Live data from Hacker News

LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

thenextweb.com

31–40 of 43 posts

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#31
post #26

We've just posted a response about what we do and don't do. http://blog.linkedin.com/2012/06/06/mobile-calendar-feature/ Important point, all data is shared of SSL.

> Important point, all data is shared of SSL.

What does that mean?

Since comments are disabled on your blog, can you tell us which data was _not_ sent over SSL? (and if that has been fixed now)

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#33
post #6

This is off topic, but the next web really needs to make an effort to properly credit images. They've been called out on this a number of times before, but the way they credit image sources is just plain wrong. In this article, for example, at the very bottom of the page is a generic link that says SOURCES: IMAGE CREDIT. With this particular image, the photographer very clearly says "please, kindly credit me (Nan Pal…

Here's everywhere that's using that photo: http://www.tineye.com/search/3dab4395c0ce1c3e010b2fa699cfbfb...

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#34
post #23
post #21

Putting aside the issue that much of this data shouldn't have been sent anywhere in the first place, I'll never understand why, in 2012, SSL is still not used by default when sending any sensitive or private data across the network. It's even more puzzling when we're talking about background data upload when the potential SSL handshake latency isn't going to pose any UX issue. This has boggled my mind for years actua…

Maybe it's not an issue for LinkedIn, but the iOS app submission process requires developers to do a lot of paperwork with several governments (US, France) for export compliance when using any kind of crypto. I can easily see smaller developers deciding to go for HTTP instead of HTTPS just to avoid dealing with all that bureaucracy.

Going through CCATS is pretty painless; can't imagine that a public company with a good legal team like LinkedIn would have any issue getting through it if mom & pop shops can DIY without issue.

There are even handy tutorials that other devs have compiled to help the rest of us through it, like http://blog.theanimail.com/iphone-encryption-export-complian... and http://zetetic.net/blog/2009/8/3/mass-market-encryption-ccat....

To this day, LinkedIn's web site still doesn't appear to use SSL by default (I haven't used the mobile app in years after not only snooping my own proxy to see that everything was in clear-text but also finding that it recommended bunches of contacts it shouldn't have; Support was not cooperative in helping me determine why/how they acquired that contact info or how to stop it--I assume the culprit was a surreptitious Address Book siphon). Clear-text access to the Web site is a fantastic feature for employers who want to know what their employees are up to on LinkedIn all day, among other things...I would love to know why they still haven't implemented site-wide SSL by default.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#35
post #6

This is off topic, but the next web really needs to make an effort to properly credit images. They've been called out on this a number of times before, but the way they credit image sources is just plain wrong. In this article, for example, at the very bottom of the page is a generic link that says SOURCES: IMAGE CREDIT. With this particular image, the photographer very clearly says "please, kindly credit me (Nan Pal…

Thank you very much for looking out. It appears that this has been going on a bit. Matthew, can you help with the following pieces that also do not have my name attached to them, please? Doing so on both the desktop and mobile version would be greatly appreciated!

http://thenextweb.com/location/2011/08/01/foursquare-reporte...

http://thenextweb.com/insider/2011/05/14/milestone-foursquar...

http://thenextweb.com/apps/2011/03/17/agora-helps-you-meet-n...

http://thenextweb.com/insider/2011/10/24/linkedin-fixes-bug-...

http://thenextweb.com/apps/2011/08/16/linkedin-launches-slic...

http://thenextweb.com/socialmedia/2011/01/13/32-of-my-friend...

http://thenextweb.com/mobile/2010/08/31/mtv-to-reward-std-ch...

http://thenextweb.com/insider/2011/03/25/foursquare-plans-to...

http://thenextweb.com/insider/2011/01/27/linkedin-files-its-...

@Richiezc what a cool chocolate wrapper, thank you for making such a fun piece.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#36
post #6

This is off topic, but the next web really needs to make an effort to properly credit images. They've been called out on this a number of times before, but the way they credit image sources is just plain wrong. In this article, for example, at the very bottom of the page is a generic link that says SOURCES: IMAGE CREDIT. With this particular image, the photographer very clearly says "please, kindly credit me (Nan Pal…

Thank you very much for looking out. It appears that this has been going on a bit. Matthew, can you help with the following pieces that also do not have my name attached to them, please? Doing so on both the desktop and mobile version would be greatly appreciated! http://thenextweb.com/location/2011/08/01/foursquare-reporte... http://thenextweb.com/insider/2011/05/14/milestone-foursquar... http://thenextweb.com/apps/…

Wow - I knew they were bad at image attribution, but that's just plain awful. And these are just the photos from one photographer that have been improperly used! TNW clearly has a large gap in their reporting standards that needs to be corrected.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#37

Earlier quoted context omitted.

Thank you very much for looking out. It appears that this has been going on a bit. Matthew, can you help with the following pieces that also do not have my name attached to them, please? Doing so on both the desktop and mobile version would be greatly appreciated! http://thenextweb.com/location/2011/08/01/foursquare-reporte... http://thenextweb.com/insider/2011/05/14/milestone-foursquar... http://thenextweb.com/apps/…

Wow - I knew they were bad at image attribution, but that's just plain awful. And these are just the photos from one photographer that have been improperly used! TNW clearly has a large gap in their reporting standards that needs to be corrected.

I'm hopeful that they'll do the right thing.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#39
post #27
post #22

Earlier quoted context omitted.

Will you post your email and cell contacts to this thread now? If not, why not? I'm confused that you're confused. There are a hundred scenarios I can think of. Gmail being good at spam detection is your defense? For one, I get text message spam all the time now. I dont want people having my number who don't need it.

> Will you post your email and cell contacts to this thread now? If not, why not? Well that is completely different to what LinkedIn is doing. Sending information via plain text is bad but is fairly unlikely to be read in transit. (This isn't to say that it shouldn't be changed) LinkedIn shouldn't be collecting the data. At the same time it isn't making the data public. It is somewhat unclear what they are doing with…

The OP was making a very broad claim. Why would anyone want to keep their contact list secret? Who cares?

In this particular case, I agree LinkedIn in all likelihood is not going to post your contacts to a public forum. But it's completely conceivable that it could happen.

But if there are hundreds of apps and services out there storing your contacts (and there will be if you're careless), then it's a virtual certainty that they will be used in ways you didn't attend.

It almost seems more likely than not these days that a big trove of personal information will be hacked. Even if it doesn't contain your credit card numbers, personal information is still extremely valuable because it allows hackers to bypass security questions and reset passwords.

EDIT: Haha, front page, huge dump of linkedn PW hashes leaked: http://news.ycombinator.com/item?id=4073309. I had written something about LinkedIn probably having "decent engineers", and being safer than giving your personal data to a shoddy government website. But I realize security is more a matter of process than hiring top engineers. And all these startups in a huge rush. They're only going to do security right after they're embarrassed. Being a programmer, I know how the sausage is made.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#40

Earlier quoted context omitted.

Wow - I knew they were bad at image attribution, but that's just plain awful. And these are just the photos from one photographer that have been improperly used! TNW clearly has a large gap in their reporting standards that needs to be corrected.

I'm hopeful that they'll do the right thing.

Hello Nan, thank you for collecting those links, I know that it took your personal time to find those and we'll definitely make sure that you're credited properly in them.

All of the posts appear to have an 'image credit' or 'photo source' link back to your Flickr profile, but we understand that this isn't good enough and from now on will be moving image sources into the body of the article.

Please accept our apologies for not crediting it more clearly and thank you for the great shots!

Post reply on HN