Troy Hunt, the Have I Been Pwned person, has a very informative analysis of the breach that was not a breach, turns out nothing actually "leaked" from Linkedin, it's a mix of scrapped and generated stuff
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
Yeah but that doesn't get the clicks!!!!11one!
It says it's scraped and not leaked
Well, fuck. This was the ONE social media site that I put my data on, and that was out of necessity (job hunting). I know it's not the same, but this sort of feels like the Equifax breach.
If it's any consolation, LinkedIn is notoriously terrible at this, so your data was probably out there as early as 2016 and almost certainly after 2021, when they managed to get hit with similar breaches twice in the same year.
And we share real background information, very specific details. This could lead them to our friends and colleagues!
But I'm not sure it can be called social media, though, but if you are looking for social media platforms that can avoids data leaks, and don't ask for your personal info when register, WireMin and Damus are both good choices.
Speaking of which, we should have a version of LinkedIn that is decentralized!
linked in that is decentralized
Now you shut your damn mouth, let's just let Linked In die like it was always supposed to. It's not some sort of positive networking platform, it's just a platform that reinforces the old boys club, with some cringey posts from people who are trying to hard.
It’s not an actual leak. It’s mostly scraped data and fake addresses.
What private info is on LinkedIn? I thought the whole point was to make your resume public and get found by employers.
Yeah it's the only public social media I have with any personal information. If it leaks I'm fine with that because I use VPN and even have my email alias on there.
Can someone check if my password is there? It's 'dupa.7'. Thanks.
dupa.7
https://haveibeenpwned.com/Passwords confirms that is has been hacked 11 times.
Ok, changed to 'dupa.8'. Thanks.
s e c u r i t y
Or the most secure one: hunter2
What's that? All I see is *******
I see Lemmy has implemented Reddit's security settings. Impressive.
~~Reddit~~
IRC ftfy
This password has been seen 2,265 times before
I'm excited for my class action award of $3
Figures. The only way to get someone interested in my linkedin account is for them to steal the data.
Let me know if you see anything you like. I didn't put it on there but I'm also proficient in bocce ball
The jokes on LinkedIn. T-Mobile already has my social security number, birth date, and other important information on the dark web, thanks to their security breach.
Don't forget Equifax, assuming you are in the USA
Strangely enough, that data doesn't seem to have surfaced anywhere. There's a decent chance it was stolen by a nation-state actor using it for espionage.
Slightly refreshing from them selling your email to spammers as soon as you signed up.
Again and again and again and again. I get more spam on my linkedin email address than I do on any other.
I have a set it up so that any email sent to unknown users on my domain gets redirected to email. If you send an email to bad_address@example.com
and my real email is uranibaba@example.com
, I will still receive the email.
Now this is great because I will just use name_of_service@example.com
and still get the email. If the email is leaked, I will know where it came from.
Owning your own domain is great that way. Even makes the little bit I pay to ProtonMail well worth it. There are a few addresses I have dedicated, like my aws@example.com, me@, and my-name@, but the rest just go to a catch all. It's fantastic.
I ended up just disabling the alias I use to receive emails from LinkedIn. Since I noticed I just kept deleting those emails without ever reading them, I figured I'd just opt to not receive any emails. :D
That would explain the targeted scams I've been subjected to which seem to have been coming from old colleagues
Now I know why I'm getting scam mails on the email address that I never use online and scam phonecalls on the phone number I never use online, except for LinkedIn.
Gadammit, my linkedin uses my clean email account. Linkedin security, do better!
Was surprised at first, then I went to go log in to change my password.
And then it said I was emailed a 2FA code... the code was part of the email header.
Now I'm completely unsurprised this happened.
I'm not sure what you're implying here regarding headers? Email is insecure regardless; even when using SMTP with TLS, it's not like the headers are exposed whereas the body would be encrypted or something.
the code was part of the
... part of the Subject header in the encrypted body of the message, you mean? What a nothing-burger.
That's why today I got an email from a headhunter that used Data from my LinkedIn profile. Fuck this.
no because they probably paid a couple of hundred bucks to email you from one of the many data banks that source their information from LinkedIn.
Doesn’t sound like anything that hasn’t already been leaked elsewhere, boring 🥱
Not to mention its on my resume so its pretty available.
Anyone got an onion url to that forum? Asking for a friend.
It’s just BreachForums. Pretty sure the whole site is a honey pot.