Skip to main content

Facebook finally hides your phone number … after exposing it for nine months

facebook evilIf you’ve used Facebook on your mobile phone before, then you probably have also used at least one mobile app that requires access to your email address.  The only problem is, there’s a bug that causes Facebook to return your 10-digit phone number instead, and it took a solid nine months before the team finally decided to resolve the privacy breach.

A report of the phone number issue was brought to Facebook’s attention as early as June of last year and was posted on the developer site, where it was immediately confirmed as a bug.  According to the report, instead of receiving the expected properly formatted user’s email address via the graph API, at least one of a thousand queries return a 10-digit phone number.

Recommended Videos

Other app developers have actually experienced a higher frequency of this bug.  The American Legacy Foundation, the non-profit org behind Ubiquitous, reported that they were retrieving one phone number for every 200 queries.

Though the bug is now completely patched, there really is no way to know if app developers who’ve encountered this bug in the past actually used the information exposure to their advantage by calling up users on their phones (or harvesting and selling that information to phone list services).  The fact that the social networking site twiddled its thumbs for nine months while this bug remained unresolved gives privacy die-hards more reason to believe that Facebook, rather than help you protect your personal information, is secretly selling it to the highest bidder.

facebook-graph-search
Image used with permission by copyright holder

Graph Search, Facebook’s latest feature that lets users search their friends’ data using simple, specific phrases (like ‘photos my friends took in New York City’), is apparently also a potential threat to users’ privacy.  Here’s to hoping that Facebook watches this new tool’s activity like a hawk before it gets out of control (like, before “frenemies” in your circle sift through your old posts using cleverly phrased queries and find out details about your life you thought were safely under the radar).

[UPDATE]

Looks like there’s more to this story that we didn’t know.  The report we read as basis for this article had some of the details wrong, so we’d like to apologize and issue this correction:

According to Fred Wolens, Facebook Policy Communications, any FB user could sign up to Facebook with either an email address or a phone number, and if that user decided to not give an email address, “in keeping with the users privacy we provided the phone number since this was the piece of registrant information used”. Also, users are given ample warning by applications before sharing personal information, and in the case of giving out a phone number, it may be called an email address (in the absence of one). The real bug is the mislabeling of the API call, calling a phone number an email address. It has been corrected.

Jam Kotenko
Former Digital Trends Contributor
When she's not busy watching movies and TV shows or traveling to new places, Jam is probably on Facebook. Or Twitter. Or…
I paid Meta to ‘verify’ me — here’s what actually happened
An Instagram profile on an iPhone.

In the fall of 2023 I decided to do a little experiment in the height of the “blue check” hysteria. Twitter had shifted from verifying accounts based (more or less) on merit or importance and instead would let users pay for a blue checkmark. That obviously went (and still goes) badly. Meanwhile, Meta opened its own verification service earlier in the year, called Meta Verified.

Mostly aimed at “creators,” Meta Verified costs $15 a month and helps you “establish your account authenticity and help[s] your community know it’s the real us with a verified badge." It also gives you “proactive account protection” to help fight impersonation by (in part) requiring you to use two-factor authentication. You’ll also get direct account support “from a real person,” and exclusive features like stickers and stars.

Read more
Here’s how to delete your YouTube account on any device
How to delete your YouTube account

Wanting to get out of the YouTube business? If you want to delete your YouTube account, all you need to do is go to your YouTube Studio page, go to the Advanced Settings, and follow the section that will guide you to permanently delete your account. If you need help with these steps, or want to do so on a platform that isn't your computer, you can follow the steps below.

Note that the following steps will delete your YouTube channel, not your associated Google account.

Read more
How to download Instagram photos for free
Instagram app running on the Samsung Galaxy Z Flip 5.

Instagram is amazing, and many of us use it as a record of our lives — uploading the best bits of our trips, adventures, and notable moments. But sometimes you can lose the original files of those moments, leaving the Instagram copy as the only available one . While you may be happy to leave it up there, it's a lot more convenient to have another version of it downloaded onto your phone or computer. While downloading directly from Instagram can be tricky, there are ways around it. Here are a few easy ways to download Instagram photos.

Read more