Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

31–40 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#32
There is definitely not much value here for risk involved (handing out your credentials to a 3rd party). Although interesting, the hack seems pretty straight forward. I wonder if they had to do something more complex for 2-face authentication enabled accounts (gmail) or that is not supported?

Re: LinkedIn Intro: Doing the Impossible on iOS

#33
post #27
post #17

I don't care who the company is, or how trustworthy you think they are: avoid giving third parties credentials to your inbox.

If you think about the reach Linked in has, combine that with each contact the linked in user has and you have a very fast database of emails that can be misused.

Isn't that the whole point of Rapportive? They're the only company I can think of that has successfully solved the "social profile matching" problem that I can think of off the top of my head.

Re: LinkedIn Intro: Doing the Impossible on iOS

#37
post #26
post #15

Earlier quoted context omitted.

Of course. They can send as you too, which given their spammy record is quite a huge issue. They will also be storing your IMAP password in plaintext.

Since they are proxying the request, they don't actually have to store the password at all.

It took me a moment to understand what you're saying, which (correct me if I'm wrong) is that they could just forward the credentials along to the imap server they're proxying for, and not store those credentials themselves.

Re: LinkedIn Intro: Doing the Impossible on iOS

#38
So you give up your email credentials to LinkedIn and in exchange you get a little widget that tells you the name of the person who is emailing you, the company they work for, their position in the company, and some contact information? Isn't that's what the signature line is for? Seriously, don't people already setup their signature line to include all that information.

It's a cool hack, however.

Re: LinkedIn Intro: Doing the Impossible on iOS

#39
post #29
post #17

I don't care who the company is, or how trustworthy you think they are: avoid giving third parties credentials to your inbox.

Except the third party that actually is your inbox?

And the third party that wrote the mail client you are using?

Not to say that this isn't a bad idea though. It would have been an easier sell if you could do the IMAP proxying on the local device somehow.

Re: LinkedIn Intro: Doing the Impossible on iOS

#40
This is essentially a mitm attack. I am amazed that a company the size of LinkedIn would think that this is in any way appropriate. These are the tricks of spammers and cyber criminals. This is what LinkedIn has become.

Will customers be explicitly told that all of their emails will be going through and stored on LinkedIn servers? I doubt it. I do envision a dialog box along the lines of "Click Here to make your experience better". Sadly people will click without realizing the implications.

Post reply on HN