Live data from Hacker News

LinkedIn suffers DNS hijack

alpha.app.net

81–90 of 95 posts

Re: LinkedIn suffers DNS hijack

#81
post #14

Can anyone think of a good reason LinkedIn didn't mark their cookies as HTTPS-only? http://en.wikipedia.org/wiki/HTTP_cookie#Secure_and_HttpOnly

Because they allow HTTP, which for any sensitive site is a very bad idea. Their setup enables MITM attacks even against users that are careful to always use HTTPS for visiting LinkedIn.

Re: LinkedIn suffers DNS hijack

#82
post #42

I'm done with LinkedIn. I've been on the fence about it for a year now. I get more recruiter spam than value. I'm also a bit too old for the schadenfreude that accompanies news of my overpaid friends getting canned. I'm running my own race these days and I've never been happier since I stopped comparing my lot in life to the few lucky SOBs I know that survived the cull of sub-prime. I think a better strategy is (1) y…

LinkedIn's value is not centered around your personal profile - it's about the other people that are linked to you and will always have an up-to-date CV/contact details for you. It is a self-updating rolodex, Outlook Contacts list, phone book, whateveryouwanttocallit. I really don't want to bookmark 300+ individual pages that all have different creative layouts, get moved, etc. My LinkedIn profile stays up-to-date, y…

linked-in's value is also linked somewhat to your curiosity to check who has viewed your profile.

Re: LinkedIn suffers DNS hijack

#83
post #80
post #42

I'm done with LinkedIn. I've been on the fence about it for a year now. I get more recruiter spam than value. I'm also a bit too old for the schadenfreude that accompanies news of my overpaid friends getting canned. I'm running my own race these days and I've never been happier since I stopped comparing my lot in life to the few lucky SOBs I know that survived the cull of sub-prime. I think a better strategy is (1) y…

If recruiters bother you so much, why do offer them bait? Just remove your CV and replace it with a link to your personal site.

I feel a little unloved because recruiters almost never contact me on LinkedIn. I guess my skills aren't cool enough, or else it's because I do more hiring than job seeking..?

I would have thought with Java, C#, objective C, php, node, etc that I'd be a good catch but apparently not!

Re: LinkedIn suffers DNS hijack

#85
post #7

I guess they didn't mark their cookies as 'Secure'. Oh well, the real story here is an app.net link at #1 on HN.

> Oh well, the real story here is an app.net link at #1 on HN.

Looks like the app.net post was by a founder so I would take that with a grain of salt.

Edit: While I'm at it according to https://twitter.com/mikegreenspan , the submitter also works at app.net.

Re: LinkedIn suffers DNS hijack

#86

Earlier quoted context omitted.

LinkedIn's value is not centered around your personal profile - it's about the other people that are linked to you and will always have an up-to-date CV/contact details for you. It is a self-updating rolodex, Outlook Contacts list, phone book, whateveryouwanttocallit. I really don't want to bookmark 300+ individual pages that all have different creative layouts, get moved, etc. My LinkedIn profile stays up-to-date, y…

Thus I've never had more than minimal info on my linkedin profile. As of this writing, I only have my undergrad and grad school names listed. I don't think I even have my areas of study on there. Works perfectly as a rolodex.

I don't even have that; just my name and the other required stuff. I still accept connections in the hope that I will join one day, but that seems more and more unlikely.

Re: LinkedIn suffers DNS hijack

#87
post #42

I'm done with LinkedIn. I've been on the fence about it for a year now. I get more recruiter spam than value. I'm also a bit too old for the schadenfreude that accompanies news of my overpaid friends getting canned. I'm running my own race these days and I've never been happier since I stopped comparing my lot in life to the few lucky SOBs I know that survived the cull of sub-prime. I think a better strategy is (1) y…

> I think a better strategy is (1) your own domain and/or (2) a site on github with actual code to validate* your talents.

Possibly, but that's for programmers. There are more professions out there.

I just closed my account too. The help page said that my account would no longer be visible on LinkedIn, but after closing and logging out, I still get the "sign up to see the full profile" bait on visiting my old URL (search result from Google).

Re: LinkedIn suffers DNS hijack

#88

Earlier quoted context omitted.

LinkedIn's value is not centered around your personal profile - it's about the other people that are linked to you and will always have an up-to-date CV/contact details for you. It is a self-updating rolodex, Outlook Contacts list, phone book, whateveryouwanttocallit. I really don't want to bookmark 300+ individual pages that all have different creative layouts, get moved, etc. My LinkedIn profile stays up-to-date, y…

linked-in's value is also linked somewhat to your curiosity to check who has viewed your profile.

This feature was interesting, but on the other hand it affected my own ability to look at other people's profiles - because, no, I don't want people to know that I looked at their profile.

Which is why I completely disabled it. Having the ability to see who viewed your profile seemed cool at first, but then again, it's useless and the downsides are great.

Re: LinkedIn suffers DNS hijack

#89
post #53

Can they actually snarf cookies from other sites you're logged into, or would they only be able to get at your LinkedIn session cookies?

No. Cookies only get sent to the originating domain. What happened here is *.linkedin.com points to the rogue server so your cookies get passed to them instead of the real Linkedin.

Re: LinkedIn suffers DNS hijack

#90
http://confluence-networks.com/:

Important Notice [20th June, 2013]

Confluence Networks is a Colocation & Network service provider having tie-ups with data centers across various geographical regions. We don't host any services ourselves. Starting few hours ago, we received reports about some sites (including linkedin.com) pointing to IPs allotted to our ranges. We are in touch with the affected parties & our customer to identify the root cause of this event.

Note that it has already been verified that this issue was caused due to a human error and there was NO security related issue caused by the same. More details will be provided shortly.

Post reply on HN