Live data from Hacker News

LinkedIn violated data protection by using 18M email addresses of non-members

techcrunch.com

91–100 of 151 posts

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#91

I am 99% sure LinkedIN used my IP address to match with my second floor neighbor, despite their claims that they would never use IP address as a connection data point. I was sharing my wifi for a brief period with my neighbors on the second floor. My neighbor had a new room mate. The guy was from another country. He didn't work in the same industry I do. I didn't have any of his contact information anywhere on any of…

That's creepy. Different topic: I think the biggest connection business is whatsapp. If a person does not use whatsapp but a friend of that person does, whatsapp knows the person's phone number anyway. If >= 2 whatsapp users have that person's phone number stored with the same name in the contact list, whatsapp even knows the person's name (and other information). With that information they can accurately identify th…

And then you add [1] this - Facebooks ability to access WhatsApps files on iOS from any other app in their “family”.

[1] https://news.ycombinator.com/item?id=18479567

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#92
Of course they did. In an industry full of shady characters, LinkedIn is among the worst. They're proof that dark patterns and other nasty tactics are profitable, and also that if you make enough money, people in the valley will look past how you made it. The fact that Hoffman is enthusiastically welcomed in polite society says something not great about Silicon Valley ethics.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#93

I am 99% sure LinkedIN used my IP address to match with my second floor neighbor, despite their claims that they would never use IP address as a connection data point. I was sharing my wifi for a brief period with my neighbors on the second floor. My neighbor had a new room mate. The guy was from another country. He didn't work in the same industry I do. I didn't have any of his contact information anywhere on any of…

> I am 99% sure LinkedIn used my IP address to match with my second floor neighbor, despite their claims that they would never use IP address as a connection data point.

The way the creepiest connections have been made for me are by search terms. I didn't open a LinkedIn account until a couple years ago, and I was immediately shown the profiles of people who had probably just searched my name on LinkedIn (and not found me) over the previous four or five years, including some random young woman I met in a Starbucks once.

It's possible your neighbour searched your name.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#94
> What we also don’t really know here — the DPC doesn’t really address it — is where LinkedIn obtained those 18 million email addresses, and any other related data, in the first place.

Well, one such source of email addresses was me.

When I joined it more than 10 years ago, I was not as privacy aware as I am today. So, upon joining, I uploaded my address book to connect to people who already had a LinkedIn account.

I shortly after realized that they abused it. They sent an invite email to every person that was not on their platform.

I only got to know about it becasue one of my university professors sent me an email saying that she was not interested in joining yet another network. I had to apologize, because I did not expect that to happen.

To this day, LinkedIn still uses that information to suggest new connections to me and to prompt me to invite people that are still not on their platform.

In retrospect, it was a stupid move to upload my address book, but I'm sure I am not the only one that made that mistake, and probably many people still do nowadays.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#95

> What we also don’t really know here — the DPC doesn’t really address it — is where LinkedIn obtained those 18 million email addresses, and any other related data, in the first place. Well, one such source of email addresses was me. When I joined it more than 10 years ago, I was not as privacy aware as I am today. So, upon joining, I uploaded my address book to connect to people who already had a LinkedIn account. I…

It wasn't stupid of you, not your fault LinkedIn literally impersonated you. The mail it sent out all those years ago was written in your name and as though you had actively crafted and sent it. Anyone who knows your name could have impersonated you. Don't worry about doing something wrong.

A quick google suggests linkedin was sued and reached a class action settlement in exchange for the practice.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#96

> What we also don’t really know here — the DPC doesn’t really address it — is where LinkedIn obtained those 18 million email addresses, and any other related data, in the first place. Well, one such source of email addresses was me. When I joined it more than 10 years ago, I was not as privacy aware as I am today. So, upon joining, I uploaded my address book to connect to people who already had a LinkedIn account. I…

It wasn't stupid of you, not your fault LinkedIn literally impersonated you. The mail it sent out all those years ago was written in your name and as though you had actively crafted and sent it. Anyone who knows your name could have impersonated you. Don't worry about doing something wrong. A quick google suggests linkedin was sued and reached a class action settlement in exchange for the practice.

You can be almost certain that LinkedIn knew it was illegal when they did it, and accurately calculated that the fine they would receive (if any) would be much lower than the value derived from increased membership. In fact they would be stupid not to in winner-takes-all markets like social media.

Silicon Valley has a phrase for such flagrantly unethical practice, it is called "growth hacking".

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#98

Earlier quoted context omitted.

linkedIn was suggesting people that were using the same wifi network as I was. I thought this was spooky — I could see more info about my hotel guests than they probably realized.

LinkedIn definitely uses same IP address to suggest connections. My wife as suggested connection really stood up in this way for many reasons (profile recently created, a few connections from the other side of the world and in a totally different industry).

But you probably have your wife in your contacts.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#99

I naively installed the app on my phone, which gave them my phone number. Then I started getting cold calls from people who paid to have access to my number through LinkedIn. I never entered my number anywhere, however the cold callers repeatedly told me they got my information from LinkedIn.

To be fair, they could just be saying LinkedIn because it's easier than saying they bought the number from some shady middlemen, and people are less likely to react negatively to it. Unless you used a unique number only for LinkedIn, the number could have been shared by anyone (even your telco).
Post reply on HN