TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

You can use Facebook to identify people by their email or phone number

59 pointsby slashdotaccountover 11 years ago

10 comments

collingreeneover 11 years ago
I work at facebook on the security team.<p>This is an account recovery endpoint used if your account was hacked for example.<p>Your name, profile picture and a few other things are considered public information so there is no security issue displaying them. See: <a href="https://www.facebook.com/help/167709519956542" rel="nofollow">https:&#x2F;&#x2F;www.facebook.com&#x2F;help&#x2F;167709519956542</a>
评论 #7068217 未加载
评论 #7068144 未加载
评论 #7067898 未加载
评论 #7067996 未加载
RKearneyover 11 years ago
It appears this only works if you&#x27;re using an account that you&#x27;ve already logged into from that IP address.<p>If you try someone else&#x27;s phone number, it has a placeholder profile picture, says &quot;Facebook User&quot;, and has censored out email addresses to send a recovery email too.<p>I&#x27;m guessing everyone here is using their own phone number to test with which yields a lot more information than if you were to try it with a phone number of a friend whose never logged into Facebook from your network.
评论 #7068020 未加载
mikeyouseover 11 years ago
Pair this with the Snapchat leak, so you can go from:<p>Snapchat Username --&gt; Snapchat Phone Number --&gt; Facebook Account<p>I hope people are behaving.
评论 #7067596 未加载
评论 #7068006 未加载
评论 #7068409 未加载
anmalhotover 11 years ago
I had reported this to FB security last year when I found it was trivial to find partially masked email ids &amp; phone numbers of anyone behind my Uni&#x27;s gateway.<p>I was informed that this was a design decision since previously used IPs are more trustworthy than any new IP. I considered this a design flaw and reported since large institutions are typically behind a NAT and they become susceptible to targeted attacks.
eridiusover 11 years ago
This URL now redirects to the root of facebook.com, so I guess they&#x27;ve already disabled it.
评论 #7067813 未加载
评论 #7067805 未加载
obblekkover 11 years ago
Is this legal? Did I give consent to Facebook publicly associating this information in ToS?
评论 #7067920 未加载
jamdavswimover 11 years ago
It definitely gives you much more information than you had when you started... It really shouldn&#x27;t display name&#x2F;photo.<p>An example of a poor trade for experience vs security.
评论 #7067705 未加载
评论 #7067862 未加载
pyvpxover 11 years ago
privacy is dead.<p>if you&#x27;re going to do something that might raise the ire of someone sophisticated, don&#x27;t do it online with your true and&#x2F;or trusted persona.<p>now if you&#x27;re complaining the waterline for &quot;sophisticated&quot; is getting lower...well...welcome to technology :)
Lobitaover 11 years ago
This discussion overlooks proxies, macchangers, firewalls, browsers, and pseudo identity...
amaksover 11 years ago
I&#x27;ll probably end up deleting my facebook account. Wait, is it even possible to do?
评论 #7068468 未加载
评论 #7068465 未加载