Facebook Uses Two-Factor Authentication Phone Numbers to Help Users Find You

(Image credit: Vizilla/Shutterstock)

Facebook's promises are getting harder and harder to believe. Despite telling people that phone numbers used for two-factor authentication (2FA) wouldn't be used for anything else, it's been revealed that the company also uses those numbers to help Facebook users find people's accounts, and there's no way to prevent that process.

We already knew that Facebook had lied about only using phone numbers gathered via 2FA setup for security purposes: researchers discovered in September 2018 that Facebook used those numbers to inform targeted advertisements. This wasn't disclosed to users.

But the ability to find someone's Facebook account with their phone number was only publicized Friday by Jeremy Burge, chief emoji officer at Emojipedia, an emoji reference website. He explained in a series of tweets that Facebook lets its users decide if their phone numbers can be used this way by everyone, friends of friends, or friends. There's no opting out.

Worse still is the fact that this option is set to "everyone" by default. At this point, it's not clear how Facebook's decision to stop using phone numbers in its search results benefited users, since this new feature essentially does the same thing. 

Facebook also apparently shares numbers used for 2FA with its other services. Burge shared a screenshot of Instagram, which Facebook owns, asking him to confirm a phone number that he only shared with Facebook to set up 2FA on an account. Numbers are also shared with WhatsApp, another Facebook property, the whistleblower said.

Plus, Facebook's reportedly looking to merge the back-end of all these services.

Want to comment on this story? Let us know what you think in the Tom's Hardware Forums.

TOPICS
Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

Latest in Social Media
Attackers Could Have Made Private TikTok Videos Public
Myspace Lost 13 Years Worth of Data and Basically Nobody Cared
U.S. Visitors, Immigrants Could Be Required To Reveal Social Media Identities
Myspace Security Flaw Allows For Easy Account Takeover (Yes, Myspace)
Privately Offers Users Control Over Social Media Sharing
The “Snappening” Proves Self-Destructing Messages Are Not That Secure
Latest in News
Inspur
US expands China trade blacklist, closes susidiary loopholes
WireView Pro 90 degrees
Thermal Grizzly's WireView Pro GPU power measuring utility gets a 90-degree adapter revision
Qualcomm
Qualcomm launches global antitrust campaign against Arm — accuses Arm of restricting access to technology
Nvidia Ada Lovelace and GeForce RTX 40-Series
Analyst claims Nvidia's gaming GPUs could use Intel Foundry's 18A node in the future
Core Ultra 200S CPU
An Arrow Lake refresh may still be in the cards with only K and KF models, claims leaker
RX 9070 XT Sapphire
Lisa Su says Radeon RX 9070-series GPU sales are 10X higher than its predecessors — for the first week of availability