Elektrine lite

← Feed

@Ivovanwilligen@mastodon.social

Post #358048

2026-02-21 22:04 UTC

I wanted the blue checkmark on LinkedIn. The one that says “this person is real.” In a sea of fake recruiters, bot accounts, and AI-generated headshots, it seemed like a smart thing to do. So I tapped “verify.” I scanned my passport. I took a selfie. Three minutes later — done. Badge acquired. I felt a tiny dopamine hit of legitimacy. Then I did what apparently nobody does. I went and read the privacy policy and terms of service. Not LinkedIn’s. The other company’s. https://thelocalstack.eu/posts/linkedin-identity-verification-privacy/

Replies (40)

  • @alstonvicar@know.me.uk 2026-02-22 22:39

    @Ivovanwilligen@mastodon.social this is why I don't have a blue tick

    Open ##367523

  • @Ivovanwilligen@mastodon.social Wow, I quite linkedin years ago, look how smart was that. Anyway out of all the stuff on the list, the least expected and most scary seems the behavioural profiling. Hesitation detection? WT_?!

    Open ##371356

  • @Ivovanwilligen@mastodon.social Thank you for your service.

    Open ##373925

  • @Ivovanwilligen@mastodon.social I shared this on LinkedIn - let's see if shadow ban happens instantly or later :D. Thank you!

    Open ##375093

  • @Ivovanwilligen@mastodon.social #SimpedIn

    Open ##587198

  • @Tarheel@theatl.social 2026-02-22 00:53

    @Ivovanwilligen I'm speechless. Thank you for going to what was obviously a great deal of trouble to warn us all.

    Open ##1752720

  • @superflippy@mastodon.xyz 2026-02-22 00:55

    @Ivovanwilligen Thanks for doing this research.

    Open ##1752721

  • @Ivovanwilligen Is this the Clear thing? I saw what they wanted and thought, “no thanks.”

    Open ##1752722

  • @Ivovanwilligen my company gives their employees security classes twice a year and one of the first things they teach you is to not share personal data with anyone since you can't control who ultimately uses it. I'm sorry you're going through this. That's quite nerve wracking and LinkedIn should be held accountable

    Open ##1752723

  • @Theriac@plasmatrap.com 2026-02-22 07:59

    @Ivovanwilligen@mastodon.social As an individual that bails on a website that insists I don't connect anonymously, I really have a hard time understanding the compliance here. Set up a web site if you want to establish an online presence.

    Open ##1752724

  • @tansy@wandering.shop 2026-02-22 11:00

    @Ivovanwilligen holy crap - thanks for pointing this out. Appreciate it and will share!

    Open ##1752738

  • @melroy@mastodon.melroy.org 2026-02-22 12:38

    @Ivovanwilligen ow no.. Ow no no no no. It's the same company as Discord and Roblox. Persona is evil.

    Open ##1752740

  • @donhawkins@mastodon.social 2026-02-22 14:20

    @Ivovanwilligen @AnnaAnthro I dumped LI when Microslop bought them. Even with 6k+ connections. Haven’t missed LI for a second.

    Open ##1752742

  • @Ivovanwilligen Oh shit 😣🤦‍♂️ Persona 😥😵‍💫

    Open ##1752744

  • @mwop@phpc.social 2026-02-22 20:12

    @Ivovanwilligen I'd considered doing verification there, but when I saw the requirement of the passport scan, I decided there was no way in hell I'd proceed - the possibility of identity theft with third parties processing the data just seemed too high. Your digging validates that see decision. Yikes!

    Open ##1752752

  • @tsadiq@rivals.space 2026-02-22 21:59

    @Ivovanwilligen i lost access to my account a while ago when someones which was not me tried to login too many times with a wrong password. If i want my account back, i must go through this process to prove that i'm the actual owner of the account 🙃 Good thing i haven't been looking for customers lately, but it makes me wonder what will happen when i need to 🫣

    Open ##1752753

  • @lukeharby@infosec.exchange 2026-02-22 22:09

    @Ivovanwilligen The slow but complete erosion of privacy.

    Open ##1752754

  • @arildsen@mastodon.green 2026-02-22 23:08

    @Ivovanwilligen damn, thanks for looking into this. I naively did the verification some time ago and embarrassingly did not pay attention to the details. Time for me to get them to delete my data…

    Open ##1752766

  • @Ivovanwilligen I'm curious to know if your deletion request and objection to the DPO were acknowledged/honored?

    Open ##1752771

  • @plluksie@mastodon.social 2026-02-22 23:57

    @Ivovanwilligen for the sake of completeness - this persona: https://vmfunc.re/blog/persona/ #privacy #security #persona

    Open ##1752772

  • @cdb_77@mastodon.online 2026-02-23 05:54

    @Ivovanwilligen OMG! "And then there’s the weird stuff: Hesitation detection — they tracked whether I paused during the process Copy and paste detection — they tracked whether I was pasting information instead of typing it Behavioral biometrics. On top of the physical biometrics. For a LinkedIn badge." #LinkedIn #Persona

    Open ##1752773

  • @f_u_e_n_t_e@mastodon.social 2026-02-23 06:37

    @Ivovanwilligen I started the process twice in the past year - both times my spidey-sense started tingling and I didn’t scan any documents. Anthropic, AWS, OpenAI, Google, GrokAI… why would you need all of those as sub-processors?? Unless you’re using “subprocessor” as a means to share the data… Thanks for confirming my gut feeling. And for posting this warning for others!

    Open ##1752776

  • @bonkers@nerdculture.de 2026-02-23 06:50

    @Ivovanwilligen I deleted my profile instead. It was only a source of useless notifications and spam.

    Open ##1752777

  • @paul@notnull.space 2026-02-23 08:36

    @Ivovanwilligen does anybody know, from a legal perspective, how something like this sits with GDPR saying data can't be processed outside of the EU (or I guess, GDPR respecting countries? I suppose that's all buried in the terms and conditions somewhere.... "you consent to..."

    Open ##1752778

  • @aliide@mstdn.social 2026-02-23 09:08

    @Ivovanwilligen at Christmas I purchased a mini bottle of Japanese cider online as a stocking filler, something similar happened, was redirected to a third party service called verifymyage, to which I was supposed to upload my documents — they also employ "age estimation" by "analysing physical features". Of course I refused to participate in this insanity, and I eventually could do it with the supplier manually. But it's insane that this was the default and I even had to ask. #ageverification

    Open ##1752780

  • @AnthroBlogger@chaos.social 2026-02-23 10:22

    @Ivovanwilligen very interesting. Thanks!

    Open ##1752781

  • @janneke@todon.nl 2026-02-23 11:34

    @Ivovanwilligen This is terrible but I can't help wondering; why did you initially think that giving Microsoft (the owner of LinkedIn) all this data was a good idea, or at least, mostly harmless?

    Open ##1752782

  • @Ivovanwilligen Great warning about LinkedIn. Can you put a #linkedin #ID #verification hash in the main post ?

    Open ##1752783

  • @AnthroBlogger@chaos.social 2026-02-23 13:02

    @Ivovanwilligen #Persona https://www.malwarebytes.com/blog/news/2026/02/age-verification-vendor-persona-left-frontend-exposed

    Open ##1752784

  • @Simaj@toot.aquilenet.fr 2026-02-23 13:38

    @Ivovanwilligen Maybe you can use this work to help complete their page in the extension Terms of service didn't read ? It's empty... https://tosdr.org/fr/service/11449

    Open ##1752786

  • @wolf@fedi.solibre.de 2026-02-23 14:18

    @Ivovanwilligen they sit invisibly between you and the platforms you trust. But you don't trust Linkedin, no?

    Open ##1752787

  • @wthinker@libranet.de 2026-02-23 15:00

    @Ivovanwilligen Good article. I translated this to russian.

    Open ##1752789

  • @knowprose@mastodon.social 2026-02-23 15:23

    @Ivovanwilligen Your points are done well so I was able to link to it and pivot to the infrastructural cost as well. The privacy issue is real. It's also a great example of how much #AI use cumulates in something that is allegedly simple. Like your post, I posted it to LinkedIn as well. *sighs in Taran* https://knowprose.com/2026/02/the-infrastructure-cost-of-being-verified/

    Open ##1752790

  • @pcxt@piaille.fr 2026-02-23 15:32

    @Ivovanwilligen thanks for the story and the warning ! I had to make such a verification for the UK government to travel there. They call it ETA (electronic travel authorisation) I wouldn’t be surprised if they were client of such companies instead of doing it themselves with their own means. Does anyone know smth about it ?

    Open ##1752791

  • @pzumk@norden.social 2026-02-23 18:20

    @Ivovanwilligen why did you add quotation marks?

    Open ##1752792

  • @nossipova@mastodon.social 2026-02-23 21:04

    @Ivovanwilligen @nicklockwood OTOH, the data you listed under the first seven bullet points gets collected at every airport when you cross the EU border.

    Open ##1752793

  • @geolaw@aus.social 2026-02-23 21:10

    @Ivovanwilligen I predict that the public list of companies they share data with will inevitably become non-public

    Open ##1752794

  • @Ivovanwilligen LinkedIn is owned by Microsoft, notoriously the earliest collaborator into the PRISM program unveiled by Snowden. No surprises here.

    Open ##1752795

  • @dflag84@fosstodon.org 2026-02-24 02:10

    @Ivovanwilligen Linked In needs to disappear for something better and decentralized. I hate that it became the new Facebook with AI and influencers. I have to be on it for my business but I hate it. It's not for professionals anymore.... 😞

    Open ##1752796

  • @Lats@aus.social 2026-03-08 12:37

    @Ivovanwilligen interlinked services are a worry, they have to be available for the platform to work, they can be security vulnerability, they can be costly and their terms and costs can change after adoption. Now they can be harvesting clients/users details.

    Open ##1752798