Live data from Hacker News

LinkedIn forcing me to disclose my phone number to log in? No thanks

news.ycombinator.com

31–40 of 98 posts

Re: LinkedIn forcing me to disclose my phone number to log in? No thanks

#31
Demanding a phone number will not help stop the fraud.

HR execs advertising for nonexistent positions have drawers full of burner phones.

I wish fraudulent job advertisements were prosecuted as felonies. The value is typically in the hundreds of thousands of dollars, but there are no prosecutions.

Re: LinkedIn forcing me to disclose my phone number to log in? No thanks

#32

Earlier quoted context omitted.

Are you using Chrome? Do you have any extensions?

Right? Dude, please provide some additional context around your web browser stack because something you’re using is triggering their system. That or you’re click house neighbours are using your wifi.

I have private relay enabled via iOS iCloud. I have no extensions installed. Preload top hit is enabled on safari by default. (Not sure if this is could be a factor). I only use safari across my devices. 2FA is enabled for LinkedIn and save password. That is it. I access LinkedIn frequently throughout the day.

Re: LinkedIn forcing me to disclose my phone number to log in? No thanks

#33

I hear you. I just got officially banned permanently yesterday. I do not use their app except the web. Last month I was kicked off because they claimed that I am using an automation tool, which I don’t. The second time they kicked me out, they asked me to confirm that I do not use an automation all. I said I don’t. Yesterday, I got kicked out and was told to upload a government id such as a driving license. Shortly a…

Are you using Chrome? Do you have any extensions?

Good point - hijacked Chrome extensions are a huge, huge security risk, especially because auto-update is on by-default. It's entirely possible every time you login to LinkedIn some dodgy code in your browser is harvesting your cookies to pass to some bots who then scrape LinkedIn.

Auto-updating extensions, and software in general, is a huge risk that people still seem unconcerned about: popular extension authors get approached by scummy ads/data/"analytics" companies all the time to inject spyware or adware into their software (even me: I have a couple of Chrome extensions with only about 20k regular users and I get an email to Chrome Developer Dashboard address every couple of months, asking me to add a small bit of JS which in-turn loads in other arbitrary JS which could be doing anything to my users' browsers - I'm proud to say that I reply to each and every of those e-mails with feigned interest, as the only morally correct course of action here is to waste their time.

Re: LinkedIn forcing me to disclose my phone number to log in? No thanks

#35

Earlier quoted context omitted.

Right? Dude, please provide some additional context around your web browser stack because something you’re using is triggering their system. That or you’re click house neighbours are using your wifi.

I have private relay enabled via iOS iCloud. I have no extensions installed. Preload top hit is enabled on safari by default. (Not sure if this is could be a factor). I only use safari across my devices. 2FA is enabled for LinkedIn and save password. That is it. I access LinkedIn frequently throughout the day.

> I have private relay enabled via iOS iCloud

I can see that might be it - because it means LinkedIn would be seeing you logging-in from different IP addresses in different geolocations every time (though Apple doesn't let you virtually change-country, I understand in the US it does make it look like you've moved-state).

Re: LinkedIn forcing me to disclose my phone number to log in? No thanks

#36

Earlier quoted context omitted.

I would prefer to give up my ID (with mailing address censored, of course) because at least then they cannot use it to contact me.

So would I. An identify/human verification API provided by USPS would be awesome.

It takes 3-5 business days for a letter to get from one desk to mine, that won't work when you want to sign-up for your next impulsive Reddit link click-through.

There is id.me though (a non-governmental company, but effectively endorsed by the US federal gov), but because I highly value pseudonymity I don't want to use my on real, government-linked, identity for frivolous things - and I'm not aware of anyone like id.me nor any other identity-providers offering a "human-attestation-only" service that wouldn't share any actual PII like my real-name.

It's a shame that web-of-trust schemes never took-off (and I can't see how they could, honestly), I gather some schemes had a mode where a group of known people (in good standing) could collectively vouch for an anonymous person/node, but that system could be easily gamed too. Is this an intractible problem?

Re: LinkedIn forcing me to disclose my phone number to log in? No thanks

#37
The best solution I have to fixing this is somewhat complicated but worth it.

First get a prepaid phone number and the card for it using some backup phone you have.

Then port that number to Google voice or some voip text service.

For some reason, when you sign up with google voice or a voip service using their number allocation tool, services know that it's a voip number.

But when you port it, they never seem to find out. I think because the profile tag for the number on the exchange side doesn't change. Someone who knows how phone infrastructure works could probably explain how the backend works.

This is how I get around 2fa using Google voice if the service doesn't want me using a voip line.

Re: LinkedIn forcing me to disclose my phone number to log in? No thanks

#38
Looks like big tech, chasing those +25% YoY, is progressing from data theft to data extortion: "hey, you've got a nice decade old profile with us, with lots of valuable connections, it would be sad to have it gone! you have 24 hours to give us more data, otherwise we can't guarantee safety of your profile. have a wonderful day!"

Re: LinkedIn forcing me to disclose my phone number to log in? No thanks

#40
post #9

It's a standard measure to increase the cost of fake identities to decrease spam and Sybil attacks. If you exclusively belong to communities that don't have such measures, you will be dominated by third parties who create mass accounts instead of the platform. Choose your poison I guess.

I'm embarrassed to admit this but I created a fake LinkedIn account of a woman I used to rope in men for sales calls. I "friended" probably 200 odd linked in open networkers over the course of a week and then would flirt with guys using my catfish account.

Those guys would enevitably get sappy and I would rope them onto a sales call with me as a bait and switch. I hated doing sales as well as myself and got out of it in a year.

Making a fake burner linked in was trivial.

Post reply on HN