Facebook has urged users to enable phone number-based 2FA, but the numbers are used in a user lookup feature with no opt out and to target ads, sparking outcry
and you can't opt-out. http://techcrunch.com/... Anil Dash / @anildash : Well put. It's doubly devastating when a major platform betrays user trust, because they not only victimize their own users, they hurt the ability for everyone else to build systems that users can put their trust in. http://twitter.com/... Will Oremus / @willoremus : “We appreciate the feedback we've received about these settings and will take it into account” sounds a bit like “We're tired of apologizing for privacy invasions, so we're gonna just go ahead and invade your privacy without apologizing from now on” Josh Constine / @joshconstine : Facebook requires you to sacrifice liberty for safety, as apparently we deserve neither http://techcrunch.com/... Antonio Garca Martnez / @antoniogm : This is bad. Worse, it's not just bad, it's dumb. The fraction of users that have 2FA enabled must be small, so the usage gain is minimal, while the PR risk is huge. Dumb trade-off. Assuming it wasn't just: team A: writes 2FA #'s to DB team B: oh lookie here new data to use... http://twitter.com/... John Paczkowski / @johnpaczkowski : Wow. Using security concerns to weaken privacy. Awesome. http://twitter.com/... April Doss / @aprilfdoss : This latest news about Facebook privacy practices - that users' phone numbers are searchable, with no opt-out - is likely to drive further scrutiny from regulators. It also underscores the importance of clearly understandable privacy policies and meaningful user choice. http://twitter.com/... Jeremy Burge / @jeremyburge : Facebook now defaults phone number search to “everyone”. Unless you change this setting, anyone with your phone number can look up and confirm your Facebook profile. Here's where to change it (and no you can't turn it off altogether if using for 2FA) https://www.facebook.com/... pic.twitter.com/PUItHuFZmI Zeynep Tufekci / @zeynep : See thread! Using security to further weaken privacy is a lousy move—especially since phone numbers can be hijacked to weaken security. Putting people at risk. What say you @facebook? http://twitter.com/... Jeremy Burge / @jeremyburge : The original FB phone number prompt never mentioned “and more”. It was shown for MONTHS before a link was added in September 2018 clarifying “actually we'll use this wherever we damn well please” pic.twitter.com/FcOTIZdVf5 Anil Dash / @anildash : Abusing a security feature like this in a way that makes people vulnerable to targeting & surveillance is unconscionable. Unbelievable thread. http://twitter.com/... Jeremy Burge / @jeremyburge : My personal Instagram account isn't linked to my Facebook. But I am the admin of a page on Facebook which now *requires* 2FA and mobile phone numbers (as of 2018). Here's Instagram ~days~ after giving my phone number to Facebook (for 2FA only) pic.twitter.com/ul9wXWMaoH Greg Greene / @ggreeneva : For years people have been urged — especially in high-value-target industries such as mine, politics — to use two-factor authentication to secure themselves. Now we find that FB co-opted that advice to harvest another data point that helps it sell ads. http://twitter.com/... Jeremy Burge / @jeremyburge : Using a phone number to sign up for services has been the single greatest coup for the social media and advertising industries. One unique ID that is used to link your identity across every platform on the internet. That is why every startup wants your phone number. Jeremy Burge / @jeremyburge : TL;DR: Login-with-Phone-Number is the new Login-with-Facebook. Easy to track, shared between services, it's the key to invisible mesh of your data. Don't do it. Ryan Ford / @theryanford : It's so underhanded. “Give us a number to secure your account.” Okay here you go “Cool so we're going to use this for ads and make everybody able to look you up with it too. Also security, I guess.” No that's not what you said “Sorry can't hear you la la la la la” http://twitter.com/... @jason : Shocked to hear that #zuckerberg and @facebook are still screwing their users at every possible juncture. http://twitter.com/... Jane Ruffino / @janeruffino : Another problem with using phone numbers as IDs is something you end up owning as a #uxwriter. Your error messages can't tell users an ID is taken or you make it possible for anyone motivated to find out who is using your service. http://twitter.com/... @msuiche : Another reason why everyone should have a burner phone just for public/internet services. We all have multiple emails, computers etc - So why carrying only one single phone number of years like it is a social security number? Think Segmentation. http://twitter.com/... Privacy Matters / @privacymatters : Another key issue of using phone numbers as an ID is the disassociation of the ID from the number. For example, mobile carriers in a country may not have a consistent policy or practice wrt to mobile number recycling. This is but one issue. http://twitter.com/... Immo Landwerth / @terrajobst : That's another reason why 2FA via SMS just sucks. http://twitter.com/... James Ball / @jamesrbuk : As others have flagged, this is Facebook undermining privacy (and potentially putting vulnerable users at risk) for no good reason - for something it encourages users to share for security. Appalling corporate behaviour. Again. http://twitter.com/... @iyad_elbaghdadi : Ok. How do I delete *all* my data on Facebook? Not just remove my account, but ensure that none of my data remains with Facebook... http://twitter.com/... Jeremy Burge / @jeremyburge : *Not* giving your phone number to FB is a borderline pointless: they have it anyway. If any of your friends accepts to Messenger or WhatsApp accessing their contacts, Facebook knows your number, no matter what you do pic.twitter.com/0t0omI747I
Context & Ripple Effects
Facebook spent years making the phone number a core identity key: since Android apps could skip SMS verification by matching a number to a Facebook profile, the company has treated the phone number as verified, portable data. Now it is urging users to hand over that number for two-factor authentication — while running it through an ad-targeting system and a user-lookup feature with no opt-out.
The outcry lands on a platform already fighting a trust deficit. Anil Dash's widely shared reaction frames the stakes beyond Facebook itself: every betrayal by a major platform makes users warier of the next service asking for their data.
First-order effects
- Users who enabled 2FA as a security measure discover their phone numbers are simultaneously serving Facebook's ad-targeting engine and its people-search — a consent problem, since no opt-out exists.
- Facebook's own security messaging is undercut: the same channel it recommends for account protection is exposed to lookup and scraping, which matters given how phone-linked data has leaked before.
Second-order effects
- Security-conscious users and enterprises get another reason to steer clear of SMS-based 2FA toward authenticator apps, weakening the phone number's role as a universal login credential — a direction Facebook itself later moved when Messenger dropped phone-number signup in favor of Facebook accounts.
- Rival platforms face pressure to publish explicit purpose-limitation promises for security data, turning 'we won't use your 2FA number for ads' into a competitive differentiator.
Third-order effects
- The episode sharpens the structural conflict in ad-funded platforms: the team selling user trust (security) reports into a business model monetizing the same data, so purpose limitation becomes a regulatory question rather than a design choice.
- If the pattern holds, phone-number-based identity loses credibility as infrastructure — foreshadowing incidents like the unsecured database of 419M+ phone numbers linked to Facebook accounts that made number-as-identity look like a liability, not an asset.
The trend: Platform security features are doubling as data-collection surfaces, eroding phone-number-based identity just as regulators and users start demanding purpose limits on credentials.