Skip to main content

Facebook’s Graph Search flaw exposes names with phone numbers

facebook security
Image used with permission by copyright holder

Email address collection using Facebook has been a problem that we’ve encountered before when hackers were selling email addresses by the millions. Recently a similar issue – this time having to do specifically with phone numbers – has popped up again by way of Texan mobile developer Brandon Copley who has amassed a database of 2.5 million phone numbers.

Despite having brought the issue to Facebook’s attention, Copley found that the social network preferred to brush the problem off as just a feature within Facebook that’s actually public information. If you do a quick Graph Search for individual phone numbers, granted that the user has set their profile to public and included their phone number, Graph Search will spit out the names of Facebook users associated with that phone number. 

Recognizing the technicality of scraping Graph Search for phone numbers (and email addresses), Facebook told TechCrunch, “Your privacy settings govern who can find you with search using the contact info you have provided, such as your email address and phone number. You can modify these settings at any time from the Privacy Settings page.” There’s not much indication of Facebook’s willingness to patch up that loophole, it seems.

Since Facebook wasn’t going to be working on fixing the security flaw within Graph Search, Copley took matters into his own hands. He scraped 2.5 million phone numbers, apparently to prove a point, and presented the evidence to Facebook. He went as far as testing the limits of his developer account and by searching thousands of phone numbers on a daily basis, bumping this up to millions of searches using the “API token of an app that isn’t rate-limited,” until his account was consequently banned by Facebook numerous times.

Then noticing what was happening, Facebook’s lawyers sprung into action with a cease and desist letter claiming that Copley was “unlawfully acquiring Facebook user data” without permission. What its lawyers were reportedly sniffing around for included the method and script itself for how Copley was scraping Facebook’s database, and with whom he’s shared this knowledge with. Understandably Facebook may have reasons to be concerned about the safety of its users considering that Copley could use his “research” for malicious purposes, but bringing its lawyers into play really makes you question if the collection of personal information is really the non-issue that Facebook initially made it out to be.

Editors' Recommendations

Topics
Francis Bea
Former Digital Trends Contributor
Francis got his first taste of the tech industry in a failed attempt at a startup during his time as a student at the…
How to create multiple profiles on a Facebook account
A series of social media app icons on a colorful smartphone screen.

Facebook (and, by extension, Meta) are particular in the way that they allow users to create accounts and interact with their platform. Being the opposite of the typical anonymous service, Facebook sticks to the rule of one account per one person. However, Facebook allows its users to create multiple profiles that are all linked to one main Facebook account.

In much the same way as Japanese philosophy tells us we have three faces — one to show the world, one to show family, and one to show no one but ourselves — these profiles allow us to put a different 'face' out to different aspects or hobbies. One profile can keep tabs on your friends, while another goes hardcore into networking and selling tech on Facebook Marketplace.

Read more
How to set your Facebook Feed to show most recent posts
A smartphone with the Facebook app icon on it all on a white marble background.

Facebook's Feed is designed to recommend content you'd most likely want to see, and it's based on your Facebook activity, your connections, and the level of engagement a given post receives.

But sometimes you just want to see the latest Facebook posts. If that's you, it's important to know that you're not just stuck with Facebook's Feed algorithm. Sorting your Facebook Feed to show the most recent posts is a simple process:

Read more
How to go live on TikTok (and can you with under 1,000 followers?)
Tik Tok

It only takes a few steps to go live on TikTok and broadcast yourself to the world:

Touch the + button at the bottom of the screen.
Press the Live option under the record button.
Come up with a title for your live stream. 
Click Go Live to begin.

Read more