Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

71–80 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#72

Unless LinkedIn open sources it and I host my own copy, there is no way for me to hand all my emails to LinkedIn.

A private self-hosted version of this wouldn't be that bad. Imagine that you write the same proxy, and it injects data grabbed from the various API's its hooked up to.

Re: LinkedIn Intro: Doing the Impossible on iOS

#73
post #67
post #14

Earlier quoted context omitted.

There are lots of concerns: * your local mail client might get different E-mail content every time mail is downloaded, which is not the intent of IMAP, * LinkedIn (hence, the NSA) gets full access to your E-mail, * once people get hooked it's easy to transition to inserting ads, or "more helpful LinkedIn content", I find all this rather disturbing and would never use this service.

> * LinkedIn (hence, the NSA) gets full access to your E-mail, What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.

Before every email as yourself "if this email went public, would anyone care?" If I ever answer "yes", I don't send it. I either call or meet in person assuming we're not too remote.

Re: LinkedIn Intro: Doing the Impossible on iOS

#74
> A little-known fact about CSS on Mobile Safari: in certain circumstances, tapping a link once simulates a :hover state on that link, and tapping it twice has the effect of a click.

I have noticed that on websites that clearly don't intend that behavior, and it's quite annoying. Does anyone have any details about the exact circumstances required for this phenomenon?

Re: LinkedIn Intro: Doing the Impossible on iOS

#75
I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack".

At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying.

How would you even go about installing that on the user's phone? Oh, that's in there too... they ship a 'configuration profile' which adds a new email account, so your password is leaving the device in cleartext and being used to create the profile server-side which is then shipped back to the phone and installed, how exactly?

This just gets worse and worse if I understand correctly... I'm surprised that configuration profiles can be shipped to an arbitrary device from a third party this way without the user manually installing LinkedIn's certificate as trusted. In other words, it should be a lot harder to "Accept" these profiles outside an enterprise setting, because it sounds exploitable. What else can you configure "so easily" I wonder?

Then you get into how they are hacking CSS and iframes into the email body, to substitute for Javascript, and actually create a workable user interface. Now this is fascinating, impressive, and deserves further study... Without fully understanding exactly what they are doing, however, it sounds highly abusive of the Mail app's rendering capabilities, and points to exploitable paths within the Mail app that probably need to be tightened up by Apple. If LinkedIn can make an email "act" like that without any opt-in on my part, how would Mallory use the same "feature" in their latest SPAM campaign?

Thanks LinkedIn... really, I'm impressed. When exactly did Walter Bishop start working for you?

P.S. I look forward to following your pending class-action lawsuit for violation of US federal wiretapping laws. Cheers!

Re: LinkedIn Intro: Doing the Impossible on iOS

#77
post #24

Earlier quoted context omitted.

Why would the service close? It's supported by LinkedIn and AFAIK they're not in the habit of shutting things down. This almost feels like a no-brainer for them, especially given the move to mobile devices and locked-down apps. Edit: Have I missed the point? I'm sure LinkedIn is a little more cautious about such changes than your average newly-founded startup. This product gives them access to people emails which the…

"It's supported by LinkedIn and AFAIK they're not in the habit of shutting things down" You mean besides job agents, Answers, Events, ...

Fair enough but as I tried (and obviously failed) to caveat, these are not shutdowns I really knew about. I clearly wasn't a user of those products so I didn't feel any pain when they went away.

Perhaps my claim is weak and my knowledge limited but I find it more ridiculous to claim the inevitability of a closure before a product is even being used.

NB I feel I should add that I'm not going to be a user of this product as I won't hand over email access. However, I can imagine many people who don't think the same finding it very useful.

Re: LinkedIn Intro: Doing the Impossible on iOS

#78
post #69
post #51

Earlier quoted context omitted.

Think of it like a value proposition. Is the (dubious IMO) convenience of having Linkedin profiles in your email worth the cost of Linkedin having the content of your email? Even if they pinky-swear to never read it, don't forget that this proxy email server would be, overnight, one of the most valuable corporate espionage targets in the world. (If yes, you should probably ditch reading email and do something more pr…

That's not the point I was responding to. It was the claim that this service will inevitably close that I was disagreeing with.

Apologies, I was so gobsmacked by the security implications that I found it hard to focus on anything else!

Re: LinkedIn Intro: Doing the Impossible on iOS

#79
A privacy pledge, how cute! The problem with stuff like this is not knowing the third, fouth, and fifth party uses. Granted most user's don't read these disclosure and even more don't have the technical aspects of how this works. But even if you're ok with one big evil company have access to your inbox, allowing two just seems crazy. What happens when LinkedIn think of a cool way to use your emails from five years ago? By cool I of course mean horrifying.
Post reply on HN