those numbers? I’m occasionally getting sms message with bogus sender info (i cannot reply, nor get contact info), always wonder how spammers pull that off so easily.
- Scoundreller 5y agoAs a challenge, I try to takedown these things by reporting them to Google Safebrowsing, their SSL provider (if they have one), their host, their URL shortener, etc. Though in Canada, I'm seeing them apply some cloaking measures so they don't get removed as quickly. I think there's two streams of this: 1. a crooked telecom that has low-level access 2. buy a bunch of SIM cards and dump them into one of these aliexpress machines that has 16 wireless modems in them that let you do whatever you want: https://www.aliexpress.com/item/4000462982086.html https://www.aliexpress.com/item/4000462982086.html Can even network them to a bank thingy that'll hold 128 cards: https://www.aliexpress.com/item/4000462976225.html https://www.aliexpress.com/item/4000462976225.html
- ALittleLight 5y agoIt's funny how the hacker who is selling stolen private data is also complaining about GDPR compliance and privacy. On the one hand, he's right that Clubhouse (if this is true) has done something bad, but the hacker is much worse.
- stackedinserter 5y agoIs clubhouse still a thing in July 2021? How do you use it? (and who do you talk to?)
- afrcnc 5y agoIt's fake: https://twitter.com/troyhunt/status/1419013520763539457 https://twitter.com/troyhunt/status/1419013520763539457
- anigbrowl 5y agoEnough phone numbers for half the population of the world? Cool story, bro. I refer here to the aspiring salespeople, not the person reporting it. I suspect this list will be available for free on the dark web within a couple of months. Much as I like to collect interesting data this doesn't seem useful.
- paxys 5y agoI wonder how feasible a business model it is to collect all the data from all leaks which make their way to the internet, massage the data a little bit, and sell it as a brand new "hack" of some popular service. You can probably do this a few times a year without a problem.
- d110af5ccf 5y agoWhy fake a new data leak at all? It's likely to be illegal either way. Depending on the quality of your work I suspect it would be easy to find buyers for aggregated and cross validated data sets on the black market. For that matter, I have to assume that the shadier businesses silently make use of publicly available leaks. The data is just too valuable to ignore depending on your business model.
- fabiandesimone 5y agoHey @fabianbeiner how can I get in touch with you?