Skip to main content

Facebook finally hides your phone number … after exposing it for nine months

facebook evilIf you’ve used Facebook on your mobile phone before, then you probably have also used at least one mobile app that requires access to your email address.  The only problem is, there’s a bug that causes Facebook to return your 10-digit phone number instead, and it took a solid nine months before the team finally decided to resolve the privacy breach.

A report of the phone number issue was brought to Facebook’s attention as early as June of last year and was posted on the developer site, where it was immediately confirmed as a bug.  According to the report, instead of receiving the expected properly formatted user’s email address via the graph API, at least one of a thousand queries return a 10-digit phone number.

Other app developers have actually experienced a higher frequency of this bug.  The American Legacy Foundation, the non-profit org behind Ubiquitous, reported that they were retrieving one phone number for every 200 queries.

Though the bug is now completely patched, there really is no way to know if app developers who’ve encountered this bug in the past actually used the information exposure to their advantage by calling up users on their phones (or harvesting and selling that information to phone list services).  The fact that the social networking site twiddled its thumbs for nine months while this bug remained unresolved gives privacy die-hards more reason to believe that Facebook, rather than help you protect your personal information, is secretly selling it to the highest bidder.

facebook-graph-search
Image used with permission by copyright holder

Graph Search, Facebook’s latest feature that lets users search their friends’ data using simple, specific phrases (like ‘photos my friends took in New York City’), is apparently also a potential threat to users’ privacy.  Here’s to hoping that Facebook watches this new tool’s activity like a hawk before it gets out of control (like, before “frenemies” in your circle sift through your old posts using cleverly phrased queries and find out details about your life you thought were safely under the radar).

[UPDATE]

Looks like there’s more to this story that we didn’t know.  The report we read as basis for this article had some of the details wrong, so we’d like to apologize and issue this correction:

According to Fred Wolens, Facebook Policy Communications, any FB user could sign up to Facebook with either an email address or a phone number, and if that user decided to not give an email address, “in keeping with the users privacy we provided the phone number since this was the piece of registrant information used”. Also, users are given ample warning by applications before sharing personal information, and in the case of giving out a phone number, it may be called an email address (in the absence of one). The real bug is the mislabeling of the API call, calling a phone number an email address. It has been corrected.

Editors' Recommendations

Jam Kotenko
Former Digital Trends Contributor
When she's not busy watching movies and TV shows or traveling to new places, Jam is probably on Facebook. Or Twitter. Or…
Facebook will protect your data — as long as no one’s paying them for it
Facebook CEO Mark Zuckerberg speaking on a panel at the Paley Center for Media

At a Capitol Hill hearing Tuesday — no, not the one with the impeachment and such — Sen. Dick Durbin (D-Illinois) asked Jay Sullivan, Facebook’s product management director for privacy and integrity in Messenger, whether Facebook collected any data from its Messenger Kids app. It was the exact same question, Durbin said, that he had posed to Mark Zuckerberg last year, when he received an answer he deemed unsatisfactory.

“I have significant concerns that the data gathered by this app might be used or sold,” Durbin told Sullivan. “[Zuckerberg] responded, ‘in general, that data is not going to be shared with third parties.’ I said his use of that terms was ‘provocative and worrisome.'” Durbin then asked Sullivan the same question. “Is your answer that there is no information collected via Messenger Kids that is shared by Facebook to any third parties?”

Read more
Millions of phone numbers linked to Facebook found in exposed database
facebook-logo-blue

Millions of phone numbers associated with Facebook accounts have been discovered in an exposed database.

A server that wasn’t protected by a password was found to contain over 419 million records from Facebook users worldwide: 133 million U.S. records, 18 million U.K. records, and more than 50 million records from Vietnam, TechCrunch reports.

Read more
Facebook admits it was listening to your private conversations, too
Facebook Pages

Facebook outsourced contractors to listen in on your audio messenger chats and transcribe them, a new report reveals. 

Bloomberg reports that the contractors were not told why they were listening in or why they were transcribing them. Facebook confirmed the reports but said they are no longer transcribing audio. 

Read more