Skip to main content

Facebook’s Graph Search flaw exposes names with phone numbers

facebook security

Email address collection using Facebook has been a problem that we’ve encountered before when hackers were selling email addresses by the millions. Recently a similar issue – this time having to do specifically with phone numbers – has popped up again by way of Texan mobile developer Brandon Copley who has amassed a database of 2.5 million phone numbers.

Despite having brought the issue to Facebook’s attention, Copley found that the social network preferred to brush the problem off as just a feature within Facebook that’s actually public information. If you do a quick Graph Search for individual phone numbers, granted that the user has set their profile to public and included their phone number, Graph Search will spit out the names of Facebook users associated with that phone number. 

Recognizing the technicality of scraping Graph Search for phone numbers (and email addresses), Facebook told TechCrunch, “Your privacy settings govern who can find you with search using the contact info you have provided, such as your email address and phone number. You can modify these settings at any time from the Privacy Settings page.” There’s not much indication of Facebook’s willingness to patch up that loophole, it seems.

Since Facebook wasn’t going to be working on fixing the security flaw within Graph Search, Copley took matters into his own hands. He scraped 2.5 million phone numbers, apparently to prove a point, and presented the evidence to Facebook. He went as far as testing the limits of his developer account and by searching thousands of phone numbers on a daily basis, bumping this up to millions of searches using the “API token of an app that isn’t rate-limited,” until his account was consequently banned by Facebook numerous times.

Then noticing what was happening, Facebook’s lawyers sprung into action with a cease and desist letter claiming that Copley was “unlawfully acquiring Facebook user data” without permission. What its lawyers were reportedly sniffing around for included the method and script itself for how Copley was scraping Facebook’s database, and with whom he’s shared this knowledge with. Understandably Facebook may have reasons to be concerned about the safety of its users considering that Copley could use his “research” for malicious purposes, but bringing its lawyers into play really makes you question if the collection of personal information is really the non-issue that Facebook initially made it out to be.

Topics
Francis Bea
Former Digital Trends Contributor
Francis got his first taste of the tech industry in a failed attempt at a startup during his time as a student at the…
Twitter CEO claims platform had best day last week
A stylized composite of the Twitter logo.

Twitter CEO Linda Yaccarino tweeted on Monday that despite the current fuss over Meta’s new and very similar Threads app, Twitter had its largest usage day last week.

Subtly including the name of Meta’s new app, which launched to great fanfare last Wednesday, Yaccarino did her best to sing Twitter’s praises, tweeting: “Don’t want to leave you hanging by a thread … but Twitter, you really outdid yourselves! Last week we had our largest usage day since February. There’s only ONE Twitter. You know it. I know it.”

Read more
Meta brings cartoon avatars to video calls on Instagram and Messenger
Meta's cartoon avatars for Instagram and Messenger.

The pandemic was supposed to have made us all comfortable with video calls, but many folks still don’t particularly enjoy the process.

Having to think about what to wear, or how our hair looks, or even fretting about puffy eyes following another bout of hay fever can sometimes be a bit much, even more so if it’s an early-morning call and your brain is still in bed.

Read more
Twitter is now giving money to some of its creators
A lot of white Twitter logos against a blue background.

Some Twitter users are now earning money via ads in the replies to their tweets.

New Twitter owner Elon Musk announced the revenue-sharing program in February, and on Thursday some of those involved have been sharing details of their first payments.

Read more