24 ms·
New LinkedIn Data Leak Leaves 700M Users Exposed
- Sebb767 5y ago> making this one of the largest LinkedIn data leaks to date. one of. This is insane.
- SavageBeast 5y agoKinda makes you want to transfer all your cloud ops to Azure doesn't it.
- HatchedLake721 5y agoNice try Satya Nadella
- ianpurton 5y agoSo the attacker claims to have harvested the data via the API. Looks like you can get any user profile if you're an approved developer. Possible the attacker slowly downloaded the whole database.
- rvz 5y agoNow we will see an increase in SIM swapping attacks via this data dump and tons of fraud happening here. I hope they didn't use their phone number to login to their bank, crypto exchange or other social media accounts. Using phone numbers for login should be completely discouraged.
- emodendroket 5y agoIf someone merely knowing your phone number is a security risk that really seems like a flaw that should be addressed with the phone system and not by treating the numbers like sensitive information.
- darkfirefly 5y agoTrue, but whether or not it should be or not doesn't change the fact that it is the current state of the US. And it's not really just the phone number, but the combination of personal info that allows for social engineering - without having the existing customer confirm the transfer.
- rightbyte 5y agoI've seen worse. All you need to use a credit card is the number printed on it and still we hand it to strangers to run off with for 3 minutes like nothing.
- eythian 5y ago> and still we hand it to strangers to run off with for 3 minutes like nothing. Why would you do that?
- rightbyte 5y agoI'm joking about the restaurant experience. Nowadays the staff usually comes out with a portable machine though.
- emodendroket 5y agoI saw that in Canada but it's rare in the US.
- SketchySeaBeast 5y agoThere was a time when there were whole books of said numbers and it wasn't a security risk. We've definitely gone wrong with our assumptions somewhere.
- justusw 5y agoThis is why it’s good to only share data with LinkedIn that you expect to be leaked.
- bennyp101 5y agoCrazy that this is the default stance now for places that should know better
- SketchySeaBeast 5y agoMy LinkedIn data leaked? Honestly, it's free advertising.
- xpe 5y agoTo the extent the leak goes beyond public-facing profile information, this is far from "advertising".
- SketchySeaBeast 5y agoThat's fair and for many it's not good at all - I was speaking strictly for myself. I didn't link my account to any other social media, nor did I put a phone number on there.
- dylan604 5y agoAnd what in that leak is going to make you stand out from the other 699,999,999 users? rand(oneLuckyUser) == You???
- SketchySeaBeast 5y agoDidn't say it was good advertising.
- salt-thrower 5y ago"You get what you pay for"
- bennyp101 5y agoIs this on top of the 500M in April? https://cybernews.com/news/stolen-data-of-500-million-linkedin-users-being-sold-online-2-million-leaked-as-proof-2/ https://cybernews.com/news/stolen-data-of-500-million-linked... Or is this a follow on with the rest of the data? Either way, it's pretty shoddy that they haven't put a stop to it
- kleinsch 5y agoWhere are all the folks who were complaining about the LinkedIn anti-scraping court case destroying the open web? This is what LinkedIn is fighting against.
- xpe 5y agoIt is easy for hacker(s) to claim they got this data from scraping. From the article, we can't be confident that this is true (completely or in part).
- xpe 5y ago> Where are all the folks who were complaining about the LinkedIn anti-scraping court case destroying the open web? This is what LinkedIn is fighting against. I find comments of the form "where are all the folks who were complaining..." to be tiresome. Asking "where are all the folks" suggest that "all the folks" don't exist because... you don't see them on Hacker News? ... because ... you want to make a dig at LinkedIn? ... because [reasons]? Unless I'm missing something (let me know), this comment seems like a rant based on speculation. Why believe a hacker who says they got this from scraping? I'm not defending LinkedIn, to be clear. I'm asking for more {elaboration, logic, specificity} and less rhetoric in the comments here.
- southerntofu 5y agoScraping the open web is NOT the same as accessing privileged APIs to collect private information. If LinkedIn made their pages accessible to anyone as a sort of public service (as they used to), people would think twice what data to put on there. The problem is the same as with Facebook: they pretend the data is private and secure, then let people siphon it away. Public and private networks are both fine, but huge corporations trying to mix both usually end up with the worst of both worlds.
- 101_101 5y agoYou want to defend a company that uses shitty dark patterns?
- stuff4ben 5y agoBut is this really a problem? LinkedIn is "advertising for yourself", presumably to get a job. With the exception of my phone number, I'm ok with the world knowing this information about me. It's the equivalent of a phone book and I'm putting myself out there and advertising myself in the hopes of getting a job.
- emodendroket 5y agoMy thoughts exactly. Given the nature of LinkedIn there is absolutely nothing I'd put there that I didn't want others to see.
- dylan604 5y agoIsn't the revealing thing about these leaks not the data that you provided but the data they have associated to you from other means?
- diarrhea 5y agoI imagine most people do not share your attitude, me included. Especially profile sections set to private staying that way needs to be trusted.
- rapnie 5y agoAnd emails not falling in the hands of spammers is always nice.
- dnate 5y agoI feel like the lines between a data leak and large scale scraping are getting blurred. At least in their impact for the user. Which is a bad thing as it will support the "so what" attitude that many people have toward their data. It is a fact that all this data is already being crawled by bot nets. If all data is leaked at once, this is similar to a large scale successful crawling of the site. At least from a user perspective. So I get what you are saying. It sounds more dramatic than it actually is. It is still a massive leak. But from a pool that scummy businesses have been thoroughly scooping from already anyway.
- AzzieElbab 5y agoThe article does not explain what info beyond public profiles had been stolen. You can already google search LinkedIn making this data leak very low impact
- emodendroket 5y agoSeems like just the phone number and email.
- AzzieElbab 5y agoYeah missed that. My LinkedIn api experience is dated, are those visible via api?
- emodendroket 5y agoKind of ambiguous from the article's description of "exploiting the API."
- ta988 5y agoThe Linkedin API is dated. So you are probably up to date ;)
- whoomp12342 5y agoit bypasses privacy settings users may have set up. e.g. not everyone can see my contact info
- syntaxstic 5y agohttps://github.com/vysecurity/LinkedInt https://github.com/vysecurity/LinkedInt
- JohnTHaller 5y agoNow when cold-calling scammers that buy lists from ZoomInfo say they 'got my info from LinkedIn' they may not be lying.
- literallyaduck 5y agoIf Microsoft can't safely code its apis what hope does anyone else have?
- colllectorof 5y agoThis is an excellent question/framing. The security model used in the industry right now is insane and doomed to fail, and yet it is relentlessly pushed forth and defended.
- southerntofu 5y agoMicrosoft have never exactly had a reputation of security-conscious developments. However you do have a point: building secure software is close to impossible, and that's why we should build software that collects the smallest amount possible of personal information.
- _uxgb 5y agoLinkedIn became crap a long time ago. Let's make https://www.polywork.com https://www.polywork.com the default way to share your achievements.
- keb_ 5y agoLooks terrible.
- ta988 5y agoDesign looks like a kid tv station. I scrolled through weird animations to get no info at all. I closed the page.
- nomdep 5y agoSorry, but looks like vaporware, and the company (Kalo) seems scammy: broken website, no activity for years even when they claim to have raised millions, etc.
- qku 5y agoCan't tell what it does from the website. It scrolljacks you from the beginning and shows a lot of cartoon characters and trite phrases. It doesn't even do anything yet but ask me to join a waitlist. This is supposed to replace a social network with 700 million users?! It looks horrible.
- emodendroket 5y agoHmmm no I think I'll stay on the one people have actually heard of where you actually get scouted.
- dempsey 5y agoNot sure if the waitlist/vip method is well suited to this.
- dafman 5y agoI've never seen a website chug so badly on my machine, I barely got 5fps on any of that page
- kwere 5y ago
- asdadsdad 5y agoThen they complain when people scrape their site...
- specialist 5y agoFWIW, I've been scrubbing my social profiles. LinkedIn, Yelp, Facebook, etc. Barest of bones. Removing all connections, photos, posts, personal details. (I know the damage is already done. The aggregators never really delete anything.) Why not just out right delete my profiles? I'm squatting. To ensure they're not used as socket puppets. After a beloved coworker passed, their profile got highjacked. Ten years later, I'm still so angry about it that I could just spit.
- xpe 5y ago> To ensure they're not used as socket puppets. sock puppets :) Done much network programming lately?
- scrollaway 5y agoSocket pups sounds like such a lovely alternative to sockpuppets.
- bb123 5y agoI’ve been doing the same. The potential downside risk of having LinkedIn/Facebook/Instagram profiles just keeps growing and growing. I’m a complete ghost on the Internet. I have Google alerts set up for my names and email addresses, and I regularly attempt to docs myself to find any leaks. I also can’t understand why anyone in the public eye doesn’t completely sanitise their social media profiles. The amount of people brought down by 10 year old stupid tweets is insane.
- ebb_earl_co 5y agoI was going to ask if you said "docs" as in "doxxing" [0] but then a quick Wikipedia search got me to the etymology [1] of "doxxing" which comes from "docs" as in "documents"! TIL [0] https://www.thefreedictionary.com/doxx https://www.thefreedictionary.com/doxx [1] https://en.wikipedia.org/wiki/Doxing#Etymology https://en.wikipedia.org/wiki/Doxing#Etymology
- willis936 5y ago
- kristopolous 5y agodon't put any real info on those things beyond like your name ... really.
- shoto_io 5y agoIs this a "real" leak or "just" scraped profiles?
- ParanoidalMouse 5y agoLooks like scraped with additional data from other sources. Linkedin doesn't have your Facebook account, but it included in the database sample
- shoto_io 5y agoAugmented data!
- ricardo81 5y agoNot surprising really. A few years back Hotmail/Outlook were returning people's Twitter/LinkedIn handles for emails sent/received. It had been noticed you could scrape that fairly easily at scale. With one email account you could check up to 30000 email addresses before being flagged by Outlook. Slightly longer ago you could simply iterate 1...n on LinkedIn URLs to find someone's profile, by converting the number to base12, you'd be redirected to the person's public URL. Also their bulk contact upload. Take any data leak of email addresses, bulk upload them as contacts and then correlate email addresses to social profiles. Facebook, Twitter and LinkedIn are all bad in that regard on the last method, though Facebook at least do not return people's URLs along with your contact upload (you're expected to know the person's face/name to decide whether you'd want to connect). The take away is that once you sign up, whatever information you put on your profile/account is pretty much available to anyone who wants it enough - and clearly there are plenty bad actors who want it. Obviously these social networks want to expand their network, but they also make it much more easy for data harvesting at unprecedented scale.
- Zenst 5y ago> Also their bulk contact upload. Take any data leak of email addresses, bulk upload them as contacts and then correlate email addresses to social profiles. This is one of those functionality aspects all these social/networking sites fall foul of one way or another, be email or phone number relational suggestions. That and the aspect of this scraping of phone numbers or emails - even with the users permission, kinda moots the owner of those email and phone details. But does seem that once you give anybody your email or phone number, it kinda one way or another falls into the public domain level of privacy. Heck how many contact details via email or phone numbers do these sites hold on people who never even held an account with them. Be nice if the law and data privacy had some global standards as this region/country by country aspect does nobody any good and in a World in which taxation works with the same model, do we really want to let data protection end up with data havens in much the same way as tax does.
- ricardo81 5y agoAgreed. One of the poorer aspects of those 'functionalities' is friends of friends details get added, i.e. sharing your phone contacts or email contacts. There's people not on those networks that have a definite amount of information about them on there anyway.
- nafizh 5y agoI have said it many times before. Unless and until you make companies pay exorbitant amount of money when your data gets stolen from them, the companies will never be serious enough about security. We had the whole Equifax fiasco, and nothing has changed.
- greenie_beans 5y agoMy lord, how many times has this happened to LinkedIn? Fuckin ridiculous. Need some public policy to hold these companies more accountable when this happens, so it will happen less.
- eli 5y agoIsn't this just data that people choose to make public on linkedin?
- fart32 5y agoI wonder. I definitelly don't have my phone number and e-mail address visible to public (this has a purpose - if someone can find it, it means they at least spent 30 seconds of their life to issue a search query in Google) and I think most people don't as well. But that's the same thing with FB 2019 - my phone number was leaked, but I never made it public. Why would I.
- CountDrewku 5y agoThis is just basically the data that's publicly available anyway unless you've locked down your profile. That sort of defeats the purpose of LinkedIn though since you're trying to get people to contact you about jobs etc. I wish LinkedIn would just go away, it's turning less into a job specific site and more of another facebook full of idiotic political posts etc. I'd rather not have to deal with it at all but it seems employers still sort of expect you to use it.
- lanstin 5y agoMy actual goal with LinkedIn is to be able to search people whom I have worked with that now work with some random company I am curious in now. “Oh, huh, LinkedIn had a leak, who do I know there, oh, they were reasonable people, probably an error then.” I must confess a certain curiosity on the inferred salaries I wonder how accurate they are and if we will see the whole data dump at some point.
- Santosh83 5y agoIf I put on my thickest tinfoil hat, I might even think these continuous data leaks are deliberately happening to get users/consumers normalised towards expecting zero privacy or corporate accountability going forward.
- calotow 5y agoBy including a description of your supposed hat, you kind of pre-negate the content of your post.
- one2three4 5y agoI'm curious. Was Linkedin always so bad at securing its (our) data or things have gone downhill ever since the acquisition? It is becoming a regular thing, almost part of the news cycle. "In other news, yesterday was the biannual data leak from Linkedin". It is outrageous.
- scrollaway 5y agoIt was always that bad. In fact it probably used to be even worse.
- dannyw 5y agoI've know a few people who worked at LinkedIn prior to the acquisition. They say it was worse before.
- mr_toad 5y agoAt one point, early on, they lost everyone’s passwords. Doesn’t get much worse than that.
- SavageBeast 5y agoI'm curious enough to ask the question - having read the article and seen what data was leaked - isn't this "leaked data" the very same data that Linked In is selling to users as part of its Premium Offering?
- spsful 5y agoIMO it seems to be exactly the same thing.. LinkedIn has never made itself out to be respectful of privacy, so I'm really not surprised.
- idorosen 5y agoduplicate: - https://news.ycombinator.com/item?id=27675648 https://news.ycombinator.com/item?id=27675648 - https://news.ycombinator.com/item?id=27674393 https://news.ycombinator.com/item?id=27674393
- dada78641 5y agoWell, they finally got me to log in again after, what, 5 years? Good on them.
- atlgator 5y agoHow does LinkedIn know my facebook username if I've never linked them? How does it infer salary and is it provided to recruiters unverified?
- jacquesm 5y agoI'm not in there. I never saw any value in a LinkedIn profile.
- neya 5y agoMany of you may not know, But most recently, even Domino's Pizza (India) had a breach and they kept denying it ever happened until the hackers finally made a search engine where anyone could search through the entire database. And Domino's finally released some statement in some obscure part of their website. NONE of the users who were affected were notified directly. Many even don't know that this happened. What's worse is the data contained your precise house location and location data in general with co-ordinates. So, the hackers know your phone, your address, where you live, where you go to, been to and how much you're actually worth. It has been claimed financial data (credit cards) were stolen as well, but Domino's denies it till date and of course no one should trust them, given their history. So, in essence, this LinkedIn breach is also the same to me. Companies literally make you an attack target for hackers and don't even bother telling you. I don't know about you guys, I haven't received a single email from LinkedIn about this yet. How can we combat this dangerous behaviour of companies hiding their incompetencies from their customers? I thought of litigation and I almost sued Domino's, but who am I kidding? These cases could go on for years while they keep making people attack targets of hackers. And add to that corruption, and other variables. I don't know of what could be done to such companies. Boycotting helps, but imagine, more than half your customers don't know why the rest are boycotting and that's in your favor.
- lazyweb 5y agoHah, I was just logging into linkedin again after some months, looking at the landing page for a bit (before login). Wasn't aware they let you create accounts with passwords as short as six (!) characters.
- nzealand 5y agoThis hack includes inferred salary, facebook username, mobile number, geo location... None of this is publicly available. None of this can even be downloaded by myself when I get a copy of all my data from linkedin... https://www.linkedin.com/help/linkedin/answer/50191/downloading-your-account-data?lang=en https://www.linkedin.com/help/linkedin/answer/50191/download... So I have no idea what information about myself was leaked in this hack
- nojito 5y agoInferred salary is from salary estimates based on job titles. It isn’t tied to your personal data IIRC. It’s likely that an API endpoint was found and all the data was siphoned off.
- rcMgD2BwE72F 5y ago> Inferred salary is from salary estimates based on job titles. It isn’t tied to your personal data IIRC. How do you know? https://www.linkedin.com/help/linkedin/answer/4786/source-and-accuracy-of-salary-information-on-linkedin?lang=en https://www.linkedin.com/help/linkedin/answer/4786/source-an... >When we don’t have member-submitted data, salary insights are inferred using data between similar companies, job titles, location, and other job attributes. With enough "job attributes", you can easily tie things down to an individual: who worked as <position> at <company> in <city> from <start_date> to <end_date>, doing <job_description> with <colleagues>?
- nojito 5y agoBecause you get salary insights when you look at job postings which means it’s an API endpoint.
- nzealand 5y agoThe same API that was used in the April breach. https://restoreprivacy.com/linkedin-data-leak-700-million-users/ https://restoreprivacy.com/linkedin-data-leak-700-million-us... Even if you don't considered inferred salary directly tied to you as "personal data," surely you consider geo location personal data? Also, aren't you even slightly outraged that you can't even download data that has been hacked and released into the wild? Or outraged by the fact that you can only download data you have given directly to a service provider, but that the service provider will happily tell 3rd parties about your shadow profiles?
- skapadia 5y agoOh lord I wouldn't be surprised if recruiting companies pay to get this data.
- prennert 5y agoThe biggest issue: you cannot not give them your personal data that they then loose. Let me contribute with an anecdote from yesterday (slightly off-topic but I promise to get around to it at the end). So just yesterday I needed to create a Microsoft account to try out Teams which is supposedly free. (I have avoided it so far, but my GF has been asked to use it for an interview and we wanted to do a tech test run before). Of course, the UI on the website assumes (!) that you already have a Microsoft account. It will let you create a Teams account that will fail the login if you do not have a Microsoft account and then sends you around in a Byzantine loop without telling you: Look you need a Microsoft account to use Teams. It looks to me as it just creates a shallow alias or something without root reference. This is dark patterns all over the place. Anyway, a bit more on topic, I am course using my spam email for this account, but then they ask for my phone number. This is really an issue, because except if I get a burner phone, my personal data is linked with an account of a company I do not trust. After witnessing then how bad teams is almost 1.5 years after everyone is working remotely, (wow their web client does not allow you to share webcam and a window/screen at the same time, while their native client makes it super hard to share content while still seeing the people who you present to), I realised 1. How privileged I am not having to use Microsoft products (need to remember to charge extra, whenever asks me do a job that involves Microsoft products) 2. How anti-competitive Microsoft still is (you cannot login to Teams, MS web auth, in Chromium incognito mode, and it needs a ton of cookie domains whitelisted, even then it does not work) 3. How (and this is not Microsoft specific) difficult it is to not hand over personal data to companies that provide a utility-like service that they pretend is free (so everybody can pretend they are inclusive when they use these services) 4. An then literally a day later it turns out I am not paranoid not trusting Microsoft (and I guess other companies, big or small) with my data, because they are going to loose it sooner or later. Edit: I just logged back into this MS account. They dont even use the phone number as "2FA". They only send you a text when you register, not for subsequent logins. It looks to me as they just collect it to make sure they really have some personal data to loose..
- canadaduane 5y agoThe generous interpretation is that they need a way to give people something free while avoiding giving bots/spammers something free. You could point to CAPTCHA as a way to do this anonymously, but as far as I can tell, CAPTCHA has largely been broken by successful machine learning algos (most of the web scraping services I have seen offer "free CAPTCHA defeat" as a perk of buying their service).
- qjighap 5y agoI used to use linked'in@mycustomdomain.com. It (slightly) broke the interface for reasons I won't understand, but I eventually got lazy and changed it to a normal email. The extra page refreshes were driving me crazy. Seems I should have kept it.
- impreciouschild 5y ago"Hacker" collates linkedin users diligent self-doxing efforts.
- archsurface 5y agoBut you're fine because you didn't give them much personal data. Because by now you're perfectly aware of this scenario. So you take your privacy seriously.
- antpls 5y agoThat doesn't look like a "leak", but more like the usual mass scraping of APIs. An actual data leak from a breach would contain password hashes and private messages. It means somehow, people can access that "leaked" data anyway, either with APIs or by paying LinkedIn
- takeda 5y agoSo now we know where the security engineers from Western Digital went.
- danielEM 5y agoFeels a bit ackward to admit it nowadays, when nearly every job offer for IT proffessionals requires to provide LI profile link. But stopped using linkedin after first their leak with unencrypted passwords and not informing about it for months.
- bobbydreamer 5y agoBy the time this article is released, the scraped is stale. LinkedIn is self advertising portal for newer better opportunities and that data is actually in public view and someone is selling it to get me better opportunities it sort of sounds fine.. What would be informational is if so called hacker comes and says how he used the data or the tech stack used.