Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My linkedin account got taken over a couple months ago. The attacker changed the phone number and immediately added 2FA, but they didn’t control my email. During account recovery LinkedIn suspended the account and asks for ID verification, through a 3p vendor who do government id verification. That passed and LinkedIn said I could login and reset, but it still stayed suspended and asked for id again. My guess is they drowned in complexity in their own recovery flow and I hit an edge case or something.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: