Security clearance publicly posted

A friend of the family publicly posted “Secret Clearance” on a LinkedIn profile as part of the verbiage immediately seen on the person’s landing page. I was shocked when I saw it.

I’m not an expert and don’t know if this is a violation vs. stupid, but at a minimum it seems like it would be a security risk for bad actors to potentially compromise this person? Who BTW works in IT for DHS. I thought clearances were to be kept more on the down low and suggested to the person they remove the clearance and stop advertising it.

Countless linkedin profiles list TS/SCI, or if they have a poly. Is it good OPSEC? Maybe not, but i don’t think it’s a security issue.

I’ve seen resumes list which compartments they’re read in it. Security violation? Not that I’m aware, but definitely bad practice

2 Likes

There’s nothing wrong with listing your clearance on your resume or job profile. Just don’t go into detail about it.

1 Like

A former co-worker did not list his clearance but did mention some information security related technologies he worked on. After a number of mysterious friend requests (or whatever LinkedIn calls it), he decided to take that information off his page.

By the way, there was a news article in the computer security headlines about Microsoft (who now runs LinkedIn) loading some kind of HUGE javascript file onto your computer to look for various extensions you have loaded into your browser. Have not heard the rest of this but I dont think Microsoft really needs to know that so I have not visited LinkedIn recently.

1 Like

I don’t doubt you read that, but I find that hard to believe they would actually be doing that since Microsoft is so risk averse. That kind of thing can make them vulnerable to litigation. Maybe LinkedIn was doing it before MS came in?

Just don’t do it. It’s not a violation. It’s just bad OPSEC. Imply that you have it. Just don’t outright write it.

1 Like

This is where I heard about it: Security Now! Transcript of Episode #1073

Who in turn cited this website: https://browsergate.eu

Microsoft admits they’re doing it but say it really isn’t that bad…

2 Likes

No. There is nothing wrong with listing your clearance on your profile. This is the advice I have seen in multiple places in my career by security.

2 Likes

There is absolutely nothing wrong with saying you have a clearance or where you have worked unless you are in a protected status. It’s common practice. If you aren’t able to be compromised, then there is no reason to fear it. People get pitched all the time, Simply report it.

2 Likes

wow! Glad I don’t use LinkedIn. Also glad I use Firefox.

I see nothing wrong with listing your clearance on LinkedIn or your resume as long as you are not disclosing any sensitive information about your job.

Technical no no but eryone out here doing it. Recruiters looking for TS SCI Full poly…want to recruit them. So mentioning it works