Does anyone know if this works with the Gmail iPhone app as well?
it will probably "work" as they are abusing the network (it will probably screw up VPN configs) to hijack all imap calls. unless the gmail app uses regular http endpoints... which it probably does.
LinkedIn Intro: Doing the Impossible on iOS
81–90 of 309 posts
Re: LinkedIn Intro: Doing the Impossible on iOS
#82Earlier quoted context omitted.
Except the third party that actually is your inbox?
And the third party that wrote the mail client you are using? Not to say that this isn't a bad idea though. It would have been an easier sell if you could do the IMAP proxying on the local device somehow.
Re: LinkedIn Intro: Doing the Impossible on iOS
#83http://exchangeserverpro.com/blocking-linkedin-access-to-you...
> I ran some tests with two brand new mailboxes, and it seems that LinkedIn
> accesses both the Contacts and the Sent Items.
technical details: http://www.adamfowlerit.com/2013/06/02/linkedin-securityinfo...Re: LinkedIn Intro: Doing the Impossible on iOS
#84This is essentially a mitm attack. I am amazed that a company the size of LinkedIn would think that this is in any way appropriate. These are the tricks of spammers and cyber criminals. This is what LinkedIn has become. Will customers be explicitly told that all of their emails will be going through and stored on LinkedIn servers? I doubt it. I do envision a dialog box along the lines of "Click Here to make your expe…
Re: LinkedIn Intro: Doing the Impossible on iOS
#85Re: LinkedIn Intro: Doing the Impossible on iOS
#86This is essentially a mitm attack. I am amazed that a company the size of LinkedIn would think that this is in any way appropriate. These are the tricks of spammers and cyber criminals. This is what LinkedIn has become. Will customers be explicitly told that all of their emails will be going through and stored on LinkedIn servers? I doubt it. I do envision a dialog box along the lines of "Click Here to make your expe…
But you do have to take into account the context of what they are doing. Yes on a technical scale it is similar to a mitm attack, and yes in theory they do have access to your email content, but I don't think that by using an interesting trick to add a useful feature should put them in the same category as sleazy hackers secretly trying to steal your credit cards and such.
If (when?) this proxy service is compromised are they willing to be accountable for any information which leaks? I can't imagine wanting to even take on this risk (maybe I'm too conservative).
Edit: I just want to add - yes, it's interesting. Yes, it's sleazy.
Re: LinkedIn Intro: Doing the Impossible on iOS
#87This is a truly awesome hack. Good job! The value for LinkedIn to vacuum up my email is immense! They'll know everyone I email and the content of the emails as well. They'll know where I shop and what I purchase. If I send a private email to a friend who has this installed, I've now unknowingly bcc'ed LinkedIn. Not only that, but they know this for the entire history of my email account! The person I stopped emailing…
Maybe one such comment / thread would be enough to significantly increase quality of a discussion.
Re: LinkedIn Intro: Doing the Impossible on iOS
#88I don't care who the company is, or how trustworthy you think they are: avoid giving third parties credentials to your inbox.
If you think about the reach Linked in has, combine that with each contact the linked in user has and you have a very fast database of emails that can be misused.
The contacts application also sends things like reminders for your contacts work anniversaries or when they change positions (something that you can't access in the LI API).
I sometimes think that I shouldn't be giving LI all of this information, but this is a typical case where the benefit received is greater than my privacy concerns.
Re: LinkedIn Intro: Doing the Impossible on iOS
#89I'd be really surprised if Apple will let them use all of these hacks for long... Still great way to get full access to all email from many users.
Re: LinkedIn Intro: Doing the Impossible on iOS
#90I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…