Live data from Hacker News

LinkedIn suffers DNS hijack

alpha.app.net

71–80 of 95 posts

Re: LinkedIn suffers DNS hijack

#71

I think confluence-networks.com may be apart of Network Solutions (which is whom LinkedIn is registered with). I had a domain (nitren.com), that I let expire after 3yrs and confluence-networks.com back ordered it, I remember looking it up a while back, but if I remember right, all the ip and domains were registered or associated with netsol.

confluence-networks.com is part of DirectI. See http://www.directi.com

Re: LinkedIn suffers DNS hijack

#73
post #38
post #15

Was api.linkedin.com compromised/hijacked? If so, that means they'll need to reset a lot of OAuth token/secrets which will be very painful indeed (worse than just a site-wide session reset).

Isn't that the point of OAuth? (versus HTTP basic auth) Your secret key shouldn't be compromised, because you're supposed to keep that secret. Also if you use HTTPS for requests you'd still get a cert error even if DNS was routing incorrectly. You're probably fine.

Indeed, I misspoke and meant to say tokens/refresh tokens. A similar thing happened for Evernote a while back and knocked down all tokens and required re-authentication across the board.

Re: LinkedIn suffers DNS hijack

#74
HTTPS everywhere; that's all I have to say. Something like this is very malicious and very hard to detect -- unless you ALWAYS use SSL. I noticed right away that the DNS was incorrect.

Re: LinkedIn suffers DNS hijack

#75
post #42

I'm done with LinkedIn. I've been on the fence about it for a year now. I get more recruiter spam than value. I'm also a bit too old for the schadenfreude that accompanies news of my overpaid friends getting canned. I'm running my own race these days and I've never been happier since I stopped comparing my lot in life to the few lucky SOBs I know that survived the cull of sub-prime. I think a better strategy is (1) y…

LinkedIn's value is not centered around your personal profile - it's about the other people that are linked to you and will always have an up-to-date CV/contact details for you.

It is a self-updating rolodex, Outlook Contacts list, phone book, whateveryouwanttocallit.

I really don't want to bookmark 300+ individual pages that all have different creative layouts, get moved, etc. My LinkedIn profile stays up-to-date, you update yours, that's the implicit deal. And we all profit from it. all being defined as a western work related group, english spoken. this is not facebook. Link your gitbub repo from there, absolutely, good idea, but having LinkedIn as your standardized contact info is very valuable.

is LinkedIn managed in a bad way? sure. But for some reason the modern business world has chosen it to focus on it. Xing and other local players never grew enough. the benefits of starting out it in the US. all the surrounding crap they're building is fluff, their core feature is being a global rolodex. would love to slap sense into their product management team.

Re: LinkedIn suffers DNS hijack

#77
I just realised; If you opened a website with a linked in share button, your cookie might be compromised as well; you didn't even have to go the the site while under the DNS Hijack...

Re: LinkedIn suffers DNS hijack

#78
post #42

I'm done with LinkedIn. I've been on the fence about it for a year now. I get more recruiter spam than value. I'm also a bit too old for the schadenfreude that accompanies news of my overpaid friends getting canned. I'm running my own race these days and I've never been happier since I stopped comparing my lot in life to the few lucky SOBs I know that survived the cull of sub-prime. I think a better strategy is (1) y…

LinkedIn's value is not centered around your personal profile - it's about the other people that are linked to you and will always have an up-to-date CV/contact details for you. It is a self-updating rolodex, Outlook Contacts list, phone book, whateveryouwanttocallit. I really don't want to bookmark 300+ individual pages that all have different creative layouts, get moved, etc. My LinkedIn profile stays up-to-date, y…

Thus I've never had more than minimal info on my linkedin profile.

As of this writing, I only have my undergrad and grad school names listed. I don't think I even have my areas of study on there.

Works perfectly as a rolodex.

Re: LinkedIn suffers DNS hijack

#79
post #48

Earlier quoted context omitted.

>I think a better strategy is (1) your own domain and/or (2) a site on github with actual code to validate* your talents. That's because their target audience is not restricted to the tech savvy. Not everyone knows how to host and maintain their own domain. Not everyone uses github or know what git is. This was basically why LinkedIn came into fruition in the first place.

I totally get it. I'm only talking about me. I'm sure this community is generally capable of rolling their own LinkedIn.

I chose both routes. I don't particularly like like LinkedIn, but if it helps me network¹ then it's a positive tool to have until I no longer need it.

¹ yes, I also hate that word, but there you go.

Re: LinkedIn suffers DNS hijack

#80
post #42

I'm done with LinkedIn. I've been on the fence about it for a year now. I get more recruiter spam than value. I'm also a bit too old for the schadenfreude that accompanies news of my overpaid friends getting canned. I'm running my own race these days and I've never been happier since I stopped comparing my lot in life to the few lucky SOBs I know that survived the cull of sub-prime. I think a better strategy is (1) y…

If recruiters bother you so much, why do offer them bait? Just remove your CV and replace it with a link to your personal site.
Post reply on HN