Reading Security.nl and going to CSS Day got me thinking about the amount of information we casually put online.
LinkedIn is useful, but a public profile also tells people where you work, what your role is and sometimes which teams, tools or projects you are involved with. Put a few profiles together and you can quickly get a decent picture of how a company works. That is useful context for phishing, impersonation and other targeted attacks.
That is why I made linkedinrisico.nl. It is a tiny one-page website that explains the risk in plain language. It is not meant to say that LinkedIn is always unsafe or that nobody should use it.
A small shared standard
I mainly wanted to put something online that employers and employees can point to. Employers should not make a LinkedIn profile the only way to show professional experience. A CV, portfolio, personal website, GitHub profile or reference can work just as well. Employees should also be able to explain why they prefer to keep their public digital footprint small.
Hopefully the page creates a little more security awareness and makes that conversation easier. If it helps even one person, that is great. If it does not, that is fine too. I still think it was worth putting the idea out there.