Live data from Hacker News

What LinkedIn Could Learn From OKCupid and Others

iamvictorio.us

11–15 of 15 posts

Re: What LinkedIn Could Learn From OKCupid and Others

#11
post #8
post #3

Earlier quoted context omitted.

Yep. I never click on website profiles when I know that the person can see the visits. The good thing about LinkedIn is you can turn that off, but even then, I notice it adds the person to the suggested users list after a month or so (I wonder if it adds me to their suggested list?). There's lots of reasons why I don't want people to know. Like for example, a friend works at company x, so every so often I look at oth…

With my experience, LinkedIn will say that you are an anonymous user or give me a list of 15 people to guess who you are. I also don't think the people recommendations algorithm includes whose profile you visit.

with a paid account the information is a lot more detailed and definitely identifies specific people.

Re: What LinkedIn Could Learn From OKCupid and Others

#12
post #9

Something Linkedin ought to be taken to task for (Which they continue to get away with) -- phishing: Linkedin will show you a login-like screen with your email address pre-populated and a password prompt. Two dangerous things can happen: 1) a user can absent-mindedly assume they're at their email login page and type in their email password (less likely) 2) a user can absent-mindedly assume that this is the Linkedin l…

I'm almost certain LinkedIn doesn't try to use your username/password you use for the site to access your email. Triggering millions of password failures on gmail/yahoo/etc. is not something that they would risk. During signup, if you are on one of the major webmail services, it will explicitly ask you to authorize yourself on them so it can get your contacts however. Having worked there and specifically as product m…

That's not what the OP said. Linkedin presents a form on the front page after you're logged in that specifically asks you to enter your password so that you can search your e-mail contacts.

But many people might interpret that as a LinkedIn log-in form (not realizing that they are already logged in). If LinkedIn just had an ad there asking people to click a button to then fill out their e-mail address/password, they would likely have much fewer people let LinkedIn look at their e-mail account.

This is much more legit than just trying the Linkedin account username/password to access the e-mail account, but it is still a form of phishing.

Re: What LinkedIn Could Learn From OKCupid and Others

#13
My LinkedIn rant:

A year ago LinkedIn released the "Publications" section for your profile: http://blog.linkedin.com/2010/10/18/linkedin-profile-section...

Now you can list your academic papers on your profile, awesome. The problem being that YOU are listed in the "first author" position on any paper you submit. Author-order being very important, this is a major issue that should have been caught in the spec stage. It hasn't been fixed in over a year.

Re: What LinkedIn Could Learn From OKCupid and Others

#14
post #9

Something Linkedin ought to be taken to task for (Which they continue to get away with) -- phishing: Linkedin will show you a login-like screen with your email address pre-populated and a password prompt. Two dangerous things can happen: 1) a user can absent-mindedly assume they're at their email login page and type in their email password (less likely) 2) a user can absent-mindedly assume that this is the Linkedin l…

I'm almost certain LinkedIn doesn't try to use your username/password you use for the site to access your email. Triggering millions of password failures on gmail/yahoo/etc. is not something that they would risk. During signup, if you are on one of the major webmail services, it will explicitly ask you to authorize yourself on them so it can get your contacts however. Having worked there and specifically as product m…

No it explicitly asks if you'd like Linkedin to search your email contacts by filling out the email address and password fields below. It pre-populates the email address from your linkedin email login address. Thus without reading what the fields are for, it's very easy to assume you've simply been logged out of Linkedin and need to re-log-in. Upon doing so Linkedin will try one time to login to your email (Gmail and other web email clients do this too -- to grab contacts from older email accounts but they don't use this phishing-style approach). If your email password happens to be your Linkedin password, Linkedin will have access to your email contacts without you realizing it. And more embarrassing: Linkedin may send an email to your contacts mentioning you (they used to do this, maybe not as much anymore). Don't you remember getting all those Linkedin invite emails from your 'friends'? how do you think those got sent? Do you really think your friends intentionally typed in your email address so Linkedin could spam you?

Re: What LinkedIn Could Learn From OKCupid and Others

#15
post #11
post #8

Earlier quoted context omitted.

With my experience, LinkedIn will say that you are an anonymous user or give me a list of 15 people to guess who you are. I also don't think the people recommendations algorithm includes whose profile you visit.

with a paid account the information is a lot more detailed and definitely identifies specific people.

I have a paid account. It only identifies specific people if those people allow that.
Post reply on HN