5 ms·
I found a vulnerability in linkedIn a few years back that allowed anyone to access a private profile (because client side validation was enough for them I guess
by sparkywolf 7y ago
I found a vulnerability in linkedIn a few years back that allowed anyone to access a private profile (because client side validation was enough for them I guess..?)
They didn't take my report seriously (still not completely patched) and I feel like that told me all I needed to know about their security practices.
- john-radio 7y agoI reported an issue to the LinkedIn competitor https://about.me https://about.me two years ago where signing in with my Google credentials gives me access to some the account of some random other person with a similar name to me. I think that during registration, I attempted to register about.me/johnradio (except it's not "johnradio"), but he was already using it, and then the bug occurred that gave me this access. I randomly check every 6 months or so and yep, still not fixed.
- simonlc 7y agoI actually had a similar thing happen with facebook, though we didnt share names.
- jonathankoren 7y agoFor a while, our Comcast billing account accessed some other person’s account. Comcast didn’t take it seriously, and just told us to create a new account and not use the old one. (!!!) We had full access. I could have signed this person up for the most expensive package, or even canceled their service.
- mythrowaway1124 7y agoLet's be realistic here. Everyone knows it's not possible to cancel Comcast service.
- adjkant 7y ago"Ah yes, cancelling requires a call because of security. A feature for the user!"
- kova12 7y agoTo be fair, internets would have been equally outraged if there wasn't such requirement, because sure as hell somebody would have found an exploit and cancelled a bunch of account, just for funzies
- zentiggr 7y agoThat sounds like white hat hacking from all I've heard of Comcast... Maybe that's how we drive their customer count and revenue down and put them out of business.
- klyrs 7y agoI managed to cancel my dad's after he died. They STILL tried to upsell me! One of my favorite phrases ever uttered: "He's dead, you asshole, he doesn't need more channels!" And that actually did it. Felt sorry for the salesperson, who didn't have much of a choice in the matter...
- sjwright 7y agoSurely by making it difficult to cancel they’re really just making it easier for people to get discounts. If I were a Comcast customer I’d be calling up to cancel every few months.
- dmw_ng 7y agoI signed up for a disposable Gmail account using my real name at one point, and accepted the randomly suggested address it offered. Gmail loaded with someone else's obviously in use mailbox IIRC I logged out again and back in, same thing, my credentials worked. Went back to it a few days later and the password no longer worked
- wizzwizz4 7y agoHash collisions most likely.
- ta999999171 7y agoHave heard this so many times about Gmail... How have they not resolved this?
- joncrane 7y agoI think it's like EC2 instance IDs. When they first came up with it, they never thought there would be literally billions of unique email addresses/EC2 instances eventually.
- skissane 7y agoMy gmail is my first initial followed by my last name. There are other people on this planet with same first initial and last name, some of whom seem to think that must be their email too, because I keep on getting emails where they used it to sign up for things.
- williamscales 7y agoEven more baffling are the ones who use it to fill out job applications.
- sjwright 7y agoMy gmail is two initials and last name, so theoretically less susceptible to such errors. Yet I get misaddressed mail all the time—and a surprising amount of it is job applications!
- mrkstu 7y agoI get bank statements, job offers, party invitations, and lately a bunch of lets say very questionable email verifications from euro 'dating' sites- I've identified the guy in the UK but its too much (and getting embarrassing now) to keep forwarding his stuff to him. Downside of getting in early on popular email services.
- lazyasciiart 7y agoI went through several rounds of conversation with somebody's wedding planner over email.
- skissane 7y ago> but its too much (and getting embarrassing now) to keep forwarding his stuff to him What amazes me is when I get misaddressed email, and I reply to say its misaddressed (and I'm not talking about automated services, I'm talking about obviously manually sent stuff), and my reply just gets ignored and the misaddressed email just keeps on coming.
- Ayesh 7y agoI can only imagine about.me mass-creating profiles for names found on other web pages, and opening a way for someone to "claim" those profile with a matching Google account sign-in. About.me's business model was quite unsettling to me and they have made little to no effort to protect the user data from scrapers.
- modzu 7y agolinkedin is a computer virus
- stopadvertising 7y agoI deleted my linkedin a few years back when they had some bug where I would randomly get page views as some other person, with all their connections and account details and whatnot. It would only last a few minutes then switch me back to my account, but they aggressively ignored my attempts to reach out to them about this bug so I just gave up.
- paulgb 7y agoI had a similar experience. In 2014 I reported an issue where you could take over someone's account by adding an email you control to it and having them complete the flow by sending them a link (which, unless they looked very carefully, looked exactly like the regular log-in flow at the time - especially if they used a public email service and you registered a similar-looking account). I tried it on a friend and it worked, but LinkedIn's response was basically "meh". My life has only gotten better since I deleted LinkedIn a few years ago. I know I'm in a privileged position to be able to do that, but I strongly recommend everyone here consider whether what they gain from their account is worth the crap and spam they have to put up with.
- icebraining 7y agoLI is terrible if you actually try to use it, but it's harmless enough if you just use it as a profile hosting service, where people are likely to look. I just auto-archive their emails and only visit the site a couple of times per year.
- robbya 7y agoA few years of heads up is sufficient to disclose publicly. Full disclosure helps keep companies honest about security.
- adrianmonk 7y agoWhile not good, what's the connection to this story? The article says some LinkedIn data was scraped, but I don't see anywhere that it specifically says a LinkedIn security flaw was used in the scraping. Although it is vague about what data was scraped and how, so it doesn't preclude that either. In other words, are you saying a LinkedIn vulnerability was exploited here, or suggesting that it probably was, or are you just mentioning LinkedIn because it's tangentially related?
- Ayesh 7y agoI signed up for an API key to see what they have on me, and the data it returned looks awfully close to what I have on linked in.