Live data from Hacker News

New LinkedIn Data Leak Leaves 700M Users Exposed

restoreprivacy.com

141–150 of 153 posts

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#141

The biggest issue: you cannot not give them your personal data that they then loose. Let me contribute with an anecdote from yesterday (slightly off-topic but I promise to get around to it at the end). So just yesterday I needed to create a Microsoft account to try out Teams which is supposedly free. (I have avoided it so far, but my GF has been asked to use it for an interview and we wanted to do a tech test run bef…

I wouldn't do this if it were just a typo, but since you did it multiple times, I thought I should inform you that you mean "lose", not "loose".

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#142

This hack includes inferred salary, facebook username, mobile number, geo location... None of this is publicly available. None of this can even be downloaded by myself when I get a copy of all my data from linkedin... https://www.linkedin.com/help/linkedin/answer/50191/download... So I have no idea what information about myself was leaked in this hack

Inferred salary would be useful for recruiters, perhaps they used recruiter accounts to scrape it?

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#143

FWIW, I've been scrubbing my social profiles. LinkedIn, Yelp, Facebook, etc. Barest of bones. Removing all connections, photos, posts, personal details. (I know the damage is already done. The aggregators never really delete anything.) Why not just out right delete my profiles? I'm squatting. To ensure they're not used as socket puppets. After a beloved coworker passed, their profile got highjacked. Ten years later,…

This. The best way to erase social media is to replace the account with a bunch of BS. Most of these companies are too cheap and Zucker's "move fast" culture probably doesn't involve database record versioning. Also because it's expensive. The old SET _deleted_=1 is pretty much their main ace in the hole to f*k you. Hell, even if they do versioning, just keep filling the profiles with enough noise and they won't be a…

I saw someone on here had a program that went in your profile and rewrote all posts with garbage data before you deleted it. Like for Facebook, Twitter, Discord, etc. That way you know their database is filled with junk data. I'd really like to know what that was again so I could peak at it in case I ever wanted to do that.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#145
post #131
post #114

Earlier quoted context omitted.

Thanks for the tip! Miss google on the services

Sucks, but heres why no google support: From the redact.dev FAQ page: Why don't you support anything made by Google or Apple? At this time, we are reliant on both Google and Apple to be listed in their respective app stores. As such, we have been advised that in order to remain in good standing we should not offer support for these services.

Ouch.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#147
post #110

Earlier quoted context omitted.

Inferred salary is from salary estimates based on job titles. It isn’t tied to your personal data IIRC. It’s likely that an API endpoint was found and all the data was siphoned off.

The same API that was used in the April breach. https://restoreprivacy.com/linkedin-data-leak-700-million-us... Even if you don't considered inferred salary directly tied to you as "personal data," surely you consider geo location personal data? Also, aren't you even slightly outraged that you can't even download data that has been hacked and released into the wild? Or outraged by the fact that you can only download…

The geolocation in the response looks like the location you set in your LinkedIn profile.

Is there anything that shows that it’s your actual geo location when you access LinkedIn?

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#148

FWIW, I've been scrubbing my social profiles. LinkedIn, Yelp, Facebook, etc. Barest of bones. Removing all connections, photos, posts, personal details. (I know the damage is already done. The aggregators never really delete anything.) Why not just out right delete my profiles? I'm squatting. To ensure they're not used as socket puppets. After a beloved coworker passed, their profile got highjacked. Ten years later,…

I had someone do that to me when I've been -still alive-... just posting the weirdest shit right on other people's pages after adding a bunch of my friends for a cheap laugh.

It was literally just some idiot binging on drugs who thought it was really funny until i ran over to his place and kicked his door in. I had people ask me what the hell that was about for YEARS afterwards. How do you explain to all these people at parties or whatever that you just happen to know stupider people than they do?

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#149

This hack includes inferred salary, facebook username, mobile number, geo location... None of this is publicly available. None of this can even be downloaded by myself when I get a copy of all my data from linkedin... https://www.linkedin.com/help/linkedin/answer/50191/download... So I have no idea what information about myself was leaked in this hack

> None of this is publicly available.

I received message on WhatsApp from someone claiming to be my LinkedIn contact, I asked how that person got my mobile number and was told my number is visible on my profile.

I didn't remember ever adding my number there, So I dug around to find that LinkedIn published my phone number to all my contacts when I uploaded it for 2FA (LinkedIn didn't have TOTP that time. You needed to have premium account to prevent it from being shown to contacts. I removed the 2FA until LinkedIn got TOTP.

LinkedIn IMO[1] has received far less scrutiny on its practices and content when compared with other social networks while having disproportionately large influence on professional life.

[1] https://news.ycombinator.com/item?id=27673024

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#150

The biggest issue: you cannot not give them your personal data that they then loose. Let me contribute with an anecdote from yesterday (slightly off-topic but I promise to get around to it at the end). So just yesterday I needed to create a Microsoft account to try out Teams which is supposedly free. (I have avoided it so far, but my GF has been asked to use it for an interview and we wanted to do a tech test run bef…

Microsoft authentication is terrible. It breaks at random times with misleading error messages (telling you that TFA failed for example, when in fact it’s one of their servers is down). Sometimes it just times out or goes into a loop until you close the page or clear cookies. And authentication for teams on Safari doesn’t work at all, even though the rest of Office works fine.
Post reply on HN