Hello, Facebook! Here is the Stalkers’ Paradise! Design and analysis of enumeration attack using phone numbers on Facebook

Jinwoo Kim, Kuyju Kim, Junsung Cho, Hyoungshick Kim, Sebastian Schrittwieser

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

7 Scopus citations

Abstract

We introduce a new privacy issue on Facebook. We were motivated by the Facebook’s search option, which exposes a user profile with his or her phone number. Based on this search option, we developed a method to automatically collect Facebook users’ personal data (e.g., phone number, location and birthday) by enumerating the possibly almost entire phone number range for the target area. To show the feasibility, we launched attacks for targeting the users who live in two specific regions (United States and South Korea) by mimicking real users’ search activities with three sybil accounts. Despite Facebook’s best efforts to stop such attempts from crawling users’ data with several security practices, 214,705 phone numbers were successfully tested and 25,518 actual users’ personal data were obtained within 15 days in California, United States; 215,679 phone numbers were also tested and 56,564 actual users’ personal data were obtained in South Korea. To prevent such attacks, we recommend several practical defense mechanisms.

Original languageEnglish
Title of host publicationInformation Security Practice and Experience - 13th International Conference, ISPEC 2017, Proceedings
EditorsJoseph K. Liu, Pierangela Samarati
PublisherSpringer Verlag
Pages663-677
Number of pages15
ISBN (Print)9783319723587
DOIs
StatePublished - 2017
Event13th International Conference on Information Security Practice and Experience, ISPEC 2017 - Melbourne, Australia
Duration: 13 Dec 201715 Dec 2017

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10701 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference13th International Conference on Information Security Practice and Experience, ISPEC 2017
Country/TerritoryAustralia
CityMelbourne
Period13/12/1715/12/17

Keywords

  • Enumeration attack
  • Facebook
  • Information leakage
  • Privacy
  • User profile

Fingerprint

Dive into the research topics of 'Hello, Facebook! Here is the Stalkers’ Paradise! Design and analysis of enumeration attack using phone numbers on Facebook'. Together they form a unique fingerprint.

Cite this