Live data from Hacker News

New LinkedIn Data Leak Leaves 700M Users Exposed

restoreprivacy.com

61–70 of 153 posts

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#61
post #22

Earlier quoted context omitted.

I have no problem with people accessing my data, but only so long as it's people who have a valid reason to access that data. In the case of LinkedIn, I don't mind my connections, coworkers, and (reluctantly) recruiters seeing what's on my resume. I do mind a random hacker accessing that information, selling it to anyone who'll buy, and those people then using that data for things that probably aren't related to offe…

How do you know someone accessing your data through the Web site is a recruiter?

I look their details up in this spreadsheet of 700 million people I've got.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#62
post #8

Where are all the folks who were complaining about the LinkedIn anti-scraping court case destroying the open web? This is what LinkedIn is fighting against.

Scraping the open web is NOT the same as accessing privileged APIs to collect private information. If LinkedIn made their pages accessible to anyone as a sort of public service (as they used to), people would think twice what data to put on there.

The problem is the same as with Facebook: they pretend the data is private and secure, then let people siphon it away. Public and private networks are both fine, but huge corporations trying to mix both usually end up with the worst of both worlds.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#63
Not surprising really.

A few years back Hotmail/Outlook were returning people's Twitter/LinkedIn handles for emails sent/received. It had been noticed you could scrape that fairly easily at scale. With one email account you could check up to 30000 email addresses before being flagged by Outlook.

Slightly longer ago you could simply iterate 1...n on LinkedIn URLs to find someone's profile, by converting the number to base12, you'd be redirected to the person's public URL.

Also their bulk contact upload. Take any data leak of email addresses, bulk upload them as contacts and then correlate email addresses to social profiles.

Facebook, Twitter and LinkedIn are all bad in that regard on the last method, though Facebook at least do not return people's URLs along with your contact upload (you're expected to know the person's face/name to decide whether you'd want to connect). The take away is that once you sign up, whatever information you put on your profile/account is pretty much available to anyone who wants it enough - and clearly there are plenty bad actors who want it. Obviously these social networks want to expand their network, but they also make it much more easy for data harvesting at unprecedented scale.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#68

FWIW, I've been scrubbing my social profiles. LinkedIn, Yelp, Facebook, etc. Barest of bones. Removing all connections, photos, posts, personal details. (I know the damage is already done. The aggregators never really delete anything.) Why not just out right delete my profiles? I'm squatting. To ensure they're not used as socket puppets. After a beloved coworker passed, their profile got highjacked. Ten years later,…

I’ve been doing the same. The potential downside risk of having LinkedIn/Facebook/Instagram profiles just keeps growing and growing. I’m a complete ghost on the Internet. I have Google alerts set up for my names and email addresses, and I regularly attempt to docs myself to find any leaks. I also can’t understand why anyone in the public eye doesn’t completely sanitise their social media profiles. The amount of people brought down by 10 year old stupid tweets is insane.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#69
This is just basically the data that's publicly available anyway unless you've locked down your profile. That sort of defeats the purpose of LinkedIn though since you're trying to get people to contact you about jobs etc.

I wish LinkedIn would just go away, it's turning less into a job specific site and more of another facebook full of idiotic political posts etc. I'd rather not have to deal with it at all but it seems employers still sort of expect you to use it.

Post reply on HN