Hacker News new | ask | show | jobs
by xendipity 3002 days ago
"Until today, people could enter another person’s phone number or email address into Facebook search to help find them. ... malicious actors have also abused these features to scrape public profile information by submitting phone numbers or email addresses they already have through search and account recovery. Given the scale and sophistication of the activity we’ve seen, we believe most people on Facebook could have had their public profile scraped in this way."

Hm. This seems like an interesting tidbit, I would love to know more. It seems to imply that many profiles have already been scraped in this way. A phone number is a really strong cross-domain identifier as we use it across a bunch of different online services. Collate your Facebook scrape with a couple data brokers and you've got a real strong profile of someone.