Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

61–70 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#61
post #40

This is essentially a mitm attack. I am amazed that a company the size of LinkedIn would think that this is in any way appropriate. These are the tricks of spammers and cyber criminals. This is what LinkedIn has become. Will customers be explicitly told that all of their emails will be going through and stored on LinkedIn servers? I doubt it. I do envision a dialog box along the lines of "Click Here to make your expe…

But you do have to take into account the context of what they are doing. Yes on a technical scale it is similar to a mitm attack, and yes in theory they do have access to your email content, but I don't think that by using an interesting trick to add a useful feature should put them in the same category as sleazy hackers secretly trying to steal your credit cards and such.

Re: LinkedIn Intro: Doing the Impossible on iOS

#62
post #15

Earlier quoted context omitted.

Of course. They can send as you too, which given their spammy record is quite a huge issue. They will also be storing your IMAP password in plaintext.

We don't store passwords or emails. Checkout our pledge of privacy: https://intro.linkedin.com/micro/privacy

According to the linked document:

• passwords are stored for a minute, maybe up to two hours

• emails are stored for a few minutes, maybe a few hours

Most clients will poll for emails every few minutes, which means that the storage of the passwords is for all intents; permanent.

Re: LinkedIn Intro: Doing the Impossible on iOS

#64
Not only does it obliterate users' security but it introduces a potentially unreliable point of failure. Sometimes the hack is worse than the problem it solves. I hope they're being extremely upfront with users about how this works, not that most users will really understand the implications...

Re: LinkedIn Intro: Doing the Impossible on iOS

#65
post #57

Earlier quoted context omitted.

Anyone can send email as anyone else anyway. That lack of security is inherent in the way email currently works. Not sure I see how giving IMAP access makes things worse since IMAP doesn't have a mechanism for sending messages. I would also hope they're not storing passwords in plaintext. Obviously they need access to the plaintext password to auth with your mail server, but I would hope this is still stored encrypte…

> Anyone can send email as anyone else anyway. Many emails are signed with DKIM now, which does help with verifiability. > but I would hope this is still stored encrypted Encryption is pointless when the keys for decryption are on the same server. Given their hack in 2012, I doubt there's any protection at all.

Which is why the key should be physically given to the system when it is started and then only stored in memory. The key file should not be available on any network-attached machine. Of course there's still potential for exploits in this scenario, but it does help minimize the attack surface.

Re: LinkedIn Intro: Doing the Impossible on iOS

#66
post #36

So what happens if you reply to a mail like this? Does the quoted part contain all that linkedin fluff?

According to "Pledge of Privacy"[1], no. It seems they will also modify your outgoing mail to remove the profile info.

So in addition to reading your incoming mail they can also modify your outgoing mail as well.

Suppose that user B gets mail from A, then forwards it to C. I'd see why this could be valuable info. for a company like this (and also has a high potential for abuse).

[1. https://intro.linkedin.com/micro/privacy ]

Re: LinkedIn Intro: Doing the Impossible on iOS

#67
post #14

Technologically this is straightforward: it uses a proxy server that sits in between you and your actual mailserver. I think the privacy concerns of having your mail (potentially) available over yet another server in exchange for modest convenience makes it unlikely that I would use this, but I'm sure many will find the trade-off acceptable and desirable.

There are lots of concerns: * your local mail client might get different E-mail content every time mail is downloaded, which is not the intent of IMAP, * LinkedIn (hence, the NSA) gets full access to your E-mail, * once people get hooked it's easy to transition to inserting ads, or "more helpful LinkedIn content", I find all this rather disturbing and would never use this service.

> * LinkedIn (hence, the NSA) gets full access to your E-mail,

What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost?

My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.

Re: LinkedIn Intro: Doing the Impossible on iOS

#68
post #12

Surely corporate IT departments are going to have a collective heart attack as employees start handing all their email to a third party?

Since this only works with Gmail, Google Apps, Yahoo, AOL, and iCloud, the email is already with a third party.

Re: LinkedIn Intro: Doing the Impossible on iOS

#69
post #51
post #24

Earlier quoted context omitted.

Why would the service close? It's supported by LinkedIn and AFAIK they're not in the habit of shutting things down. This almost feels like a no-brainer for them, especially given the move to mobile devices and locked-down apps. Edit: Have I missed the point? I'm sure LinkedIn is a little more cautious about such changes than your average newly-founded startup. This product gives them access to people emails which the…

Think of it like a value proposition. Is the (dubious IMO) convenience of having Linkedin profiles in your email worth the cost of Linkedin having the content of your email? Even if they pinky-swear to never read it, don't forget that this proxy email server would be, overnight, one of the most valuable corporate espionage targets in the world. (If yes, you should probably ditch reading email and do something more pr…

That's not the point I was responding to. It was the claim that this service will inevitably close that I was disagreeing with.
Post reply on HN