8 ms·
So... what advise is there for technology comfortable people who want to mitigate the effects of data leaks like these? It seems like data provided is will be e
by andrewallbright 4y ago
So... what advise is there for technology comfortable people who want to mitigate the effects of data leaks like these? It seems like data provided is will be exposed eventually and company size doesn't seem correlate with data safety.
For example should people be advised to rotate phone numbers every N amount of time?
- Komodai 4y ago
- solarkraft 4y agoExcept that even if I don't use WhatsApp and somebody I know and who has my contact information does, WhatsApp also has my contact information.
- aliqot 4y agoIt's disgusting that this comment had to be vouched for, it's common sense.
- _puk 4y agoIt's also low quality. Not using WhatsApp isn't going to magically secure your details online. As per GP's point, most services eventually seem to leak data, so it may as well be saying "Don't go online". Compare that to the alternate response which provides solid actionable advice for how to limit exposure when these services ultimately leak your data, and you can see why that post was downvoted to oblivion.
- Kiro 4y agoI downvoted and flagged it. It's low-effort bait.
- deleted 4y ago[deleted]
- kadoban 4y agoThe basic stuff helps a decent amount. Assume your name, phone, email, address are all public. Don't reuse passwords, ever (use a password manager), use 2fa wherever possible, ideally not the SMS kind. Use a password manager that has a tie-in with haveibeenpwned or whatever so you know asap to change your creds. Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you can blackhole one that gets leaked, and you can know where it got leaked from. If you can, have a separate setup (completely separate email account(s), not just aliases, and even separate hardware to access them if you can) for very important accounts, the ones that would ~ruin your life for a good bit if they got taken over (bank, retirement, etc.) There's also credit monitoring type stuff, which I've never been clear how useful it is, but might be worthwhile. You also may get it free if some company you use has a leak and they try to PR it away that way. I think there's some way to basically lock your credit against new accounts, I need to look into that someday, don't know the details or if it even exists.
- idiocrat 4y ago>Don't reuse passwords, ever Note to myself: change the combination on my luggage. https://www.youtube.com/watch?v=LcHnf7VQuhc https://www.youtube.com/watch?v=LcHnf7VQuhc
- MattDemers 4y ago>Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you can blackhole one that gets leaked, and you can know where it got leaked from. If you pay for ProtonMail, you get a SimpleLogin Premium for free, which makes the creation of dummy/alias emails a lot easier. They're owned by the same company.
- screamingninja 4y ago> If you pay for ProtonMail These are free for all- https://relay.firefox.com/ https://relay.firefox.com/ https://duckduckgo.com/email/ https://duckduckgo.com/email/
- grammers 4y ago
- jsnell 4y agoThe advise is to do literally nothing about it. What effect do you think this specific leak has on you? What kind of adversary do you think will be able to benefit from this data, and how? The reality is that the data is useless trash, and there is no indication that this has actually leaked from Facebook or is showing any kind of security problem in their systems.
- A4ET8a8uTh0 4y ago<<The reality is that the data is useless trash, That remains to be seen. People are fairly ingenious when it comes to abusing information and information runs the world now. I will offer an unrelated example, partially because I do not want to give ideas on how to benefit from this. Do you remember when certain entrepreneurial billionaire offered a checkmark for sale, which resulted in people impersonating companies and manipulating their stock price[1]? Like with most things, any tool is worth what one is able to do with it. << The advise is to do literally nothing about it. I would not advise to panic, but doing nothing is not exactly great advice either. Some re-assessment of one's current security posture may be warranted. [1]https://www.fiercepharma.com/marketing/eli-lilly-hit-new-twitter-blue-fake-account-forced-apologize-over-free-insulin-tweet https://www.fiercepharma.com/marketing/eli-lilly-hit-new-twi...
- jsnell 4y ago> Like with most things, any tool is worth what one is able to do with it. Yes, and given an attacker will not get new capabilities from this data, it is worth nothing. Any attack that could be feasibly run with a list of nothing but phone numbers associated with some (unknown) WhatsApp account could be done without that list just as easily. That's because of two things: a) phone numbers within a given country are easy to enumerate, b) the WhatsApp account space is dense, i.e. the odds of any legit phone number being used for WhatsApp is high. > I would not advise to panic, but doing nothing is not exactly great advice either. Some re-assessment of one's current security posture may be warranted. If you can't formulate a realistic threat from this data, how can you possibly re-evalate your security posture in light of it? You need a threat model for that. Pondering about the security of one's digital life can of course be worthwhile in general, but advising anyone to do so in the context of this linkbait is just advising them to waste their time. In your Twitter example, the impersonation did not come as a surprise. People were predicting that outcome within minutes of Musk announcing it. Can you make a prediction about what bad things will happen to the people whose phone number is in this dump, compared to people whose phone number isn't there?
- drdaeman 4y agoPeople should be advised to not use phone numbers at all. There was a joke "all phone numbers leaked" list that just listed everything from 000-000-0000 to 999-999-9999. If there is no other information associated (names, pictures, emails, anything) then this leak is of almost comparable severity.
- philjohn 4y agoWe used to have these things called Phone Books, that literally, contained everyone's phone numbers. We didn't call those leaks.
- lawtalkinghuman 4y agoThere's an important difference between people being able to do inefficient paper-based one-off `SELECT ... LIMIT 1` queries when needed and the entire world being able to find new and exciting ways to search, join and mix data at great speed—the latter tends to enable new and exciting ways for the data to be used both for commercial gain, criminal purposes, and abusive trolling. (See: the history of internet harassment for the last 20 years.) Pointing out that we used to put all the phone numbers in a book published by the phone company and now we don't is historically true but practically unimportant, just as "hey, sorry to hear your house got broken into, but you know, people in IDYLLIC_RURAL_HAMLET don't even lock their front doors like you BIG_CITY folks do" isn't useful unless giving up living and working in BIG_CITY and moving to IDYLLIC_RURAL_HAMLET is actually a practical option, which most likely it isn't (and if that were to happen en masse, IDYLLIC_RURAL_HAMLET would suddenly find they'd also need to lock their front doors if their population increased by a factor or two). Who could have predicted that technological change might lead to shifts in social attitudes? Or, indeed, that the rules, principles and institutions we collectively create to make society bearable have to adapt to said changes?