Live data from Hacker News

LinkedIn Customers Allege Company Hacked E-Mail Addresses

bloomberg.com

11–20 of 35 posts

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#11
post #9

“LinkedIn pretends to be that user and downloads the e-mail addresses contained anywhere in that account to LinkedIn’s servers,” they said. “LinkedIn is able to download these addresses without requesting the password for the external e-mail accounts or obtaining users’ consent.” I am so hoping the case goes to trial so we can see the evidence of this presented.

This sounds like an outright BS claim. There are two or more scenarios that may be presented as evidence. i. LinkedIn used the users current passwords with their external addresses to access the external emails. ( impossible) ii. Linked in use some sort of Oauth/google authentication access to information permission thing(can't remember the name). (highly unlikely) In any case I think we can only be certain with the…

Why is the first scenario impossible? People re-use passwords all the time.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#12

“LinkedIn pretends to be that user and downloads the e-mail addresses contained anywhere in that account to LinkedIn’s servers,” they said. “LinkedIn is able to download these addresses without requesting the password for the external e-mail accounts or obtaining users’ consent.” I am so hoping the case goes to trial so we can see the evidence of this presented.

My guess is they used the same password for their email and LinkedIn account, so LinkedIn had the credentials for both and was able to harvest contacts. That, or during the sign up process they plugged in their email credentials without realizing LinkedIn would abuse them in this way. Scummy in either case, even if it's technically legal.

I had the latter happen to me and so have several other people here on HN. LinkedIn ended up sending an invite to everyone I had ever emailed. It was catastrophically embarrassing and caused a lot of grief.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#13
post #9

Earlier quoted context omitted.

This sounds like an outright BS claim. There are two or more scenarios that may be presented as evidence. i. LinkedIn used the users current passwords with their external addresses to access the external emails. ( impossible) ii. Linked in use some sort of Oauth/google authentication access to information permission thing(can't remember the name). (highly unlikely) In any case I think we can only be certain with the…

Why is the first scenario impossible? People re-use passwords all the time.

Yeah, don't they just straight up ask for your passwords? http://i.imgur.com/ucFx7Kw.png

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#14
post #9

“LinkedIn pretends to be that user and downloads the e-mail addresses contained anywhere in that account to LinkedIn’s servers,” they said. “LinkedIn is able to download these addresses without requesting the password for the external e-mail accounts or obtaining users’ consent.” I am so hoping the case goes to trial so we can see the evidence of this presented.

This sounds like an outright BS claim. There are two or more scenarios that may be presented as evidence. i. LinkedIn used the users current passwords with their external addresses to access the external emails. ( impossible) ii. Linked in use some sort of Oauth/google authentication access to information permission thing(can't remember the name). (highly unlikely) In any case I think we can only be certain with the…

The Customers filing suit should know that LinkedIn is a publicly traded company and not a scam site.

Did you mean to say that? I know nothing about the details of this lawsuit, but I hope you realize that being a publicly traded company is no proof of being virtuous in all one's business operations!

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#16

Earlier quoted context omitted.

Why is the first scenario impossible? People re-use passwords all the time.

Yeah, don't they just straight up ask for your passwords? http://i.imgur.com/ucFx7Kw.png

There's that, but what I meant was they could combine the user's LinkedIn password with their email address and most of the time that would be a valid user/pass combination due to the frequency of password reuse. It's not like LinkedIn don't have access to the plaintext version of the user's password. After all, the hashing isn't done on the client but on the server.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#17
LinkedIn provided a pop-up window which, in small print, if you had logged in via Google or Facebook, notified users in legal terms that their e-mail contacts could (potentially, under some circumstances) be accessed.

Thus, in legal proceedings, the user was entirely informed of the possibility of this situation arising.

For future users, this sets a precedent that users are aware of the terms and conditions (as they have always been), and no further accidental leaks of personal information will occur.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#18
Here's how they do it. Various times Linkedin provides me with a form to "import" my contacts from my gmail account.

This dialog looks very similar to the login form to the site. If you use the same password for both sites (I don't), you might be thinking that you're logging in, when in fact you're bringing in everyone in your address book. Not sure, if they then automatically spam everyone on your list or not.

Linkedin clearly has crossed over to the dark side since they went public. They keep reducing their free services and pushing harder and harder to try to get you to sign up for "premium" accounts. It's time for an alternative.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#19

Here's my 2 cents... maybe they'll settle and walk away with some cash. I too would love to see the evidence of this presented. In today's world - individuals' data is the digital goldmine for any company. LinkedIn is a publicly traded company (LNKD), like any publicly traded company their main goal would be profits, plus assets like customer data, etc. This info can be seen in their financial statements: http://www.…

Where is the phrase "identity fraud" agreed to? That is more the line that seems up for debate. Also, LinkedIn forces changes onto otherwise grandfathered accounts (LFN). If you don't actively delete your page, you agree to whatever the worst case is under new terms.

Re: LinkedIn Customers Allege Company Hacked E-Mail Addresses

#20

Earlier quoted context omitted.

Why is the first scenario impossible? People re-use passwords all the time.

Yeah, don't they just straight up ask for your passwords? http://i.imgur.com/ucFx7Kw.png

That's brazen, but if the plaintiffs complied with that prompt then they're basically telling the World that they not only violated the TOS of their e-mail provider but also their terms of employment and common sense.

Looks like implementing two-factor authentication might not only protect companies against malicious intruders but also from their own employees spilling the beans.

Post reply on HN