Skip to main content

Facebook’s Graph Search flaw exposes names with phone numbers

facebook security
Image used with permission by copyright holder

Email address collection using Facebook has been a problem that we’ve encountered before when hackers were selling email addresses by the millions. Recently a similar issue – this time having to do specifically with phone numbers – has popped up again by way of Texan mobile developer Brandon Copley who has amassed a database of 2.5 million phone numbers.

Despite having brought the issue to Facebook’s attention, Copley found that the social network preferred to brush the problem off as just a feature within Facebook that’s actually public information. If you do a quick Graph Search for individual phone numbers, granted that the user has set their profile to public and included their phone number, Graph Search will spit out the names of Facebook users associated with that phone number. 

Recognizing the technicality of scraping Graph Search for phone numbers (and email addresses), Facebook told TechCrunch, “Your privacy settings govern who can find you with search using the contact info you have provided, such as your email address and phone number. You can modify these settings at any time from the Privacy Settings page.” There’s not much indication of Facebook’s willingness to patch up that loophole, it seems.

Since Facebook wasn’t going to be working on fixing the security flaw within Graph Search, Copley took matters into his own hands. He scraped 2.5 million phone numbers, apparently to prove a point, and presented the evidence to Facebook. He went as far as testing the limits of his developer account and by searching thousands of phone numbers on a daily basis, bumping this up to millions of searches using the “API token of an app that isn’t rate-limited,” until his account was consequently banned by Facebook numerous times.

Then noticing what was happening, Facebook’s lawyers sprung into action with a cease and desist letter claiming that Copley was “unlawfully acquiring Facebook user data” without permission. What its lawyers were reportedly sniffing around for included the method and script itself for how Copley was scraping Facebook’s database, and with whom he’s shared this knowledge with. Understandably Facebook may have reasons to be concerned about the safety of its users considering that Copley could use his “research” for malicious purposes, but bringing its lawyers into play really makes you question if the collection of personal information is really the non-issue that Facebook initially made it out to be.

Editors' Recommendations

Topics
Francis Bea
Former Digital Trends Contributor
Francis got his first taste of the tech industry in a failed attempt at a startup during his time as a student at the…
Bluesky barrels toward 1 million new sign-ups in a day
Bluesky social media app logo.

Social media app Bluesky has picked nearly a million new users just a day after exiting its invitation-only beta and opening to everyone.

In a post on its main rival -- X (formerly Twitter) -- Bluesky shared a chart showing a sudden boost in usage on the app, which can now be downloaded for free for iPhone and Android devices.

Read more
How to make a GIF from a YouTube video
woman sitting and using laptop

Sometimes, whether you're chatting with friends or posting on social media, words just aren't enough -- you need a GIF to fully convey your feelings. If there's a moment from a YouTube video that you want to snip into a GIF, the good news is that you don't need complex software to so it. There are now a bunch of ways to make a GIF from a YouTube video right in your browser.

If you want to use desktop software like Photoshop to make a GIF, then you'll need to download the YouTube video first before you can start making a GIF. However, if you don't want to go through that bother then there are several ways you can make a GIF right in your browser, without the need to download anything. That's ideal if you're working with a low-specced laptop or on a phone, as all the processing to make the GIF is done in the cloud rather than on your machine. With these options you can make quick and fun GIFs from YouTube videos in just a few minutes.
Use GIFs.com for great customization
Step 1: Find the YouTube video that you want to turn into a GIF (perhaps a NASA archive?) and copy its URL.

Read more
I paid Meta to ‘verify’ me — here’s what actually happened
An Instagram profile on an iPhone.

In the fall of 2023 I decided to do a little experiment in the height of the “blue check” hysteria. Twitter had shifted from verifying accounts based (more or less) on merit or importance and instead would let users pay for a blue checkmark. That obviously went (and still goes) badly. Meanwhile, Meta opened its own verification service earlier in the year, called Meta Verified.

Mostly aimed at “creators,” Meta Verified costs $15 a month and helps you “establish your account authenticity and help[s] your community know it’s the real us with a verified badge." It also gives you “proactive account protection” to help fight impersonation by (in part) requiring you to use two-factor authentication. You’ll also get direct account support “from a real person,” and exclusive features like stickers and stars.

Read more