Live data from Hacker News

LinkedIn Customers Allege Company Hacked E-Mail Addresses

bloomberg.com

1–10 of 35 posts

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#2
“LinkedIn pretends to be that user and downloads the e-mail addresses contained anywhere in that account to LinkedIn’s servers,” they said. “LinkedIn is able to download these addresses without requesting the password for the external e-mail accounts or obtaining users’ consent.”

I am so hoping the case goes to trial so we can see the evidence of this presented.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#3
I'm not sure how LinkedIn does it but their "recommendations" are very spooky.

I get some really odd ones like the property manager we pay rent to. I've only ever emailed or called him.

I presume he gave LinkedIn access to his email contact list but based on the number of these creepy recommendations a lot of people I email with must do it.

Even more spooky are the recommendations to connect with people I don't know but have names that match people I do. Anyone know how they do this?

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#4

“LinkedIn pretends to be that user and downloads the e-mail addresses contained anywhere in that account to LinkedIn’s servers,” they said. “LinkedIn is able to download these addresses without requesting the password for the external e-mail accounts or obtaining users’ consent.” I am so hoping the case goes to trial so we can see the evidence of this presented.

My guess is they used the same password for their email and LinkedIn account, so LinkedIn had the credentials for both and was able to harvest contacts. That, or during the sign up process they plugged in their email credentials without realizing LinkedIn would abuse them in this way.

Scummy in either case, even if it's technically legal.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#5
post #3

I'm not sure how LinkedIn does it but their "recommendations" are very spooky. I get some really odd ones like the property manager we pay rent to. I've only ever emailed or called him. I presume he gave LinkedIn access to his email contact list but based on the number of these creepy recommendations a lot of people I email with must do it. Even more spooky are the recommendations to connect with people I don't know…

Surprisingly simple math (like https://news.ycombinator.com/item?id=5854593), the data you just described, and also IP addresses. I wouldn't be surprised if they also use browsing habits (search history on LinkedIn, profiles visited on LinkedIn). So they might guess the friend's name from the data, but not know which exact profile out of several identically-named profiles represents the person you know.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#6

“LinkedIn pretends to be that user and downloads the e-mail addresses contained anywhere in that account to LinkedIn’s servers,” they said. “LinkedIn is able to download these addresses without requesting the password for the external e-mail accounts or obtaining users’ consent.” I am so hoping the case goes to trial so we can see the evidence of this presented.

My guess is they used the same password for their email and LinkedIn account, so LinkedIn had the credentials for both and was able to harvest contacts. That, or during the sign up process they plugged in their email credentials without realizing LinkedIn would abuse them in this way. Scummy in either case, even if it's technically legal.

Somehow I'm thinking the latter.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#7
post #3

I'm not sure how LinkedIn does it but their "recommendations" are very spooky. I get some really odd ones like the property manager we pay rent to. I've only ever emailed or called him. I presume he gave LinkedIn access to his email contact list but based on the number of these creepy recommendations a lot of people I email with must do it. Even more spooky are the recommendations to connect with people I don't know…

LinkedIn does that by cross referencing cookies, contact lists, email addresses. The same way Facebook does. People just used to expect more integrity from LinkedIn.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#8
Here's my 2 cents... maybe they'll settle and walk away with some cash. I too would love to see the evidence of this presented.

In today's world - individuals' data is the digital goldmine for any company.

LinkedIn is a publicly traded company (LNKD), like any publicly traded company their main goal would be profits, plus assets like customer data, etc.

This info can be seen in their financial statements: http://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CI...

Nowadays it's common practice for our digital footprints and identities to be designed/built/directed so that before we can gain access to a company's services, data or content that we would need to read and agree to the terms & conditions and the privacy policies, etc.

This info can be seen in LinkedIn's:

Terms and Conditions http://www.linkedin.com/legal/user-agreement?trk=hb_ft_usera...

Privacy Policy http://www.linkedin.com/legal/user-agreement?trk=hb_ft_usera...

Cookie Policy http://www.linkedin.com/legal/cookie-policy?trk=hb_ft_cookie

What, you mean I'm supposed to read those things? Yes.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#9

“LinkedIn pretends to be that user and downloads the e-mail addresses contained anywhere in that account to LinkedIn’s servers,” they said. “LinkedIn is able to download these addresses without requesting the password for the external e-mail accounts or obtaining users’ consent.” I am so hoping the case goes to trial so we can see the evidence of this presented.

This sounds like an outright BS claim. There are two or more scenarios that may be presented as evidence.

i. LinkedIn used the users current passwords with their external addresses to access the external emails. ( impossible) ii. Linked in use some sort of Oauth/google authentication access to information permission thing(can't remember the name). (highly unlikely)

In any case I think we can only be certain with the actual evidence.

The Customers filing suit should know that LinkedIn is a publicly traded company and not a scam site.

Because even these claims are outrages if not utter BS.

Post reply on HN