Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You just verify that you have access to an email address that belongs to a company (@example.com) by entering a six digit code they send to your work email. This in theory verifies that you work there, but obviously nothing else like your actual position at the company.

From an attacker standpoint, if an attacker gains access to any email address with @example.com, they could pretend to be the CEO of example.com even if they compromised the lowest level employee.



This is a optional/invite only feature. LinkedIn doesn't provide that work email validation feature for all employers on their platform. Why did I know that? Because my past startup was requesting LinkedIn to enable that so that we can enable that feature but they said it's an invite only feature. Internally, I think they are only invite those employers who has certain amount of employees and/or revenues to turn it on.

Apple / Google developer program uses Dun&Bradstreet to verify company and developer identities. That's another way. But LinkedIn doesn't have that feature (yet).


You just verify that you have access to an email address that belongs to a company (@example.com)

Bad idea.

I never had my work e-mail address on LinkedIn, but then I made the mistake of doing this, and LinkedIn sold my work e-mail address to several dozen companies that are still spamming me a year later.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: