Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

131–140 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#131
post #104
post #66

Earlier quoted context omitted.

According to "Pledge of Privacy"[1], no. It seems they will also modify your outgoing mail to remove the profile info. So in addition to reading your incoming mail they can also modify your outgoing mail as well. Suppose that user B gets mail from A, then forwards it to C. I'd see why this could be valuable info. for a company like this (and also has a high potential for abuse). [1. https://intro.linkedin.com/micro/p…

Wow, it even says right there that if you forward or reply via a different account, the full content remains in the message (of course!). I'd imagine the same thing would happen if you moved the message from a folder in one imap account to a folder in another imap account. Nice.

My initial reaction to this blog post was basically revulsion on a gut level, but the more I think about it, the more my revulsion becomes justified on a rational level.

Re: LinkedIn Intro: Doing the Impossible on iOS

#132
Looks to me like Apple has some security to tighten up. I definitely don't think you should be able to do most of this stuff, but you can't really fault LinkedIn I don't think. They made something that adds value to their product and it got approved by Apple. Either way, the hacks are cool ones and I'm glad Linked-in did this write up. Keep 'em coming.

EDIT: not an app apparently.

Re: LinkedIn Intro: Doing the Impossible on iOS

#133
post #61
post #40

This is essentially a mitm attack. I am amazed that a company the size of LinkedIn would think that this is in any way appropriate. These are the tricks of spammers and cyber criminals. This is what LinkedIn has become. Will customers be explicitly told that all of their emails will be going through and stored on LinkedIn servers? I doubt it. I do envision a dialog box along the lines of "Click Here to make your expe…

But you do have to take into account the context of what they are doing. Yes on a technical scale it is similar to a mitm attack, and yes in theory they do have access to your email content, but I don't think that by using an interesting trick to add a useful feature should put them in the same category as sleazy hackers secretly trying to steal your credit cards and such.

Wasn't linkedin the defendant in a class action lawsuit about them using address books improperly?

Re: LinkedIn Intro: Doing the Impossible on iOS

#134
post #104
post #66

Earlier quoted context omitted.

According to "Pledge of Privacy"[1], no. It seems they will also modify your outgoing mail to remove the profile info. So in addition to reading your incoming mail they can also modify your outgoing mail as well. Suppose that user B gets mail from A, then forwards it to C. I'd see why this could be valuable info. for a company like this (and also has a high potential for abuse). [1. https://intro.linkedin.com/micro/p…

Wow, it even says right there that if you forward or reply via a different account, the full content remains in the message (of course!). I'd imagine the same thing would happen if you moved the message from a folder in one imap account to a folder in another imap account. Nice.

There are good ways to remove 95%+ of the content even if you forward/reply from a different account. We'll talk about this in an upcoming post.

Re: LinkedIn Intro: Doing the Impossible on iOS

#135
Holy fucking shit Batman! Assuming I read this correctly LinkedIn will now have access to all of your emails, your email credentials, and will now have the ability to both spoof your email, and MITM all incoming mail (banking etc). I was actually impressed at some of the little hacks they found, until they dropped this on me halfway through the blog. My jaw hit the ground.

This is probably the most blatant disregard for privacy and security for the smallest possible benefit that I have ever seen. Well, next to giving LinkedIn the password to your email so that they can spam your friends and hack your account.

Everyone needs to stop using this piece of shit service. They're incompetent and malicious. LinkedIn is the Zynga of HR. I'm gonna go buy some puts.

Disgusting.

Re: LinkedIn Intro: Doing the Impossible on iOS

#136
post #97
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

What exactly were you expecting? I think it's a neat hack using some clever tricks.

That LinkedIn not violate one of the simplest, most fundamental notions of security: never ever give your credentials to a third party.

Part of being a semi-decent citizen of the internet is also not encouraging users to give third parties their credentials

It is a neat hack. I'd love this if it was "here's how we integrate LinkedIn into our email clients internally". It is novel and it does use CSS in weird and new ways. It should also not be a shipping public product. MITM is bad shit.

Re: LinkedIn Intro: Doing the Impossible on iOS

#137
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

I can't agree more.

Next thing: store your S/Mime private keys on linked in servers to enable the feature also for encrypted mails...

I think LinkedIn should not offer every feature that's technically possible. Things should stay within reason, and some things should not be offered, especially not to non-savvy users.

Re: LinkedIn Intro: Doing the Impossible on iOS

#138
post #97
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

What exactly were you expecting? I think it's a neat hack using some clever tricks.

It's a neat hack, but a bad one.

Re: LinkedIn Intro: Doing the Impossible on iOS

#139
post #74

> A little-known fact about CSS on Mobile Safari: in certain circumstances, tapping a link once simulates a :hover state on that link, and tapping it twice has the effect of a click. I have noticed that on websites that clearly don't intend that behavior, and it's quite annoying. Does anyone have any details about the exact circumstances required for this phenomenon?

This is Apple trying (and IMO succeeding admirably) to handle hover navigation in a touch environment. The alternative is to be totally accurate and never fire a hover or mouse event--thereby breaking many site navs completely.

Hover navs are a usability problem and should never have been built in the first place. Computer OS and application developers figured that out years ago but for some reason web developers never got the memo.

Re: LinkedIn Intro: Doing the Impossible on iOS

#140
post #121
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

I tend to agree that no sane person with minimal technical knowledge would balk at this. I already know that Yahoo! sells the email addresses of the people I exchange even one email with to LinkedIn and I am repulsed by this. LI then turns around and offers them as connections. I should note I am always logged out from LI to prevent even more evil from them. LI is just evil and should be eradicated.

I highly doubt Yahoo is selling your e-mail contacts to LI. Do you have any proof or citations? I suspect either you authorized LI in the past (and forgot it's still authorized), or your contacts have authorized LI so it's pulling in their e-mails with you, not yours.
Post reply on HN