Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

51–60 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#51
post #24
post #18

Earlier quoted context omitted.

Additional madness when the services inevitably closes and tens of thousands of corporate tickets are files about non-working email clients.

Why would the service close? It's supported by LinkedIn and AFAIK they're not in the habit of shutting things down. This almost feels like a no-brainer for them, especially given the move to mobile devices and locked-down apps. Edit: Have I missed the point? I'm sure LinkedIn is a little more cautious about such changes than your average newly-founded startup. This product gives them access to people emails which the…

Think of it like a value proposition. Is the (dubious IMO) convenience of having Linkedin profiles in your email worth the cost of Linkedin having the content of your email? Even if they pinky-swear to never read it, don't forget that this proxy email server would be, overnight, one of the most valuable corporate espionage targets in the world.

(If yes, you should probably ditch reading email and do something more productive with your time, like picking up cans.)

Re: LinkedIn Intro: Doing the Impossible on iOS

#52
This is cool. I'm a little concerned that what they've done expose some security holes in the iPhone mail client. And, all of this work will be for naught when Apples fixes those.

(Specifically, iframes in emails have been stripped from most modern email clients for years)

Re: LinkedIn Intro: Doing the Impossible on iOS

#53
post #29

Earlier quoted context omitted.

Except the third party that actually is your inbox?

And the third party that wrote the mail client you are using? Not to say that this isn't a bad idea though. It would have been an easier sell if you could do the IMAP proxying on the local device somehow.

> It would have been an easier sell if you could do the IMAP proxying on the local device somehow.

This should be easy to run an background proxy under Android. Not sure if this is possible under iOS7 though.

Re: LinkedIn Intro: Doing the Impossible on iOS

#54
This is a truly awesome hack. Good job!

The value for LinkedIn to vacuum up my email is immense! They'll know everyone I email and the content of the emails as well. They'll know where I shop and what I purchase. If I send a private email to a friend who has this installed, I've now unknowingly bcc'ed LinkedIn. Not only that, but they know this for the entire history of my email account! The person I stopped emailing 7 years ago... LinkedIn has access to that as well.

But in this case I don't think the value prop for the user is big enough to make me overcome this large of an ask.

I appreciate LinkedIn addressing this in their Privacy Pledge, but so long as they retain the right to change it at any time, I'm too uncomfortable to install this. But, I'm still in awe of the creative work-around. :)

Re: LinkedIn Intro: Doing the Impossible on iOS

#55
post #15
post #3

Wouldn't this essentially allow them access to read/analyze/archive all of your email for any account you set up?

Of course. They can send as you too, which given their spammy record is quite a huge issue. They will also be storing your IMAP password in plaintext.

Anyone can send email as anyone else anyway. That lack of security is inherent in the way email currently works. Not sure I see how giving IMAP access makes things worse since IMAP doesn't have a mechanism for sending messages.

I would also hope they're not storing passwords in plaintext. Obviously they need access to the plaintext password to auth with your mail server, but I would hope this is still stored encrypted.

Re: LinkedIn Intro: Doing the Impossible on iOS

#56
post #15
post #3

Wouldn't this essentially allow them access to read/analyze/archive all of your email for any account you set up?

Of course. They can send as you too, which given their spammy record is quite a huge issue. They will also be storing your IMAP password in plaintext.

We don't store passwords or emails. Checkout our pledge of privacy: https://intro.linkedin.com/micro/privacy

Re: LinkedIn Intro: Doing the Impossible on iOS

#57
post #15

Earlier quoted context omitted.

Of course. They can send as you too, which given their spammy record is quite a huge issue. They will also be storing your IMAP password in plaintext.

Anyone can send email as anyone else anyway. That lack of security is inherent in the way email currently works. Not sure I see how giving IMAP access makes things worse since IMAP doesn't have a mechanism for sending messages. I would also hope they're not storing passwords in plaintext. Obviously they need access to the plaintext password to auth with your mail server, but I would hope this is still stored encrypte…

> Anyone can send email as anyone else anyway.

Many emails are signed with DKIM now, which does help with verifiability.

> but I would hope this is still stored encrypted

Encryption is pointless when the keys for decryption are on the same server. Given their hack in 2012, I doubt there's any protection at all.

Re: LinkedIn Intro: Doing the Impossible on iOS

#58
Does this mean that for a simple email : See you in 5 minutes or Let's go to lunch , ... it would actually download a full Linkedin profile with it ? (Hidden with the CSS, but still downloaded). If so, it seems to be wasteful.

All the privacy issues it raises are already discussed.

Re: LinkedIn Intro: Doing the Impossible on iOS

#60
This is a really cool hack but I would never hand over my email creds to someone like LinkedIn after their history with emails. They might decide one day to "help" you by inviting everyone you have emailed or has emailed you or they could start added a "Connect With Josh" link to the bottom of my outgoing emails that links to my LinkedIn.

Again, VERY cool how they did it but it requires quite a bit trust in a company that I don't find very trustworthy.

Post reply on HN