Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> changes last year to remove people’s ability to find others using their phone numbers.

What? That's not true, I reported the issue about user enumeration via phone numbers being possible in Whatsapp, Messenger and Instagram to them last week and they claimed (paraphrased) "it's a feature, not a security issue".



Do you intend to publish this correspondence? I think some companies prefer to sue people using these "features" instead of changing them. It's a good thing to have on record.


There's not much to publish. It is just me saying that a custom contact book allows finding out a lot of people's accounts, them saying that the behavior respects people's settings and is working as intended.


They removed "people's" ability, but not their own.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: