TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

From email to phone number, a new OSINT approach (2019)

312 pointsby Lucover 1 year ago

21 comments

1nd1ansumm3rover 1 year ago
Fun to see this issue get talked about. Ancedote- I bought some car parts from a semi-scammer. Not a full-on scam but the guy wouldn't ship the complete order even though he had my money for several weeks. We had communicated on a few different platforms. Each platform offered up a little piece of his identity. Last four of this. First four of that. It was enough to piece it all together. I gave him a call at his place of employment which happened to be in the exact same industry as the parts that were being sold. I asked him to ship the parts and casually asked if his employer was involved in the sale. He perked right up and the next day he shipped everything I had bought and a few extras.
评论 #38296775 未加载
评论 #38294454 未加载
miki123211over 1 year ago
There&#x27;s one missing piece in that article, and it&#x27;s the CNAM database (US only).<p>CNAM is the database that carriers use to give you alphanumeric caller ID (&quot;SMITH JOHN&quot; instead of &quot;+1 (555) 123-4567&quot;). Many carriers don&#x27;t display this data as far as I believe, but most of them make it available.<p>Querying that database isn&#x27;t free, but you could probably find a way to do it for a few hundred numbers relatively cheaply. People&#x27;s names and emails are often similar, so you could probably figure out an algorithm to give you the most likely candidates.<p>The data is often wrong in interesting ways (I&#x27;ve seen everything from deadnames to people&#x27;s exes they still share a plan with), but it is still pretty useful.
评论 #38296153 未加载
评论 #38292728 未加载
评论 #38293546 未加载
alkonautover 1 year ago
I use my real name as my email (as many of us do). And my phone number is publicly listed in many phonebooks. In Sweden it&#x27;s standard practice for everyone to have their address and phone number searchable unless you opt out. Basically what used to be in the phone books in the 80s (which was everyone) just moved online in the 90s so now everyone&#x27;s adress and phone number is publicly searchable. This can be really useful, but of course it can be used for evil as well.<p>But one of the really positive things about having so much &quot;public PII&quot; (SSNs, Addresses, phone numbers, birth days) is that people don&#x27;t have to treat this information as some sort of secret. Everyone needs proper ID and eID because knowing someones digits doesn&#x27;t make it any easier to impersonate them.<p>If someone wants my phone number, they take my email which has first- and last name, go to any of the N search sites and they find 100 people sharing my first and last name. If they know a city and approximate age (Which they can easily get from a social platform) they can narrow it down to just a couple of people. Public records then shows my birthdays, my cars, my income, who&#x27;s also registered on the address, and so on. It&#x27;s not difficult doing OSINT in Sweden...
swozeyover 1 year ago
lol<p>&gt; Paypal, which displays five digits including area code to anyone knowing the email address (but only three if the attacker knows the target’s password), decided this is working as designed and will not take action.<p>Wild.<p>Does anyone know how scammers are getting numbers off of LinkedIn? Or correlating them to numbers from elsewhere? I know a company whose employees are constantly getting fake CEO texts.
评论 #38291697 未加载
评论 #38325492 未加载
saltminerover 1 year ago
&gt; If it is a requirement, consider using a virtual number like Google Voice or even a dedicated SIM that you only use for this purpose and never give the number away.<p>For the second SIM option, that requires a dual-SIM device, which are still fairly niche in the US.<p>When it comes to VOIP numbers, unfortunately, many sites look up phone numbers and block VOIP providers, which sucks because Android still has no good way of sending&#x2F;receiving carrier texts on the desktop (and before someone suggests the Google Messages web interface, it &quot;forgets&quot; my device too often for me to take it seriously). Occasionally, this can create a catch 22, where the VOIP blocking is implemented after the fact and prevents you from ever using the account again because the VOIP blocking was also implemented on the SMS 2FA.<p>And then there&#x27;s services which don&#x27;t even bother to check if they can actually reach a number before accepting it. Harris Teeter pharmacies, for example, will happily accept a VOIP number, but their system is unable to call or text VOIP numbers, so you never get your prescription notices. (And I&#x27;d bet this applies to all Kroger brands since they share a lot of systems.)
评论 #38295449 未加载
评论 #38294098 未加载
评论 #38292860 未加载
评论 #38293332 未加载
评论 #38298017 未加载
评论 #38298430 未加载
BHSPitMonkeyover 1 year ago
&quot;Good morning class. A certain agitator, for privacy&#x27;s sake let&#x27;s call her Lisa S... No, that&#x27;s too obvious. Let&#x27;s say L. Simpson.&quot;
xhkkffbfover 1 year ago
This kind of uncoordinated leaking is a deeper problem. Many share the last four digits of a SS#. Okay. But often the first five are easy to guess from the birthday and the birth state. The first few digits tell the state where the number was issued.
评论 #38291590 未加载
评论 #38291615 未加载
评论 #38291557 未加载
hipadev23over 1 year ago
Great technique for those VCs who think they can just ignore my emails
bunabhucanover 1 year ago
All this hassle using different email addresses for each service and a Google voice number was worth it.
评论 #38301617 未加载
评论 #38301471 未加载
SpaceLawnmowerover 1 year ago
One thing I&#x27;ve always wondered is how security researchers feel justified in releasing tools like the one in this blog post to the public. I can almost certainly say that the number of bad or creepy uses for an automated email to phone number generating tool massively outweighs the good reasons for having one. Does he get a pass because he&#x27;s doing this for &quot;research&quot; and it&#x27;s a grey area anyways? Does he feel better because he talked to the companies who exposed the vulnerability and it&#x27;s neutered now?
评论 #38292779 未加载
评论 #38293100 未加载
评论 #38292232 未加载
评论 #38292797 未加载
评论 #38294299 未加载
评论 #38292440 未加载
评论 #38297852 未加载
sp0rkover 1 year ago
I check GitHub&#x27;s Trending page for Python projects every day or so. I was a little confused why this repo was trending today, particularly because the note at the top indicates that a lot of the services patched the exploit long ago.<p>It&#x27;s interesting to see that this being posted here on Hacker News is presumably enough to push the GitHub repo to the trending page for Python.
doolsover 1 year ago
As an Australian I can only ever recall seeing the last 2 or 3 digits of my mobile number. The first 2 digits of all mobile numbers are the same and you can&#x27;t send text messages to landlines.
dangover 1 year ago
Related:<p><i>Email to Phone Number Osint Tool</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30476792">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30476792</a> - Feb 2022 (2 comments)
hackideiomatover 1 year ago
The amazon thing bugs me, as someone with a custom domain :D I literally get 1 or 2 * in my name and the rest is public knowledge due to this
RecycledEleover 1 year ago
The author ignores number portability. Just because I currently live in a city and have AT&amp;T does not mean they issued my phone number.
fudged71over 1 year ago
@dang please append (2019) to the title
评论 #38292081 未加载
shivz45over 1 year ago
Oh i tried this technique just now to confirm one scammer&#x27;s real phone number details.<p>Paypal here again
jwallyover 1 year ago
Can someone summarize this?<p>I think the site is struggling with traffic and I&#x27;m getting 503&#x27;d...
评论 #38291725 未加载
评论 #38291710 未加载
评论 #38292091 未加载
pmarreckover 1 year ago
Keeping a phone number secret is &quot;security by obscurity&quot; and therefore the whole point of this article is rather moot.
评论 #38293603 未加载
Uptrendaover 1 year ago
I noticed that some websites also reveal different parts of the credit card. Really hope that this attack also doesn&#x27;t work there. Lmao...
egberts1over 1 year ago
LOL! DOA!<p>Next: Signal app, method
评论 #38326389 未加载