9 ms·
I recommend filing a report with the Microsoft Security Response Center, especially in light that a malicious party may now have information on you, and as peop
by aspectmin 4y ago
I recommend filing a report with the Microsoft Security Response Center, especially in light that a malicious party may now have information on you, and as people below pointed out there may be (1) risk of Doxing, and/or (2) there are some suggestions that Microsoft (LinkedIn) employees may be compromised.
https://www.microsoft.com/en-us/msrc https://www.microsoft.com/en-us/msrc (Report an Issue)
- jupp0r 4y agoI wonder whether by compromised you mean: 1. compromised in the spy movie sense of them voluntarily passing information to the scammers (potentially for money) 2. compromised in the IT security sense of their accounts or computers having been hacked 3. some superset of 1. and 2.
- aspectmin 4y agoProbably simpler than both of those, more as in - there are allegations/comments suggesting that there may be individuals holding trusted positions who may not be as trustworthy as one would hope (based on the potential pathways by which malicious parties may have identified the OP). Insider threat is still a significant concern to companies, and were one representing Microsoft one might want to at least take a peek at what happened and make sure nothing untoward is occurring. Standard Disclaimers apply. I am not a Microsofty, nor do I play one on TV. Objects in the mirror may be closer than they appear.
- FunnyBadger 4y agoMy primary take-home from having DOD/DOE security clearances, and having to sit through historical case studies every 3 months about security breaches, is that every DOD/DOE security lapses and espionage event in history were "trusted insiders" doing the deed. Physical security was long ago solved by pre-20th century tech like locks and security guards. No, it was always a trusted insider. There's no reason to assume that is any different with social media companies.
- codetrotter 4y ago> in the spy movie sense It’s not just in the movies. https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/ https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lap... > Microsoft says LAPSUS$ — which it boringly calls “DEV-0537” — mostly gains illicit access to targets via “social engineering.” This involves bribing or tricking employees at the target organization or at its myriad partners, such as customer support call centers and help desks. > “Microsoft found instances where the group successfully gained access to target organizations through recruited employees (or employees of their suppliers or business partners),” Microsoft wrote.
- aaaaaaaaata 4y agoRecruited employees? Or people they unknowingly hired? Small distinction?
- vageli 4y agoRecruited to join in the scheme against their employer.
- namelessoracle 4y agoIt's not a small distinction. An organization deliberately trying to inject an asset into your company to do X or Y is a different problem to solve than an existing employee who was coopted. And the co opted case has a different problem in one motivated by gain vs one motivated by threats agains them.
- Drazey 4y ago
- hetspookjee 4y agoNot OP, but if you are from LinkedIn or affiliated in any way I hope you understand the apperance of you as a fresh account with 2 karma just inquiring for the case # must seem odd and not entirely legit. In any case, it raises a set of red flags for me.
- implements 4y ago80 days ago isn't new enough to be unduly alarming, surely?
- pc86 4y agoCertainly old enough to know that HN doesn't have DM capability unless it's a spam account.
- huhtenberg 4y agoThere's no DM on HN.
- SpelingBeeChamp 4y agoDo it anyway! :P
- Dave3of5 4y agoHighly strange post here.
- byteshock 4y agoI’m not sure I understand the value of reporting this to Microsoft? Wouldn’t it be better to submit an online tip to law enforcement? Is Microsoft doing law enforcement activity now?
- huhwat 4y agoLinkedIn is a Microsoft product, so they would have the ability and interest in understanding what broke here.
- aaaaaaaaata 4y agoWhat broke is probably their internal trust..
- CheBuzz 4y agoIt's the "probably" that they want to investigate and try to get to a "almost certainly"
- aspectmin 4y agoAs huhwat said - LinkedIn is part of Microsoft now. As such it is within the auspices of the MSRC
- soSadm4n 4y agoI recommend we let LinkedIn implode under the weight of useless spam and indifferent ownership. Network directly with engineers where they spend time online. Not recruiters in purpose built HR portals.
- toma_caliente 4y ago> Network directly with engineers where they spend time online Where would that be? I wouldn't recommend HN for networking purposes.
- mynegation 4y agoTeamBlind
- Tehchops 4y agoDiscourse on Blind makes HN look like the Athenian Assembly.
- mynegation 4y agoAgreed. Still beats vapid LinkedIn feed.
- Tehchops 4y agoYes. I have to ruthlessly prune anyone who reposts chaff... which is sadly a non-trivial number of individuals.
- soSadm4n 4y agoForums and chat rooms related to technologies you have experience with, want to learn. Slack and Discord have quite a few. Some like to complain about projects using Slack or Discord because they’re not open and can’t be archived publicly but really who is pulling value from old IRC logs today? Nostalgic lizard brain is all that is.