Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

101–110 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#101
post #61

Earlier quoted context omitted.

But you do have to take into account the context of what they are doing. Yes on a technical scale it is similar to a mitm attack, and yes in theory they do have access to your email content, but I don't think that by using an interesting trick to add a useful feature should put them in the same category as sleazy hackers secretly trying to steal your credit cards and such.

Does it matter? They are purposefully inserting themselves into a stream of information which they largely have no business being a party to. If (when?) this proxy service is compromised are they willing to be accountable for any information which leaks? I can't imagine wanting to even take on this risk (maybe I'm too conservative). Edit: I just want to add - yes, it's interesting. Yes, it's sleazy.

> They are purposefully inserting themselves into a stream of information

to implement a feature that's impossible to do any other way. They have a justification for doing this.

Re: LinkedIn Intro: Doing the Impossible on iOS

#102
post #67
post #14

Earlier quoted context omitted.

There are lots of concerns: * your local mail client might get different E-mail content every time mail is downloaded, which is not the intent of IMAP, * LinkedIn (hence, the NSA) gets full access to your E-mail, * once people get hooked it's easy to transition to inserting ads, or "more helpful LinkedIn content", I find all this rather disturbing and would never use this service.

> * LinkedIn (hence, the NSA) gets full access to your E-mail, What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.

>What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost?

Can I have your gmail and password? If not, why not?

Re: LinkedIn Intro: Doing the Impossible on iOS

#103
post #61
post #40

This is essentially a mitm attack. I am amazed that a company the size of LinkedIn would think that this is in any way appropriate. These are the tricks of spammers and cyber criminals. This is what LinkedIn has become. Will customers be explicitly told that all of their emails will be going through and stored on LinkedIn servers? I doubt it. I do envision a dialog box along the lines of "Click Here to make your expe…

But you do have to take into account the context of what they are doing. Yes on a technical scale it is similar to a mitm attack, and yes in theory they do have access to your email content, but I don't think that by using an interesting trick to add a useful feature should put them in the same category as sleazy hackers secretly trying to steal your credit cards and such.

There is a saying you may have heard before, "the road to Hell is paved with good intentions." Intent doesn't matter at all, because someone will inevitably figure out a) how, and b) why to take advantage of it for nefarious purposes.

Re: LinkedIn Intro: Doing the Impossible on iOS

#104
post #66
post #36

So what happens if you reply to a mail like this? Does the quoted part contain all that linkedin fluff?

According to "Pledge of Privacy"[1], no. It seems they will also modify your outgoing mail to remove the profile info. So in addition to reading your incoming mail they can also modify your outgoing mail as well. Suppose that user B gets mail from A, then forwards it to C. I'd see why this could be valuable info. for a company like this (and also has a high potential for abuse). [1. https://intro.linkedin.com/micro/p…

Wow, it even says right there that if you forward or reply via a different account, the full content remains in the message (of course!). I'd imagine the same thing would happen if you moved the message from a folder in one imap account to a folder in another imap account. Nice.

Re: LinkedIn Intro: Doing the Impossible on iOS

#105
post #64

Not only does it obliterate users' security but it introduces a potentially unreliable point of failure. Sometimes the hack is worse than the problem it solves. I hope they're being extremely upfront with users about how this works, not that most users will really understand the implications...

Good point re point of failure. If LinkedIn doesn't put a lot of resources into the proxy servers, mail delivery could be very slow or fail completely.

I"m still impressed with the creativity from a technical standpoint.

Re: LinkedIn Intro: Doing the Impossible on iOS

#106
post #74

> A little-known fact about CSS on Mobile Safari: in certain circumstances, tapping a link once simulates a :hover state on that link, and tapping it twice has the effect of a click. I have noticed that on websites that clearly don't intend that behavior, and it's quite annoying. Does anyone have any details about the exact circumstances required for this phenomenon?

Yep, it can be pretty challenging to deal with: http://sitr.us/2011/07/28/how-mobile-safari-emulates-mouse-e...

Re: LinkedIn Intro: Doing the Impossible on iOS

#107
I often wish there was a good way to do email "apps" like this without giving away the keys to the castle.

I'm just not comfortable giving my email credentials out when access to my email is effectively a skeleton key for the rest of my accounts via password resets.

Re: LinkedIn Intro: Doing the Impossible on iOS

#108
post #67
post #14

Earlier quoted context omitted.

There are lots of concerns: * your local mail client might get different E-mail content every time mail is downloaded, which is not the intent of IMAP, * LinkedIn (hence, the NSA) gets full access to your E-mail, * once people get hooked it's easy to transition to inserting ads, or "more helpful LinkedIn content", I find all this rather disturbing and would never use this service.

> * LinkedIn (hence, the NSA) gets full access to your E-mail, What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.

You're doubling your surface for anything unethical, too. It not just the NSA, so it really makes no sense to take additional risk in this regards. You are adding an [or] operator, one that can lead to a complete failure mode. This is the opposite of risk diversification. Unless I'm missing something.

Re: LinkedIn Intro: Doing the Impossible on iOS

#109
post #57

Earlier quoted context omitted.

> Anyone can send email as anyone else anyway. Many emails are signed with DKIM now, which does help with verifiability. > but I would hope this is still stored encrypted Encryption is pointless when the keys for decryption are on the same server. Given their hack in 2012, I doubt there's any protection at all.

Which is why the key should be physically given to the system when it is started and then only stored in memory. The key file should not be available on any network-attached machine. Of course there's still potential for exploits in this scenario, but it does help minimize the attack surface.

Given their response several parents up, it's being stored on disk permanently.

Re: LinkedIn Intro: Doing the Impossible on iOS

#110
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.
Post reply on HN