Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Darkly)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. If you're on LinkedIn and are thinking about verifying your account with them, maybe read this first.

If you're on LinkedIn and are thinking about verifying your account with them, maybe read this first.

Scheduled Pinned Locked Moved Uncategorized
115 Posts 80 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • BrianKrebsB BrianKrebs

    If you're on LinkedIn and are thinking about verifying your account with them, maybe read this first. It walks through LinkedIn's privacy disclosure to identify 17 companies that may receive and process the data you submit, including name, passport photo, selfie, facial geometry, NFC data chip, national ID #, DoB, email, phone number, address, IP address, device type, MAC address, language, geolocation etc. Unsurprisingly, it seems the biggest recipients are US-based AI companies.

    https://thelocalstack.eu/posts/linkedin-identity-verification-privacy/

    BrianKrebsB This user is from outside of this forum
    BrianKrebsB This user is from outside of this forum
    BrianKrebs
    wrote last edited by
    #71

    The CEO of Persona responded to this post, saying they wanted to clarify about the identity verification process. They said:

    "The only subprocessors (8) used are: AWS, Confluent, DBT, ElasticSearch, GCP, MongoDB, Sigma Computing, and Snowflake

    All biometric personal data is deleted immediately after processing.

    All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot.

    No personal data processed is used for AI/model training. Data is explicitly used to confirm your identity.

    The subprocessors used do NOT include Anthropic, Groqcloud, or OpenAI. The referenced subprocessor list is the superset of subprocessors used across all customers which is unfortunately misleading - we are updating our documentation to make this clearer going forward (thank you for helping us realize this). Our customers select which products are used which determines which subprocessors are used."

    Kevin Karhan :verified:K David Penfold :verified:D Christian RickertC RootWyrm 🇺🇦:progress:R GunChleocG 13 Replies Last reply
    0
    • celeste 💫C celeste 💫

      @briankrebs@infosec.exchange hi, reading through this and i assume you're posting this after my research piece came up since you mention all the checks persona are running. could you please attribute credit?

      https://www.malwarebytes.com/blog/news/2026/02/age-verification-vendor-persona-left-frontend-exposed

      https://vmfunc.re/blog/persona

      BrianKrebsB This user is from outside of this forum
      BrianKrebsB This user is from outside of this forum
      BrianKrebs
      wrote last edited by
      #72

      @celeste Unless I'm missing something, the post I linked to and cited from was published 4 days before yours. It's not about the reported frontend exposure.

      celeste 💫C 1 Reply Last reply
      0
      • BrianKrebsB BrianKrebs

        The CEO of Persona responded to this post, saying they wanted to clarify about the identity verification process. They said:

        "The only subprocessors (8) used are: AWS, Confluent, DBT, ElasticSearch, GCP, MongoDB, Sigma Computing, and Snowflake

        All biometric personal data is deleted immediately after processing.

        All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot.

        No personal data processed is used for AI/model training. Data is explicitly used to confirm your identity.

        The subprocessors used do NOT include Anthropic, Groqcloud, or OpenAI. The referenced subprocessor list is the superset of subprocessors used across all customers which is unfortunately misleading - we are updating our documentation to make this clearer going forward (thank you for helping us realize this). Our customers select which products are used which determines which subprocessors are used."

        Kevin Karhan :verified:K This user is from outside of this forum
        Kevin Karhan :verified:K This user is from outside of this forum
        Kevin Karhan :verified:
        wrote last edited by
        #73

        @briankrebs still means data is subject to #CloudAct = incompatible with #GDPR & #BDSG!

        Human after allH 1 Reply Last reply
        0
        • Kevin Karhan :verified:K Kevin Karhan :verified:

          @briankrebs still means data is subject to #CloudAct = incompatible with #GDPR & #BDSG!

          Human after allH This user is from outside of this forum
          Human after allH This user is from outside of this forum
          Human after all
          wrote last edited by
          #74

          @kkarhan @briankrebs Look where Linkedin has its HQ in Europe. Ireland. The shittest DPO in the Union and under political pressure to keep the FDI money coming into Ireland. The one stop shop approach by the EU does NOT work

          Kevin Karhan :verified:K 1 Reply Last reply
          0
          • BrianKrebsB BrianKrebs

            The CEO of Persona responded to this post, saying they wanted to clarify about the identity verification process. They said:

            "The only subprocessors (8) used are: AWS, Confluent, DBT, ElasticSearch, GCP, MongoDB, Sigma Computing, and Snowflake

            All biometric personal data is deleted immediately after processing.

            All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot.

            No personal data processed is used for AI/model training. Data is explicitly used to confirm your identity.

            The subprocessors used do NOT include Anthropic, Groqcloud, or OpenAI. The referenced subprocessor list is the superset of subprocessors used across all customers which is unfortunately misleading - we are updating our documentation to make this clearer going forward (thank you for helping us realize this). Our customers select which products are used which determines which subprocessors are used."

            David Penfold :verified:D This user is from outside of this forum
            David Penfold :verified:D This user is from outside of this forum
            David Penfold :verified:
            wrote last edited by
            #75

            @briankrebs And what assurances do they have that Snowflake etc aren't keeping copies? You don't master a cloud supply chain.

            Vick Forcella ™🌈🌳❄️☑️:verifiV EmoryE 2 Replies Last reply
            0
            • BrianKrebsB BrianKrebs

              The CEO of Persona responded to this post, saying they wanted to clarify about the identity verification process. They said:

              "The only subprocessors (8) used are: AWS, Confluent, DBT, ElasticSearch, GCP, MongoDB, Sigma Computing, and Snowflake

              All biometric personal data is deleted immediately after processing.

              All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot.

              No personal data processed is used for AI/model training. Data is explicitly used to confirm your identity.

              The subprocessors used do NOT include Anthropic, Groqcloud, or OpenAI. The referenced subprocessor list is the superset of subprocessors used across all customers which is unfortunately misleading - we are updating our documentation to make this clearer going forward (thank you for helping us realize this). Our customers select which products are used which determines which subprocessors are used."

              Christian RickertC This user is from outside of this forum
              Christian RickertC This user is from outside of this forum
              Christian Rickert
              wrote last edited by
              #76

              @briankrebs

              I'd take a pinky-finger promise from a third-party company over any data privacy law! 💯

              1 Reply Last reply
              0
              • BrianKrebsB BrianKrebs

                The CEO of Persona responded to this post, saying they wanted to clarify about the identity verification process. They said:

                "The only subprocessors (8) used are: AWS, Confluent, DBT, ElasticSearch, GCP, MongoDB, Sigma Computing, and Snowflake

                All biometric personal data is deleted immediately after processing.

                All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot.

                No personal data processed is used for AI/model training. Data is explicitly used to confirm your identity.

                The subprocessors used do NOT include Anthropic, Groqcloud, or OpenAI. The referenced subprocessor list is the superset of subprocessors used across all customers which is unfortunately misleading - we are updating our documentation to make this clearer going forward (thank you for helping us realize this). Our customers select which products are used which determines which subprocessors are used."

                RootWyrm 🇺🇦:progress:R This user is from outside of this forum
                RootWyrm 🇺🇦:progress:R This user is from outside of this forum
                RootWyrm 🇺🇦:progress:
                wrote last edited by
                #77

                @briankrebs and if you believe this from a company where the executives hide from the public, explicitly authoritarian goals of irreversibly identifying everyone online, and direct ties to outspoken Nazis and fascists through funding?

                Then all you need to do is pay the $5000 processing fee in Visa gift cards, and I can transfer you $500M USD from the Euorpean lottery tomorrow.

                RootWyrm 🇺🇦:progress:R 1 Reply Last reply
                0
                • BrianKrebsB BrianKrebs

                  The CEO of Persona responded to this post, saying they wanted to clarify about the identity verification process. They said:

                  "The only subprocessors (8) used are: AWS, Confluent, DBT, ElasticSearch, GCP, MongoDB, Sigma Computing, and Snowflake

                  All biometric personal data is deleted immediately after processing.

                  All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot.

                  No personal data processed is used for AI/model training. Data is explicitly used to confirm your identity.

                  The subprocessors used do NOT include Anthropic, Groqcloud, or OpenAI. The referenced subprocessor list is the superset of subprocessors used across all customers which is unfortunately misleading - we are updating our documentation to make this clearer going forward (thank you for helping us realize this). Our customers select which products are used which determines which subprocessors are used."

                  GunChleocG This user is from outside of this forum
                  GunChleocG This user is from outside of this forum
                  GunChleoc
                  wrote last edited by
                  #78

                  @briankrebs Aye right, totally trustworthy company https://youtube.com/watch?v=S-Jo-djilvo

                  1 Reply Last reply
                  0
                  • RootWyrm 🇺🇦:progress:R RootWyrm 🇺🇦:progress:

                    @briankrebs and if you believe this from a company where the executives hide from the public, explicitly authoritarian goals of irreversibly identifying everyone online, and direct ties to outspoken Nazis and fascists through funding?

                    Then all you need to do is pay the $5000 processing fee in Visa gift cards, and I can transfer you $500M USD from the Euorpean lottery tomorrow.

                    RootWyrm 🇺🇦:progress:R This user is from outside of this forum
                    RootWyrm 🇺🇦:progress:R This user is from outside of this forum
                    RootWyrm 🇺🇦:progress:
                    wrote last edited by
                    #79

                    @briankrebs which is to say: absofuckingloutely Persona is lying. They've lied the whole time. These are the same dipshits that left their entire system exposed which revealed that, surprise! They're storing all the biometrics permanently and just straight lying about everything top to bottom!

                    1 Reply Last reply
                    0
                    • Human after allH Human after all

                      @kkarhan @briankrebs Look where Linkedin has its HQ in Europe. Ireland. The shittest DPO in the Union and under political pressure to keep the FDI money coming into Ireland. The one stop shop approach by the EU does NOT work

                      Kevin Karhan :verified:K This user is from outside of this forum
                      Kevin Karhan :verified:K This user is from outside of this forum
                      Kevin Karhan :verified:
                      wrote last edited by
                      #80

                      @humanhorseshoes @briankrebs that's due to #Ireland artifically grifting itself into a "#nearshore #TaxHaven"…

                      See "#DoubleDutchIrishSandwich" #TaxEvasion setup…

                      Human after allH 1 Reply Last reply
                      0
                      • Kevin Karhan :verified:K Kevin Karhan :verified:

                        @humanhorseshoes @briankrebs that's due to #Ireland artifically grifting itself into a "#nearshore #TaxHaven"…

                        See "#DoubleDutchIrishSandwich" #TaxEvasion setup…

                        Human after allH This user is from outside of this forum
                        Human after allH This user is from outside of this forum
                        Human after all
                        wrote last edited by
                        #81

                        @kkarhan @briankrebs That loophole has closed and the argument that any EU country could do what Ireland have done is valid too. I will concede that the DPO is very weak and deliberately so

                        Kevin Karhan :verified:K 1 Reply Last reply
                        0
                        • Human after allH Human after all

                          @kkarhan @briankrebs That loophole has closed and the argument that any EU country could do what Ireland have done is valid too. I will concede that the DPO is very weak and deliberately so

                          Kevin Karhan :verified:K This user is from outside of this forum
                          Kevin Karhan :verified:K This user is from outside of this forum
                          Kevin Karhan :verified:
                          wrote last edited by
                          #82

                          @humanhorseshoes @briankrebs OFC it is too weak ON PURPOSE!

                          • #GDPR should've been sharper and harder than #BDSG and #COPPA together, banning the #BusinessModel of #DataBrokers like #NSAbook / #StasiBook for good!
                          Human after allH 1 Reply Last reply
                          0
                          • Kevin Karhan :verified:K Kevin Karhan :verified:

                            @humanhorseshoes @briankrebs OFC it is too weak ON PURPOSE!

                            • #GDPR should've been sharper and harder than #BDSG and #COPPA together, banning the #BusinessModel of #DataBrokers like #NSAbook / #StasiBook for good!
                            Human after allH This user is from outside of this forum
                            Human after allH This user is from outside of this forum
                            Human after all
                            wrote last edited by
                            #83

                            @kkarhan @briankrebs GDPR is poorly implemented all over the EU, for example if you set up outside the EU and have EU data subjects and business nobody wants to touch you and you can do whatever you like

                            Kevin Karhan :verified:K 1 Reply Last reply
                            0
                            • BrianKrebsB BrianKrebs

                              The CEO of Persona responded to this post, saying they wanted to clarify about the identity verification process. They said:

                              "The only subprocessors (8) used are: AWS, Confluent, DBT, ElasticSearch, GCP, MongoDB, Sigma Computing, and Snowflake

                              All biometric personal data is deleted immediately after processing.

                              All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot.

                              No personal data processed is used for AI/model training. Data is explicitly used to confirm your identity.

                              The subprocessors used do NOT include Anthropic, Groqcloud, or OpenAI. The referenced subprocessor list is the superset of subprocessors used across all customers which is unfortunately misleading - we are updating our documentation to make this clearer going forward (thank you for helping us realize this). Our customers select which products are used which determines which subprocessors are used."

                              Paul HutchingsS This user is from outside of this forum
                              Paul HutchingsS This user is from outside of this forum
                              Paul Hutchings
                              wrote last edited by
                              #84

                              @briankrebs this also contradicts their own privacy policy which calls out companies like OpenAI. Also don't remember it saying anything about any data being deleted after any period of time too.

                              (This was for a wire transfer and I politely said fuck you and got a cashiers check instead)

                              1 Reply Last reply
                              0
                              • BrianKrebsB BrianKrebs

                                The CEO of Persona responded to this post, saying they wanted to clarify about the identity verification process. They said:

                                "The only subprocessors (8) used are: AWS, Confluent, DBT, ElasticSearch, GCP, MongoDB, Sigma Computing, and Snowflake

                                All biometric personal data is deleted immediately after processing.

                                All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot.

                                No personal data processed is used for AI/model training. Data is explicitly used to confirm your identity.

                                The subprocessors used do NOT include Anthropic, Groqcloud, or OpenAI. The referenced subprocessor list is the superset of subprocessors used across all customers which is unfortunately misleading - we are updating our documentation to make this clearer going forward (thank you for helping us realize this). Our customers select which products are used which determines which subprocessors are used."

                                A-nom-nom-nom-aly BSC SSCA This user is from outside of this forum
                                A-nom-nom-nom-aly BSC SSCA This user is from outside of this forum
                                A-nom-nom-nom-aly BSC SSC
                                wrote last edited by
                                #85

                                @briankrebs

                                The CEO of Persona... can go fuck themselves.

                                1 Reply Last reply
                                0
                                • Human after allH Human after all

                                  @kkarhan @briankrebs GDPR is poorly implemented all over the EU, for example if you set up outside the EU and have EU data subjects and business nobody wants to touch you and you can do whatever you like

                                  Kevin Karhan :verified:K This user is from outside of this forum
                                  Kevin Karhan :verified:K This user is from outside of this forum
                                  Kevin Karhan :verified:
                                  wrote last edited by
                                  #86

                                  @humanhorseshoes @briankrebs exactly!

                                  IMHO #GDPR must be sharpened harder than #CloudAct (which is incompatible with it)!

                                  Human after allH 1 Reply Last reply
                                  0
                                  • BrianKrebsB BrianKrebs

                                    If you're on LinkedIn and are thinking about verifying your account with them, maybe read this first. It walks through LinkedIn's privacy disclosure to identify 17 companies that may receive and process the data you submit, including name, passport photo, selfie, facial geometry, NFC data chip, national ID #, DoB, email, phone number, address, IP address, device type, MAC address, language, geolocation etc. Unsurprisingly, it seems the biggest recipients are US-based AI companies.

                                    https://thelocalstack.eu/posts/linkedin-identity-verification-privacy/

                                    Paul LP This user is from outside of this forum
                                    Paul LP This user is from outside of this forum
                                    Paul L
                                    wrote last edited by
                                    #87

                                    @briankrebs excellent deep dive!
                                    Gee, I wish pur politics would read such summaries more often!
                                    After the discord breach, this is a blatant proof that the big tech companies are simply unable to be trusted to take responsibility to make identity or age verification!

                                    Paul LP 1 Reply Last reply
                                    0
                                    • BrianKrebsB BrianKrebs

                                      The CEO of Persona responded to this post, saying they wanted to clarify about the identity verification process. They said:

                                      "The only subprocessors (8) used are: AWS, Confluent, DBT, ElasticSearch, GCP, MongoDB, Sigma Computing, and Snowflake

                                      All biometric personal data is deleted immediately after processing.

                                      All other personal data processed is automatically deleted within 30 days. Data is retained during this period to help users troubleshoot.

                                      No personal data processed is used for AI/model training. Data is explicitly used to confirm your identity.

                                      The subprocessors used do NOT include Anthropic, Groqcloud, or OpenAI. The referenced subprocessor list is the superset of subprocessors used across all customers which is unfortunately misleading - we are updating our documentation to make this clearer going forward (thank you for helping us realize this). Our customers select which products are used which determines which subprocessors are used."

                                      definitely just a musicianT This user is from outside of this forum
                                      definitely just a musicianT This user is from outside of this forum
                                      definitely just a musician
                                      wrote last edited by
                                      #88

                                      @briankrebs

                                      In 2018 I was at a company where we had the first automated identity verification system in market

                                      I was one four engineers on the team at the end when we finally found PMF— verifying doctors in conjunction with Duo security to allow online prescriptions

                                      It was Ruby on Rails

                                      We had two products

                                      Knowledge
                                      Photo

                                      Knowledge was really just a pretty oauth flow wrapping a transition api

                                      Photo was Microsoft for facial recognition between the front of an ID and a selfie

                                      Front and back was through a provider (confirm) that had exclusive partnership with morpho trust that does all the identity verification at customs that can effectively detect the security features on IDs

                                      NIST LOA3 SOC2 HIPPA

                                      With three external surfaces

                                      All this to say: WTF is LinkedIn doing and if earth needs me to rebuild a product from a decade ago, we just need a few engineers— less engineers than persona has vendors

                                      definitely just a musicianT 1 Reply Last reply
                                      0
                                      • definitely just a musicianT definitely just a musician

                                        @briankrebs

                                        In 2018 I was at a company where we had the first automated identity verification system in market

                                        I was one four engineers on the team at the end when we finally found PMF— verifying doctors in conjunction with Duo security to allow online prescriptions

                                        It was Ruby on Rails

                                        We had two products

                                        Knowledge
                                        Photo

                                        Knowledge was really just a pretty oauth flow wrapping a transition api

                                        Photo was Microsoft for facial recognition between the front of an ID and a selfie

                                        Front and back was through a provider (confirm) that had exclusive partnership with morpho trust that does all the identity verification at customs that can effectively detect the security features on IDs

                                        NIST LOA3 SOC2 HIPPA

                                        With three external surfaces

                                        All this to say: WTF is LinkedIn doing and if earth needs me to rebuild a product from a decade ago, we just need a few engineers— less engineers than persona has vendors

                                        definitely just a musicianT This user is from outside of this forum
                                        definitely just a musicianT This user is from outside of this forum
                                        definitely just a musician
                                        wrote last edited by
                                        #89

                                        @briankrebs “first automated PHOTO verification”

                                        Jumio was our primary competitor

                                        They had people physically comparing pictures with a 60-90 second SLA

                                        We had APIs and even figured out how to optimize image size so uploads could be as small as possible on mobile while still able to catch security details

                                        Because of the sequencing of events, we basically had the results immediately at the end of the flow

                                        definitely just a musicianT 1 Reply Last reply
                                        0
                                        • definitely just a musicianT definitely just a musician

                                          @briankrebs “first automated PHOTO verification”

                                          Jumio was our primary competitor

                                          They had people physically comparing pictures with a 60-90 second SLA

                                          We had APIs and even figured out how to optimize image size so uploads could be as small as possible on mobile while still able to catch security details

                                          Because of the sequencing of events, we basically had the results immediately at the end of the flow

                                          definitely just a musicianT This user is from outside of this forum
                                          definitely just a musicianT This user is from outside of this forum
                                          definitely just a musician
                                          wrote last edited by
                                          #90

                                          @briankrebs all this to say— I do feel partially to blame for the mass proliferation of photo ID products since we proved it possible to automate

                                          The company went in a different direction, I was fired along with the rest of my team

                                          Sequoia was the primary investor of the company, so I assume the IP proliferated across their portfolio

                                          In very short order stripe launched photo id verification that was roughly shot for shot what I built as the front end lead

                                          Not a bad crash course in Silicon Valley economics and the hidden network effects

                                          Venture firms definitely encourage successful startups to run startups in their startups that benefit their other startups and they’ll win no matter what

                                          Miss GayleM 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups