Facebook Uses Two-Factor Phone Numbers for Profile Lookups Without Opt-Out

Facebook faces backlash for using phone numbers provided for two-factor authentication to let anyone look up user profiles, with no option to completely disable the feature. Critics warn this practice sacrifices user privacy under the guise of security.

Facebook users express outrage as they discover that phone numbers provided for two-factor authentication serve a second purpose as searchable profile identifiers. Anyone with or without a Facebook account can use these numbers to find user profiles, and the social network does not offer a way to completely opt out of this feature. This controversy gains traction after a viral tweet highlights how Facebook treats security phone numbers as unique identifiers linked across the internet.

The situation worsens because hiding a phone number on a user's profile does not prevent people from finding the account through other methods, such as syncing mobile contacts. Facebook allows users to restrict who can look up their profile using their phone number to "friends" or "friends of friends," but the company refuses to provide a strict "no one" option. This default behavior follows last year's admission that Facebook used these same security numbers to target users with advertisements.

Security experts strongly criticize this practice, noting that it forces users to sacrifice their privacy for the sake of account security. Experts point out that phone numbers are vulnerable to SIM swapping attacks, meaning a feature designed to protect accounts actually creates a new avenue for hackers to locate and target users. Critics argue that a phone number given solely for security should never double as a public search key.

Read More at the original source →