Live data from Hacker News

New LinkedIn Data Leak Leaves 700M Users Exposed

restoreprivacy.com

151–153 of 153 posts

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#151

Not surprising really. A few years back Hotmail/Outlook were returning people's Twitter/LinkedIn handles for emails sent/received. It had been noticed you could scrape that fairly easily at scale. With one email account you could check up to 30000 email addresses before being flagged by Outlook. Slightly longer ago you could simply iterate 1...n on LinkedIn URLs to find someone's profile, by converting the number to…

From OP,

> He claims the data was obtained by exploiting the LinkedIn API to harvest information that people upload to the site.

> our initial analysis indicates that the dataset includes information scraped from LinkedIn as well as information obtained from other sources. This was not a LinkedIn data breach and our investigation has determined that no private LinkedIn member data was exposed.

If the attacker is telling the truth, Then somehow the attacker has gained access to privileged API of LinkedIn which gives out more fields than those listed in the official LinkedIn API doc[1].

If LinkedIn is telling the truth, Then the source of breach is most likely one of the many data brokers who have been breached several times in the past[2].

[1] https://docs.microsoft.com/en-us/linkedin/shared/references/...

[2] https://news.ycombinator.com/item?id=21606415

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#152

I'm curious. Was Linkedin always so bad at securing its (our) data or things have gone downhill ever since the acquisition? It is becoming a regular thing, almost part of the news cycle. "In other news, yesterday was the biannual data leak from Linkedin". It is outrageous.

At one point, early on, they lost everyone’s passwords. Doesn’t get much worse than that.

Re: New LinkedIn Data Leak Leaves 700M Users Exposed

#153
By the time this article is released, the scraped is stale.

LinkedIn is self advertising portal for newer better opportunities and that data is actually in public view and someone is selling it to get me better opportunities it sort of sounds fine..

What would be informational is if so called hacker comes and says how he used the data or the tech stack used.

Post reply on HN