|
|
|
|
|
by A4ET8a8uTh0
1295 days ago
|
|
<<The reality is that the data is useless trash, That remains to be seen. People are fairly ingenious when it comes to abusing information and information runs the world now. I will offer an unrelated example, partially because I do not want to give ideas on how to benefit from this. Do you remember when certain entrepreneurial billionaire offered a checkmark for sale, which resulted in people impersonating companies and manipulating their stock price[1]? Like with most things, any tool is worth what one is able to do with it. << The advise is to do literally nothing about it. I would not advise to panic, but doing nothing is not exactly great advice either. Some re-assessment of one's current security posture may be warranted. [1]https://www.fiercepharma.com/marketing/eli-lilly-hit-new-twi... |
|
Yes, and given an attacker will not get new capabilities from this data, it is worth nothing.
Any attack that could be feasibly run with a list of nothing but phone numbers associated with some (unknown) WhatsApp account could be done without that list just as easily. That's because of two things: a) phone numbers within a given country are easy to enumerate, b) the WhatsApp account space is dense, i.e. the odds of any legit phone number being used for WhatsApp is high.
> I would not advise to panic, but doing nothing is not exactly great advice either. Some re-assessment of one's current security posture may be warranted.
If you can't formulate a realistic threat from this data, how can you possibly re-evalate your security posture in light of it? You need a threat model for that. Pondering about the security of one's digital life can of course be worthwhile in general, but advising anyone to do so in the context of this linkbait is just advising them to waste their time.
In your Twitter example, the impersonation did not come as a surprise. People were predicting that outcome within minutes of Musk announcing it. Can you make a prediction about what bad things will happen to the people whose phone number is in this dump, compared to people whose phone number isn't there?