Live data from Hacker News

I verified my LinkedIn identity. Here's what I handed over

thelocalstack.eu

331–340 of 516 posts

Re: I verified my LinkedIn identity. Here's what I handed over

#331
I don't get the whole idea of treating identity verification as a private enterprise problem. I realize it's easy to just blame LinkedIn or Microsoft here, but the core issue is architectural. We are trying to solve a public utility problem by building private honeypots.

The government should provide an API or interface to validate a user, essentially acting just like an SSO. Instead of forcing users to upload raw passport scans to a third-party data broker, LinkedIn should just hit a government endpoint that returns an anonymized token or a simple boolean confirming "yes, this is a real, unique person." It gives platforms the sybil resistance they need without leaking the underlying PII.

Re: I verified my LinkedIn identity. Here's what I handed over

#333

Earlier quoted context omitted.

Why can't the EU deploy capital? Regulation doesn't create better products, more aggressive marketing techniques, or deeply entrepreneurial mindsets which favor innovation and growth. While OP is quite aggressive here, there is a nugget of truth: innovation doesn't happen because "we have the best lawyers" or "the best regulations". Maybe some self-criticism would be warranted to solve the problem. Also nothing force…

Here's another JD Vance who doesn't understand what international rules are and justifies that with (lack of) innovation Below you can find the relevant GDPR excerpt. But before that, let me add to the coment below that US companies only comply with what EU institutions can enforce and what suits them; which is normal, since China does the same. Well, it couldn’t have been said better: in fact, we’re beginning to vie…

First I'm not american, I'm simply displeased to see my fellow Europeans seething about the consequences, while refusing to address the causes.

You speak about China: their government is very eager to favor local alternatives, which helps fund the local ecosystem.

In contrast, Euro countries don't generally procure office software from elsewhere than US companies (especially, Microsoft). It's always talk, talk, when the time for action comes, everyone looks at their shoes and signs the contract from the US company.

Even the European commission does the same, and filed a lawsuit against their own regulatory body after it pointed out that MS Office 365 wasn't fully compliant with the EC's own privacy rules! Rules for thee, not for me, as always with the EC.[0]

So yeah, regulations and laws don't replace political will and action. Especially when we talk about the EU, where hypocrisy and lobbying is at its highest.

[0] https://www.freevacy.com/news/official-journal-of-the-europe...

Re: I verified my LinkedIn identity. Here's what I handed over

#334
post #288

I'll note that Persona's CEO responded on LinkedIn [1] pointing out that: - No personal data processed is used for AI/model training. Data is exclusively used to confirm your identity. - All biometric personal data is deleted immediately after processing. - All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot. - The only subprocessor…

Why would we believe they are deleted after processing and not shared with the government?

Re: I verified my LinkedIn identity. Here's what I handed over

#335

Earlier quoted context omitted.

A KYC provider is a company that doesn't start with neutral trust. It starts with a huge negative trust. Thus it is impossible to believe his words.

What does the (I assume) acronym KYC mean?

Kill Your Customer.

Re: I verified my LinkedIn identity. Here's what I handed over

#336

I used to have a LinkedIn account, a long time ago. To register I created an email address that was unique to LinkedIn, and pretty much unguessable ... certainly not amenable to a dictionary attack. I ended up deciding that I was getting no value from the account, and I heard unpleasant things about the company, so I deleted the account. Within hours I started to get spam to that unique email address. It would be int…

This is precisely why I give each website an alias such as website@example.com. If I start receiving spam to that address, I revoke the alias and name and shame the website online whenever I get the chance. Not that I would use LinkedIn anyway.

Re: I verified my LinkedIn identity. Here's what I handed over

#337

Earlier quoted context omitted.

A KYC provider is a company that doesn't start with neutral trust. It starts with a huge negative trust. Thus it is impossible to believe his words.

What does the (I assume) acronym KYC mean?

Know your customer

https://en.wikipedia.org/wiki/Know_your_customer

Re: I verified my LinkedIn identity. Here's what I handed over

#338
post #288

I'll note that Persona's CEO responded on LinkedIn [1] pointing out that: - No personal data processed is used for AI/model training. Data is exclusively used to confirm your identity. - All biometric personal data is deleted immediately after processing. - All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot. - The only subprocessor…

> that require legal to get involved and you do end up with documents that sound excessively broad

If you let your legal team use such broad CYA language, it is usually because you are not sure what's going on and want CYA, or you actually want to keep the door open for broader use with those broader permissive legal terms. On the other hand, if you are sure that you will preserve user's privacy as you are stating in marketing materials, then you should put it in legal writing explicitly.

Re: I verified my LinkedIn identity. Here's what I handed over

#339
post #288

I'll note that Persona's CEO responded on LinkedIn [1] pointing out that: - No personal data processed is used for AI/model training. Data is exclusively used to confirm your identity. - All biometric personal data is deleted immediately after processing. - All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot. - The only subprocessor…

Why would we believe they are deleted after processing and not shared with the government?

What's the government going to do with a picture of the ID they, themselves issued to you?

Re: I verified my LinkedIn identity. Here's what I handed over

#340
post #137

I work in this space for a competitor to Persona, so take my opinion as potentially biased, but I have two points: 1. just because the DPA lists 17 subprocessors, it doesn't mean your data gets sent to all of them. As a company you put all your subprocessors in the DPA, even if you don't use them. We have a long list of subprocessors, but any one individual going through our system is only going to interact with two…

> Why would _that_ be the problem Because it should still be my choice as to what you do with it, which data you associate with it, and how you store it. Removing that choice is anti-privacy.

It's way less your choice what happens with a photo of your face in pretty much every other situation.

When your face is on your LinkedIn profile, anyone can download it and do whatever they want with it. Legally. Here, the vendor has to tell you how they use it.

Post reply on HN