Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

81–90 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#81
post #10

Does anyone know if this works with the Gmail iPhone app as well?

it will probably "work" as they are abusing the network (it will probably screw up VPN configs) to hijack all imap calls. unless the gmail app uses regular http endpoints... which it probably does.

They aren't 'hijacking' all imap calls, you explicitly set up their service as your email provider, and email is proxied through it.

Re: LinkedIn Intro: Doing the Impossible on iOS

#82
post #29

Earlier quoted context omitted.

Except the third party that actually is your inbox?

And the third party that wrote the mail client you are using? Not to say that this isn't a bad idea though. It would have been an easier sell if you could do the IMAP proxying on the local device somehow.

And the third party that wrote your operating system's networking stack? And your ISP?

Re: LinkedIn Intro: Doing the Impossible on iOS

#83
How (and Why) You Should Block LinkedIn Access to your Exchange Server Organization

http://exchangeserverpro.com/blocking-linkedin-access-to-you...

  > I ran some tests with two brand new mailboxes, and it seems that LinkedIn 
  > accesses both the Contacts and the Sent Items.
technical details: http://www.adamfowlerit.com/2013/06/02/linkedin-securityinfo...

Re: LinkedIn Intro: Doing the Impossible on iOS

#84
post #40

This is essentially a mitm attack. I am amazed that a company the size of LinkedIn would think that this is in any way appropriate. These are the tricks of spammers and cyber criminals. This is what LinkedIn has become. Will customers be explicitly told that all of their emails will be going through and stored on LinkedIn servers? I doubt it. I do envision a dialog box along the lines of "Click Here to make your expe…

The "attack" part of "man in the middle attack" refers to the fact that it is done secretly and generally with ill intentions. LinkedIn is not being secretive (and we can speculate about their intentions). If everything that's in the middle of something is a man in the middle attack, then that would include your home router.

Re: LinkedIn Intro: Doing the Impossible on iOS

#86
post #61
post #40

This is essentially a mitm attack. I am amazed that a company the size of LinkedIn would think that this is in any way appropriate. These are the tricks of spammers and cyber criminals. This is what LinkedIn has become. Will customers be explicitly told that all of their emails will be going through and stored on LinkedIn servers? I doubt it. I do envision a dialog box along the lines of "Click Here to make your expe…

But you do have to take into account the context of what they are doing. Yes on a technical scale it is similar to a mitm attack, and yes in theory they do have access to your email content, but I don't think that by using an interesting trick to add a useful feature should put them in the same category as sleazy hackers secretly trying to steal your credit cards and such.

Does it matter? They are purposefully inserting themselves into a stream of information which they largely have no business being a party to.

If (when?) this proxy service is compromised are they willing to be accountable for any information which leaks? I can't imagine wanting to even take on this risk (maybe I'm too conservative).

Edit: I just want to add - yes, it's interesting. Yes, it's sleazy.

Re: LinkedIn Intro: Doing the Impossible on iOS

#87

This is a truly awesome hack. Good job! The value for LinkedIn to vacuum up my email is immense! They'll know everyone I email and the content of the emails as well. They'll know where I shop and what I purchase. If I send a private email to a friend who has this installed, I've now unknowingly bcc'ed LinkedIn. Not only that, but they know this for the entire history of my email account! The person I stopped emailing…

Thanks for this comment, nostromo. You've managed to address privacy problems with the Linkedin Intro while praising the technical solution. This is a great example of constructive criticism that I, for one, would like to see more on HN. Constant raging decreases the efficiency of knowledge transfer and community building.

Maybe one such comment / thread would be enough to significantly increase quality of a discussion.

Re: LinkedIn Intro: Doing the Impossible on iOS

#88
post #27
post #17

I don't care who the company is, or how trustworthy you think they are: avoid giving third parties credentials to your inbox.

If you think about the reach Linked in has, combine that with each contact the linked in user has and you have a very fast database of emails that can be misused.

If you look at one of LinkedIn's alternate applications, LinkedIn Contacts, http://contacts.linkedin.com/ it actually is a light-weight CRM application. The CRM meaning, it automatically connects to your email and calendar to your LinkedIn account to know when and how you are interfacing with people. I get a daily email with the meetings that I had the day before about who I met, as well as information on their LI profile about the last email conversation I had with them. This is super nice if you meet a bunch of people and need a way to take notes on who they are and what they are doing, independent of their business card.

The contacts application also sends things like reminders for your contacts work anniversaries or when they change positions (something that you can't access in the LI API).

I sometimes think that I shouldn't be giving LI all of this information, but this is a typical case where the benefit received is greater than my privacy concerns.

Re: LinkedIn Intro: Doing the Impossible on iOS

#89
post #63

I'd be really surprised if Apple will let them use all of these hacks for long... Still great way to get full access to all email from many users.

Which parts would Apple have an issue with? The proxy server is the only part I can think of. Using images, CSS, and iframes in Mail is presumably a very deliberate feature.

Re: LinkedIn Intro: Doing the Impossible on iOS

#90
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

[deleted]
Post reply on HN