Lessons from Snapchat: Using phone numbers for IMs will always be risky
While the Snapchat data breach came as bad news for users, what many may not have realised is that the really scary part was that mobile numbers of users were breached.


The Snapchat logo is seen in this file photo. AFP[/caption]Stephen Wilson, a digital identity expert and Founder and Principal of Lockstep Consulting, explains in his blog on the Snapchat breach that such cybercriminals patiently acquire multiple data sets over many months, sometimes years, and then gradually piecing together detailed personal profiles. These data sets could include your user name, e-mail address, real name, etc.Piecing together or re-identification is enabled by linking diverse data sets. As Wilson explains, "E-mail addresses and phone numbers are superbly valuable indices for correlating an individual's various records. Your e-mail address is common across most of your social media registrations. And your phone number allows your real name and street address to be looked up from reverse White Pages. So the Snapchat breach could be used to join aliases or e-mail addresses to real names and addresses via the phone numbers. For a social engineering attack on a call centre -- or even to open a new bank account -- an identity thief can go an awful long way with real name, street address, e-mail address and phone number." Wilson goes on to say that he believes that phone numbers are most valuable to the highly organised ID thief, for they can be used to index names in public directories, and to link different data sets, in ways that social security numbers or credit card numbers cannot.Does that sound scary? It should. Because when you call up your mobile service provider or your bank's call centre, often all you need to provide are your birth date and your address. That also explains how the gang busted in New Delhi went about wiping out bank accounts and making a mockery of the Reserve Bank of India's SMS alerts recommendation by ensuring that even the victim's cellphone SIM has been deactivated or a new SIM issued based on a fake ID they had forged. There are more cases of a similar kind emerging in India.If you think Wilson's concerns are only relevant to the West where technology usage is far deeper, you couldn't be more wrong. With projects like Aadhaar, the Indian government now has deep digital databases of Indian citizens and as a report in The Times of India today reveals, the situation is perhaps scarier in India than in other parts of the world. While the government may be focused on keeping Aadhaar data safe and may have failed even in that, the report reveals that various government agencies have put vast amounts of information on individuals online, that literally anyone could access quite easily. So, you could get lots of details from websites of energy companies supplying LPG for household use, from government-run telecom providers like MTNL, the Election Commission, etc. For a cybercriminal, some of these Indian websites would be a rich hunting ground.Re-identification based on linking multiple data sets is not a new concern, as Dr Latanya Sweeney's research has proved. Dr Sweeny is Professor of Government and Technology in Residence at Harvard University and the Director of the Data Privacy Lab at Harvard. Her first contribution involved linking de-identified patient-specific medical data to a population register (a voter list, for instance) to re-identify patients by name. She then showed that 87 percent of the US population can be uniquely identified by date of birth, gender and ZIP code. Her site Aboutmyinfo.org, tells people living in the US how unique their demographics may be, and therefore how easy it is to identify them from these values. For instance, I tried using my birth date, gender and a ZIP code in Sunnyvale, California and to my shock no one else from among the nearly 46000 people living in that area shared my birth date.Should users then ditch mobile instant messengers like WhatsApp and Snapchat which leverage mobile numbers? That's no easy task, because on the flip side, using mobile numbers also makes discovery of friends far simpler. Perhaps the answer lies in what Snapchat is now planning, an option where users can opt of the Find Friends feature that uses mobile numbers. But for platforms like WhatsApp, which only use mobile numbers the danger continues to exist. And it could only be a matter of time before the ease-of-use argument touted by WhatsApp proponents over secure mobile instant messengers like BlackBerry Messenger (BBM), comes to bite them on their backsides.
@IvorSoans on Twitter

Key differences between third party, comprehensive & zero depreciation bike insurance coverage
These lucky members played the CRED bounty and won massive prizes, including Rs 1.5 lakh cash, a PS5, and more: Here’s how you can win as well!
Tech Goes Bold with the New Age Baleno: Everything A Hatchback Wants To Be
How saving water will save our future
‘Dune’ Is A Visual Extravaganza Tied With Spellbinding Performances That You Just Can’t Afford To Miss
