TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Have I Been Facebooked?

384 pointsby mendelmalehabout 4 years ago

45 comments

aiurabout 4 years ago
&quot;Currently, we don&#x27;t know if Facebook has fixed the vulnerability since the company hasn&#x27;t released any statement regarding the breach.&quot;<p>&quot;This is old data that was previously reported on in 2019. We found and fixed this issue in August 2019&quot; - FB
评论 #26709505 未加载
评论 #26708805 未加载
评论 #26708190 未加载
shnpabout 4 years ago
I deleted my (outdated) phone number from facebook years ago and it&#x27;s still part of the leak, with my name and gender in it. I did not replace the phone number with another phone number. Really says something about what delete means for fb.
评论 #26712008 未加载
评论 #26709901 未加载
评论 #26708990 未加载
评论 #26710256 未加载
评论 #26733948 未加载
评论 #26713275 未加载
评论 #26710108 未加载
评论 #26710911 未加载
helbabout 4 years ago
Troy just added phone number search to Have I Been Pwned as well: <a href="https:&#x2F;&#x2F;www.troyhunt.com&#x2F;the-facebook-phone-numbers-are-now-searchable-in-have-i-been-pwned&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.troyhunt.com&#x2F;the-facebook-phone-numbers-are-now-...</a> (<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26709848" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26709848</a>)
评论 #26710702 未加载
obiShawnKenobiabout 4 years ago
My number was leaked (checked the dump myself) but I don&#x27;t show up on this site. Seems like there are some bugs to work out
评论 #26708697 未加载
评论 #26709448 未加载
评论 #26708128 未加载
评论 #26706922 未加载
评论 #26707650 未加载
评论 #26706336 未加载
MarcoBusterabout 4 years ago
I am a co-author of the site. We are already aware of your concerns about giving out your phone number. The source code is free and reviewable on Github. We know it&#x27;s not possible to verify what&#x27;s running on a server but we hope it adds a level of trust. We are currently hashing all phone numbers so we don&#x27;t have to deal with them anymore. We will keep you updated.
评论 #26709602 未加载
评论 #26709702 未加载
评论 #26709736 未加载
x3sphereabout 4 years ago
Facebook should email those affected... surely they know who was compromised or not. Shouldn&#x27;t have to use random sites for this. Why has there been no communication from them?
评论 #26705844 未加载
评论 #26706333 未加载
tonymetabout 4 years ago
Can someone bcrypt all these phone numbers &amp; emails and make that public? Share the salt and then everyone can just test their own phone number without sending it to some rando
评论 #26707112 未加载
评论 #26707023 未加载
评论 #26707537 未加载
评论 #26708446 未加载
评论 #26707527 未加载
szundiabout 4 years ago
How does one know a site like this is not just an other data harvesting site?
评论 #26708726 未加载
评论 #26708864 未加载
评论 #26708558 未加载
评论 #26710570 未加载
评论 #26709376 未加载
评论 #26708715 未加载
评论 #26709064 未加载
tngranadosabout 4 years ago
Not sure what’s going on but it says my number is not part of the leak, but I’ve checked myself and it is actually leaked. Just be aware that it may not be complete.
评论 #26709635 未加载
评论 #26709706 未加载
评论 #26710061 未加载
nottorpabout 4 years ago
Hmm I haven&#x27;t given facebook a phone number. How can I check if my account is included in the leak? Haveibeenpwned doesn&#x27;t include facebook in the leaks with my FB email, but I&#x27;m not sure I&#x27;m checking in the right place.
评论 #26706004 未加载
chillwavesabout 4 years ago
No one else wanted to try, but I had a feeling my data is breached (seems to happen every few months?)<p>Anyhow, my phone number had a hit and they showed my first and last initial and corresponding asterisks; seems legit.<p>For people saying &quot;why enter your phone number into random site&quot; -- not sure how much value a phone number provides without the accompanying information.
评论 #26707352 未加载
CloselyChunkyabout 4 years ago
From what I can see, this site sends your whole number to the backend to search for a number in the dump[0], while haveibeenpwned.com will hash the input, send only a prefix to the server and receive a list of hashes with the same prefix. If your hash is in the list, you&#x27;ve been pwned, but you can check without leaking your data to HIBP.<p>Edit: I just checked, seems like the form on the frontpage of HIBP also submits your complete email&#x2F;phone number. Pretty sure I read about how you don&#x27;t have to submit your personal data to validate against HIBP, not to long ago...<p>[0]: <a href="https:&#x2F;&#x2F;github.com&#x2F;Fumaz&#x2F;haveibeenfacebooked-api&#x2F;blob&#x2F;master&#x2F;src&#x2F;api&#x2F;app.py#L21" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Fumaz&#x2F;haveibeenfacebooked-api&#x2F;blob&#x2F;master...</a>
评论 #26712105 未加载
Flatcircleabout 4 years ago
why would I enter my info on a random site though?
评论 #26705920 未加载
评论 #26705998 未加载
评论 #26703826 未加载
discordanceabout 4 years ago
“Has my credit card number been leaked”.com
评论 #26707500 未加载
评论 #26707895 未加载
flixicabout 4 years ago
I have made a similar site, but just for Lithuanian numbers:<p><a href="https:&#x2F;&#x2F;fbhack.lekevicius.com" rel="nofollow">https:&#x2F;&#x2F;fbhack.lekevicius.com</a><p>All the numbers that I know for sure to be in the leak return &quot;not found in the leak&quot; on this site.
eganistabout 4 years ago
So, a few things.<p>1) no indication that there&#x27;s any rate limiting here beyond a 2 second cooldown (thanks for that, grenoire), but I only tested it using burp intruder community edition, and I only tested it on a set of numbers guaranteed to return false. If anyone wants to test a range with a known-leaked number in it, up to you.<p>2) it&#x27;s very possible that if there is rate limiting, it acts invisibly.<p>But if there&#x27;s no rate limiting as I suspect, someone can easily just iterate through this data set and extract every number (well, until cloudflare trips the requests). Alternatively, someone can request a large set of numbers that includes their own in order to fuzz the range their own number is in.
评论 #26706658 未加载
评论 #26706683 未加载
davidcbcabout 4 years ago
I&#x27;m looking forward to the sequel, &quot;Have I Been &#x27;Have I Been Facebooked&#x27;ed&quot; when it turns out this is just a data harvesting operation.<p>If you don&#x27;t want your phone number leaked don&#x27;t hand it over to a random website that pinky swears it won&#x27;t keep it. It&#x27;s maybe not a scam, but still...
评论 #26706034 未加载
评论 #26706297 未加载
评论 #26706041 未加载
评论 #26707796 未加载
评论 #26708839 未加载
评论 #26706730 未加载
rvbaabout 4 years ago
Every time I see a site like this I wonder if the site is legit, or does it &quot;match&quot; the phone number with an IP.
Kiroabout 4 years ago
Aren&#x27;t telephone directories a thing anymore? At least in my country you can just search for a person online and see their phone number. Someone&#x27;s phone number seems like the least sensitive PII.
评论 #26708850 未加载
评论 #26709760 未加载
评论 #26712208 未加载
评论 #26709388 未加载
hmsimhaabout 4 years ago
Be aware that this (currently) doesn&#x27;t work for Canadians (at least the one I checked). You&#x27;ll have to download the dump yourself and grep.
评论 #26708453 未加载
r00fabout 4 years ago
This is the first time when I see the UAE being called ARE in a country list. I even went and asked Google, and it turns out there is in fact one ISO standard that calls it ARE. All the others, including ITU (we are talking about phone codes, after all) call it as UAE. Really strange choice of naming standard for something phone-related.
ocelikerabout 4 years ago
Wish it supported wildcards. I&#x27;m not comfortable putting in my phone number for the exact reasons the author states.
评论 #26706102 未加载
eythianabout 4 years ago
Be aware that this site doesn&#x27;t seem to be the whole story, it doesn&#x27;t match me for example, but this one does: <a href="https:&#x2F;&#x2F;jstsch.com&#x2F;facebook&#x2F;" rel="nofollow">https:&#x2F;&#x2F;jstsch.com&#x2F;facebook&#x2F;</a> (NL only)<p>So there&#x27;s some ambiguity or incompleteness somewhere.
anonytraryabout 4 years ago
I wish there was an &quot;email&quot; input. Last time I had a Facebook account was 10 years ago (probably before phone numbers were de facto identity) and I would be fascinated to learn if my old accounts were in the leak, because Facebook was supposed to fully delete those accounts :)
评论 #26708027 未加载
codeecanabout 4 years ago
If you don&#x27;t want to input your full phone number, you can use this tool: <a href="https:&#x2F;&#x2F;codeeverywhere.ca&#x2F;apps&#x2F;fb_data" rel="nofollow">https:&#x2F;&#x2F;codeeverywhere.ca&#x2F;apps&#x2F;fb_data</a> .<p>Searches use partial data from multiple fields to find matches.
评论 #26709607 未加载
fvvabout 4 years ago
my 2c security tips:<p>- i trust my browser and site owner version : text in clear<p>- i barely trust site owners ( if a match is found they still have access the fact that I&#x27;ve verified that number ) :<p>hash each phone address hashed ie using bcrypt and using a composed salt ( ie : site address + email in the account + phone address ) so rainbow table will be impossible to use ( this because phone numbers are low entropy and even without rainbow table IMO are not that very secure )<p>than ask user for the hashed version in the text field ( also write a linux terminal style command that can be used to hash given salt and hashing , or redirect to a trusted hasher service online (multiple links can be provided ) )<p>both text fields can be provided to allow the user a choice
atemerevabout 4 years ago
That&#x27;s odd. My number is in the leak, but it doesn&#x27;t check on this website.
a10cabout 4 years ago
I&#x27;m a little skeptical this is accurate. Supposedly 1&#x2F;3rd of my country&#x27;s population is in this leak, yet not one of the 40 people i tried in my contacts list appears on the leak.
otagekkiabout 4 years ago
The website says no, but after downloading the whole dataset and doing a quick search using &quot;grep -rnw&quot; I got my current phone number in addition to that of my grandfather&#x27;s (also on FB), so even if the site says you&#x27;re not facebooked, please check the raw data available on pastebin archive (<a href="https:&#x2F;&#x2F;archive.is&#x2F;MZqak" rel="nofollow">https:&#x2F;&#x2F;archive.is&#x2F;MZqak</a>)
beardboundabout 4 years ago
I am annoyed. I haven&#x27;t updated my Facebook in years so most of the data is out of date and I use a separate phone line for personal correspondence, but I do still have a Facebook account for the occasional friend&#x2F;family that uses messenger. This might be the final nail in the coffin for me and get me to delete my account.<p>Maybe I can finally get my last couple of friends to switch to Signal.
code-expressabout 4 years ago
The phone numbers put into this website can be trivially reversed despite of the false sense of security the phone-number disclaimer provides: <a href="https:&#x2F;&#x2F;code.express&#x2F;docs&#x2F;blogs&#x2F;facebooked&#x2F;" rel="nofollow">https:&#x2F;&#x2F;code.express&#x2F;docs&#x2F;blogs&#x2F;facebooked&#x2F;</a>
myth_busterabout 4 years ago
haveibeenzucked is arguably better name for a site.
tonymetabout 4 years ago
anyone know of one of these sites where they don&#x27;t send your phone number &#x2F; email to the server? The &#x2F;search endpoint phone_number param has your number.<p>They should instead hash your number client side and test the hash.
dandareabout 4 years ago
I never shared my phone number with FB, neither for 2FA nor anything else, yet it is in this DB. Could FB get the number via my Android FB app?
paul7986about 4 years ago
yeah not going to use any search tool where i need to enter my number ... you could just post the data by area codes..... just create a bland UI that lists all area codes ..let user click into the area code and then on the next page list all the phone numbers in that area code that have been affected.<p>I&#x27;d use that but not searching by phone number.
aszantuabout 4 years ago
Never handed over my number when I could avoid it. I&#x27;m very suspicious about it for some reason
gabegmabout 4 years ago
This site doesn&#x27;t seem to include the leaked numbers from my country +356 (MT).
villgaxabout 4 years ago
Do not put your number here FFS
CobaltFireabout 4 years ago
Down as of 06APR 1715 PST. Looks like a legal warning by the Italian Gov?
guerrillaabout 4 years ago
This says no but haveibeenpwned says yes. Hash collision on the HIBP site?
doodpantsabout 4 years ago
&quot;Is Facebook still safe to use?&quot;<p>Has Facebook ever been safe to use?
kamiya_kimikoabout 4 years ago
HTTP 451 - Unavailable For Legal Reasons :(
idownvotedabout 4 years ago
Already getting spammed hourly by text messages pointing me towards URLs I should click.<p>AFAIK there isn&#x27;t much awareness about this leak amongst most of FB&#x27;s userbase: Less tech-savvy and 40yrs ++.
marshmallow_12about 4 years ago
what i want to know is where you can find this information. Also, is it even legal for the website owner to hold stolen information.
评论 #26705958 未加载
pnathanabout 4 years ago
``` Facebook account ID First name: P** Last name: N*** Gender Relationship status Location ```<p>:: squints ::<p>I&#x27;ll grant you, this is much more problematic for some than me. But for me, this is, roughly, analogous to my actual LinkedIn, Github, or Hacker News profile, which link to my resume (which has my phone number), combined with a squint at my age and a guess.<p>There&#x27;s a <i>lot</i> worse that could be leaked.