Live data from Hacker News

LinkedIn violated data protection by using 18M email addresses of non-members

techcrunch.com

141–150 of 151 posts

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#141

> What we also don’t really know here — the DPC doesn’t really address it — is where LinkedIn obtained those 18 million email addresses, and any other related data, in the first place. Well, one such source of email addresses was me. When I joined it more than 10 years ago, I was not as privacy aware as I am today. So, upon joining, I uploaded my address book to connect to people who already had a LinkedIn account. I…

It only takes one person in your entire contact list to upload their entire contact list, so that your information gets uploaded to Linkedin/Facebook/Google, etc. It's almost impossible to assert that level of control, so my assumption is that my details including my birthday, address, phone number, place of work, etc, has already been uploaded to all of those service. It's infuriating, but it's a reality since I can't stop one of my contacts from uploading my data.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#142

Earlier quoted context omitted.

Despite all of this bullshit, LinkedIn can be a good tool for finding opportunities if used correctly. You just need to make sure your privacy settings are bulletproof and don’t give out more information than they need to.

That's the thing, I don't know if I can trust their privacy settings.

True, but at least you can begin with making sure trusted privacy settings (the ones provided by your OS) are set correctly.

You can also not install their app and use their website in a browser with an ad blocker and in private browsing mode.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#143

Earlier quoted context omitted.

First thing I do when I click on a link on LinkedIn is to open the context/share menu and press “open in Safari”. Hopefully if enough people do this it will make it clear in their analytics that nobody wants their shitty knockoff browser. The worst is that it’s using deprecated APIs on iOS that make it several times slower than Safari.

It’s still using UIWebView?!

It's a lot slower so I assume so. It's definitely not a Safari View Controller.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#144

Earlier quoted context omitted.

Given that they have been owned by Microsoft for quite some time, how much of their current practice is learned vs inherited? If the latter, why would Microsoft allow this practice to go on?

For a few reasons: It takes time to go through all user stories in such a big application. Imagine rewriting all unit tests. When you take over a big operation, you usually don't want to rock the boat more than you are already doing.

They also might have not done due diligence, underestimated what a liability this data would become, or underestimated how long it would take to rewrite it. (E.g. GDPR was only adopted a few months before the announcement of the aquisition, and didn't come into force until two years later.)

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#145
I'm constantly alarmed by the recommended matches on LinkedIn. I'm also torn by the business community's insistence that this site is a necessary part of networking and any of its practices are therefore beyond scrutiny.

And no, you did not match me to my second cousin "based on my profile." Unless you mean "based on your email address, which is already included in the massive social graph of all address book connections we've harvested from people who know you."

If you have to mislead your users about how you're finding potential connections, maybe you shouldn't be doing that thing in the background, or maybe you shouldn't be so focused on aggressively pushing those connections.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#146

Now I know why I was getting messages from these pricks. I tried to login and had no account. Scum.

I confirm Linkedin is a vector for spam, the way they handle and publish your email address: I use a dedicated, unique email address for my account, and systematically start receiving unsollicited emails and spam a few days after. I now have the habit to register a new email address every few months on Linkedin, to track the issue. It's clear and easy to prove that the new email address is used by spammers after a sh…

> One of the main reasons is probably because once you are connected to someone, he/she can access your profile contact details including email and phone number. My guess is there are bots scraping the contacts to populate their spam databases.

I'd expect this is the case; I have a LinkedIn account with a dedicated email for name reservations purposes, but do not accept any connections, and have yet to receive any spam.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#147
post #58

Earlier quoted context omitted.

You have to wonder where the ethics are on the ground level. I understand that these decisions are made by management in virtually every case, but you still see these kind of dark patterns from places where every engineer is on $100k+ with plenty of leverage against their employer.

Every UX specialist and software engineer I know would be up in arms if they saw such a story in the backlog. I wonder about the internal dynamics of these work places as well.

People will do just about anything if they are told they are "saving the world". Silicon Valley and its... companies.. fully believe they are God's gift to the planet. Pretty much anything can be subverted to such a point of view.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#148

Earlier quoted context omitted.

Maybe LinkedIn matched you by geolocation? That would be closely related to sharing the same IP address or Wi-Fi network.

A lot of first pass geolocation is done by IP so the user doesn't have to be asked for permission.

No post body was provided.

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#149
post #54

Earlier quoted context omitted.

I regularly see YouTube recommendations for the stuff my bf is watching and we don't share a computer and he is not logged in to YouTube.

First time I hear about this. This would be very serious. Are you positive there is no other way, the Youtube recommendation algorithm is notoriously weird.

I'm not positive about anything from google because I can't see how it works. All I know is he is on the same network and we see recommendations about stuff the other has watched

Re: LinkedIn violated data protection by using 18M email addresses of non-members

#150

I am 99% sure LinkedIN used my IP address to match with my second floor neighbor, despite their claims that they would never use IP address as a connection data point. I was sharing my wifi for a brief period with my neighbors on the second floor. My neighbor had a new room mate. The guy was from another country. He didn't work in the same industry I do. I didn't have any of his contact information anywhere on any of…

It may be more complex than that. If both of you were tied into the Social Graph it's possible software on your devices simply knew the two of you were in proximity and for how long. This could be done via Bluetooth by an app like WhatsApp or Facebook, which is known to have sensors installed in urban businesses. But who's to say they didn't just turn your device into a beacon itself using the Physical Web?
Post reply on HN