TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

267M Facebook users IDs and phone numbers exposed online

175 pointsby JeanMarcSover 5 years ago

17 comments

cmdshiftf4over 5 years ago
There&#x27;s a lot of very obvious &quot;didn&#x27;t bother reading the article but I&#x27;m going to comment on the headline&quot; behaviour in this thread.<p>FB users put their details on their publicly accessible FB, someone ran a scraper across FB for publicly accessible info and dumped it into an insecure elasticsearch cluster and a researcher found that cluster.<p>How is FB at fault there? I say this as someone who has colossal issues with that company in general.
评论 #21844293 未加载
评论 #21845434 未加载
collywover 5 years ago
Wasn&#x27;t facebook pestering me for my phone number for &quot;extra security&quot; a while back? Seems like the exact opposite.
评论 #21842740 未加载
评论 #21842501 未加载
评论 #21843959 未加载
ga-vuover 5 years ago
Just a reminder that Comparitech &quot;pays&quot; security researchers for &quot;data breaches&quot; and most likely encourages people to report these things to them without getting servers patched: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;securinti&#x2F;status&#x2F;1196850409924681728" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;securinti&#x2F;status&#x2F;1196850409924681728</a><p>No offense, but if you need to &quot;pay&quot; for your researcher, you&#x27;re probably not that ethical and are most likely behind some intentional offensive hacking, so people can make money off your back.
评论 #21843601 未加载
rshnotsecureover 5 years ago
Facebook has fundamentally lost control of their infrastructure. It is insanity. There are now VPNs out of Hong Kong operating output of FB ASN space. I truly have never seen anything like this in my life.<p>At FB the morale has collapsed. The support forums and bug bounty submissions are piling up and have been for weeks.<p>FB cannot and will not act. It is a problem of leadership not engineering and I have tremendous respect for nearly all of the staff there.<p>That being said the fact that Facebook continues to ignore that servers in Vietnam are hosting what appears to be all 71 million records of the Vietnamese ppl is shocking. If you are a Muslim in Vietnam the information is shockingly detailed.<p><a href="http:&#x2F;&#x2F;125.212.244.27:9200&#x2F;_cat&#x2F;indices" rel="nofollow">http:&#x2F;&#x2F;125.212.244.27:9200&#x2F;_cat&#x2F;indices</a>
评论 #21842567 未加载
评论 #21843424 未加载
unnouinceputover 5 years ago
Slight reminder that Whatsapp is Facebook owned and that one is based on phone numbers only. Talk about phone numbers, heh?
drywaterover 5 years ago
Everyone is at fault except Facebook. Vietnam, illegal scraping, criminals.
评论 #21842517 未加载
square_usualover 5 years ago
Is there a way to check if your data was in this database? Is it on haveibeenpwned yet?
评论 #21842592 未加载
评论 #21844048 未加载
meeritaover 5 years ago
I bet, even if I deleted my account 2 and a half years ago my data can be found there.
评论 #21843392 未加载
smailiover 5 years ago
&gt; This will reduce the chances of your profile being scraped by third parties, but the only way to ensure it never happens again is to completely deactivate or delete your Facebook account.<p><i>Translation: the only way to have an account is to not have an account.</i>
marmshallowover 5 years ago
This is what happens when you centralize data - it leaks
cm2187over 5 years ago
There has been a few elastic search data leaks recently. I do not know the product. Is it unsecure by default like MongoDB?
评论 #21842586 未加载
aww_dangover 5 years ago
The author describes himself as: &quot;TECH WRITER, PRIVACY ADVOCATE AND VPN EXPERT&quot; (capitalization from source)<p>&quot;...the trove of data is most likely the result of an illegal scraping operation or Facebook API abuse by criminals...&quot;<p>More cyber alarmism. What would these &quot;VPN experts&quot; say to a phone directory?<p>He goes on to describe how this was reported as abuse the service provider instead of notifying the owners of the DB.<p>Finally he concludes that users can manage their privacy settings from within Facebook. Thereby acknowledging that users can manage their data or have chosen to provide it publicly.<p>The cyber-alarmism trend from self appointed security experts has gone too far.
评论 #21842613 未加载
Ivover 5 years ago
<p><pre><code> Zuckerberg: Yeah so if you ever need info about anyone at Harvard Zuckerberg: Just ask. Zuckerberg: I have over 4,000 emails, pictures, addresses, SNS [Redacted Friend&#x27;s Name]: What? How&#x27;d you manage that one? Zuckerberg: People just submitted it. Zuckerberg: I don&#x27;t know why. Zuckerberg: They &quot;trust me&quot; Zuckerberg: Dumb fucks. </code></pre> <a href="https:&#x2F;&#x2F;www.businessinsider.com&#x2F;well-these-new-zuckerberg-ims-wont-help-facebooks-privacy-problems-2010-5" rel="nofollow">https:&#x2F;&#x2F;www.businessinsider.com&#x2F;well-these-new-zuckerberg-im...</a>
评论 #21842870 未加载
vassilykover 5 years ago
What this highlights is that it is damn simple to be a poor developer yet achieve a particular goal. You can brute force your way towards that goal, ignoring any sort of costly &#x27;useless&#x27; security, usability or user privacy aspects. Even more so if you&#x27;re a criminal. GDPR|CCPA &lt; INTERPOL!<p>This is never going to end. This is true for criminal orgs but also legit businesses that despite regulations will mostly prioritize features to their customers over less tangible&#x2F;monetizable value like hardened infrastructure and updated software.<p>Maybe I&#x27;m wrong and this cluster was left exposed for another reason, though.
AltmousGadflyover 5 years ago
Facebook only has an issue with people getting the data for free.
onetimemanytimeover 5 years ago
just a matter of time before messages are exposed too, ruining a lot of lives in the process. One by one, all castles will fall.
wetpawsover 5 years ago
At this point, in 2019, does anyone truly care about leaks anymore? I feel like this is becoming a new norm.
评论 #21842600 未加载
评论 #21842490 未加载