Live data from Hacker News

New LinkedIn Data Leak Leaves 700M Users Exposed

restoreprivacy.com

121–130 of 153 posts

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#121

FWIW, I've been scrubbing my social profiles. LinkedIn, Yelp, Facebook, etc. Barest of bones. Removing all connections, photos, posts, personal details. (I know the damage is already done. The aggregators never really delete anything.) Why not just out right delete my profiles? I'm squatting. To ensure they're not used as socket puppets. After a beloved coworker passed, their profile got highjacked. Ten years later,…

I would do this, but my data has been up in social media long enough that I don't believe it makes a significant difference if I superficially "delete" it now. Maybe I'm wrong?

At this point, I just don't add anything new. If they're going to host my content ad infinitum, I might as well use their storage space and bandwidth.

I guess it probably would be worth ditching LinkedIn. There's no good reason why a [worthwhile] prospective employer would require it.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#122
Many of you may not know, But most recently, even Domino's Pizza (India) had a breach and they kept denying it ever happened until the hackers finally made a search engine where anyone could search through the entire database. And Domino's finally released some statement in some obscure part of their website. NONE of the users who were affected were notified directly. Many even don't know that this happened. What's worse is the data contained your precise house location and location data in general with co-ordinates. So, the hackers know your phone, your address, where you live, where you go to, been to and how much you're actually worth. It has been claimed financial data (credit cards) were stolen as well, but Domino's denies it till date and of course no one should trust them, given their history.

So, in essence, this LinkedIn breach is also the same to me. Companies literally make you an attack target for hackers and don't even bother telling you. I don't know about you guys, I haven't received a single email from LinkedIn about this yet. How can we combat this dangerous behaviour of companies hiding their incompetencies from their customers? I thought of litigation and I almost sued Domino's, but who am I kidding? These cases could go on for years while they keep making people attack targets of hackers. And add to that corruption, and other variables. I don't know of what could be done to such companies. Boycotting helps, but imagine, more than half your customers don't know why the rest are boycotting and that's in your favor.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#124

Is this a "real" leak or "just" scraped profiles?

Looks like scraped with additional data from other sources. Linkedin doesn't have your Facebook account, but it included in the database sample

Augmented data!

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#125

FWIW, I've been scrubbing my social profiles. LinkedIn, Yelp, Facebook, etc. Barest of bones. Removing all connections, photos, posts, personal details. (I know the damage is already done. The aggregators never really delete anything.) Why not just out right delete my profiles? I'm squatting. To ensure they're not used as socket puppets. After a beloved coworker passed, their profile got highjacked. Ten years later,…

This. The best way to erase social media is to replace the account with a bunch of BS. Most of these companies are too cheap and Zucker's "move fast" culture probably doesn't involve database record versioning. Also because it's expensive. The old SET _deleted_=1 is pretty much their main ace in the hole to f*k you. Hell, even if they do versioning, just keep filling the profiles with enough noise and they won't be able to filter it all out unless they somehow index and data warehouse your profile from the decrepit old backup. At that point, you are just hoping their schema changes, the logistics, and their bad practices are enough to prevent that from being cost efficient.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#126
The biggest issue: you cannot not give them your personal data that they then loose.

Let me contribute with an anecdote from yesterday (slightly off-topic but I promise to get around to it at the end). So just yesterday I needed to create a Microsoft account to try out Teams which is supposedly free. (I have avoided it so far, but my GF has been asked to use it for an interview and we wanted to do a tech test run before). Of course, the UI on the website assumes (!) that you already have a Microsoft account. It will let you create a Teams account that will fail the login if you do not have a Microsoft account and then sends you around in a Byzantine loop without telling you: Look you need a Microsoft account to use Teams. It looks to me as it just creates a shallow alias or something without root reference. This is dark patterns all over the place.

Anyway, a bit more on topic, I am course using my spam email for this account, but then they ask for my phone number. This is really an issue, because except if I get a burner phone, my personal data is linked with an account of a company I do not trust. After witnessing then how bad teams is almost 1.5 years after everyone is working remotely, (wow their web client does not allow you to share webcam and a window/screen at the same time, while their native client makes it super hard to share content while still seeing the people who you present to), I realised

1. How privileged I am not having to use Microsoft products (need to remember to charge extra, whenever asks me do a job that involves Microsoft products)

2. How anti-competitive Microsoft still is (you cannot login to Teams, MS web auth, in Chromium incognito mode, and it needs a ton of cookie domains whitelisted, even then it does not work)

3. How (and this is not Microsoft specific) difficult it is to not hand over personal data to companies that provide a utility-like service that they pretend is free (so everybody can pretend they are inclusive when they use these services)

4. An then literally a day later it turns out I am not paranoid not trusting Microsoft (and I guess other companies, big or small) with my data, because they are going to loose it sooner or later.

Edit: I just logged back into this MS account. They dont even use the phone number as "2FA". They only send you a text when you register, not for subsequent logins. It looks to me as they just collect it to make sure they really have some personal data to loose..

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#127

FWIW, I've been scrubbing my social profiles. LinkedIn, Yelp, Facebook, etc. Barest of bones. Removing all connections, photos, posts, personal details. (I know the damage is already done. The aggregators never really delete anything.) Why not just out right delete my profiles? I'm squatting. To ensure they're not used as socket puppets. After a beloved coworker passed, their profile got highjacked. Ten years later,…

I would do this, but my data has been up in social media long enough that I don't believe it makes a significant difference if I superficially "delete" it now. Maybe I'm wrong? At this point, I just don't add anything new. If they're going to host my content ad infinitum, I might as well use their storage space and bandwidth. I guess it probably would be worth ditching LinkedIn. There's no good reason why a [worthwhi…

The best time was not to do it in the first place. The second best time is now.

Your past self, current self, and your future self are different people. Don't give in to sunk cost fallacy here.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#128

FWIW, I've been scrubbing my social profiles. LinkedIn, Yelp, Facebook, etc. Barest of bones. Removing all connections, photos, posts, personal details. (I know the damage is already done. The aggregators never really delete anything.) Why not just out right delete my profiles? I'm squatting. To ensure they're not used as socket puppets. After a beloved coworker passed, their profile got highjacked. Ten years later,…

> I'm squatting. To ensure they're not used as socket puppets.

Good idea. I've noticed more of those popping up. My wife has an Instagram impersonator that constantly spams some kind of essential oils crap or other beauty product snake oil.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#129
post #110

This hack includes inferred salary, facebook username, mobile number, geo location... None of this is publicly available. None of this can even be downloaded by myself when I get a copy of all my data from linkedin... https://www.linkedin.com/help/linkedin/answer/50191/download... So I have no idea what information about myself was leaked in this hack

Inferred salary is from salary estimates based on job titles. It isn’t tied to your personal data IIRC. It’s likely that an API endpoint was found and all the data was siphoned off.

The same API that was used in the April breach.

https://restoreprivacy.com/linkedin-data-leak-700-million-us...

Even if you don't considered inferred salary directly tied to you as "personal data," surely you consider geo location personal data?

Also, aren't you even slightly outraged that you can't even download data that has been hacked and released into the wild?

Or outraged by the fact that you can only download data you have given directly to a service provider, but that the service provider will happily tell 3rd parties about your shadow profiles?

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#130
post #110

Earlier quoted context omitted.

Inferred salary is from salary estimates based on job titles. It isn’t tied to your personal data IIRC. It’s likely that an API endpoint was found and all the data was siphoned off.

> Inferred salary is from salary estimates based on job titles. It isn’t tied to your personal data IIRC. How do you know? https://www.linkedin.com/help/linkedin/answer/4786/source-an... >When we don’t have member-submitted data, salary insights are inferred using data between similar companies, job titles, location, and other job attributes. With enough "job attributes", you can easily tie things down to an individu…

Because you get salary insights when you look at job postings which means it’s an API endpoint.
Post reply on HN