Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

151–160 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#151
post #84
post #40

This is essentially a mitm attack. I am amazed that a company the size of LinkedIn would think that this is in any way appropriate. These are the tricks of spammers and cyber criminals. This is what LinkedIn has become. Will customers be explicitly told that all of their emails will be going through and stored on LinkedIn servers? I doubt it. I do envision a dialog box along the lines of "Click Here to make your expe…

The "attack" part of "man in the middle attack" refers to the fact that it is done secretly and generally with ill intentions. LinkedIn is not being secretive (and we can speculate about their intentions). If everything that's in the middle of something is a man in the middle attack, then that would include your home router.

I work in enterprise information security, and my team agreed upon hearing this news that if this was used on our email system, we would consider it a MITM attack. Whether or not the end user opted in, the corporation did not.

So, in the context of use in environments where your email address is not fully owned by you, attack would be a valid word. Otherwise, I agree that it's a MITM but not an attack.

Re: LinkedIn Intro: Doing the Impossible on iOS

#152
post #89

Earlier quoted context omitted.

Which parts would Apple have an issue with? The proxy server is the only part I can think of. Using images, CSS, and iframes in Mail is presumably a very deliberate feature.

Apple has blocked apps for a lot less than providing a feature that intercepts users' email and email password to circumvent Apple's own sandboxing and inject content into their mailbox...

What could they do about it? Not allow you to create a mail account that points to linkedin.com as the server?

Re: LinkedIn Intro: Doing the Impossible on iOS

#153
post #113

Earlier quoted context omitted.

This service shouldn't exist. It breaks the very concept of email security. They're marketing it as though it's safe. Want hyperbole? Imagine Bayer marketing heroin as safe because you know, it's opt-in.

Want hyperbole? Compare an opt in social network to heroin.

Hitler.

Re: LinkedIn Intro: Doing the Impossible on iOS

#154

Earlier quoted context omitted.

Not that we should trust anybody, but let's not forget that LinkedIn already has a history of losing user credentials: http://www.pcworld.com/article/257045/6_5m_linkedin_password...

No, they don't, and you keep posting that they do despite being proven wrong several times in the past. They lost hashed passwords which are not user credentials.

> No, they don't, and you keep posting that they do despite being proven wrong several times in the past.

You must have me confused with someone else.

> They lost hashed passwords which are not user credentials.

While you may be technically correct about credentials vs. hashed passwords, that distinction isn't relevant here. Losing hashed but unsalted passwords is still just as harmful.

Otherwise, articles like this one would not exist: http://mashable.com/2012/06/08/linkedin-stolen-passwords-lis...

Re: LinkedIn Intro: Doing the Impossible on iOS

#155
post #91
post #84

Earlier quoted context omitted.

The "attack" part of "man in the middle attack" refers to the fact that it is done secretly and generally with ill intentions. LinkedIn is not being secretive (and we can speculate about their intentions). If everything that's in the middle of something is a man in the middle attack, then that would include your home router.

I do think LinkedIn has ill intentions. In my opinion, their intentions are to collect, analyze, and ultimately profit from their user's email data. All under the guise of offering some marginal benefit.

So they're just like Gmail?

Re: LinkedIn Intro: Doing the Impossible on iOS

#156
post #67
post #14

Earlier quoted context omitted.

There are lots of concerns: * your local mail client might get different E-mail content every time mail is downloaded, which is not the intent of IMAP, * LinkedIn (hence, the NSA) gets full access to your E-mail, * once people get hooked it's easy to transition to inserting ads, or "more helpful LinkedIn content", I find all this rather disturbing and would never use this service.

> * LinkedIn (hence, the NSA) gets full access to your E-mail, What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.

Ditch Gmail and host your own email server.

Re: LinkedIn Intro: Doing the Impossible on iOS

#157
post #97
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

What exactly were you expecting? I think it's a neat hack using some clever tricks.

There is nothing new about this. Putting a proxy into to modify content is as old as the usage of tcp proxies. What is new here is that they have no shame -- I don't expect software from a reputed company to pipe my email through their servers.

Re: LinkedIn Intro: Doing the Impossible on iOS

#158

Unless LinkedIn open sources it and I host my own copy, there is no way for me to hand all my emails to LinkedIn.

A private self-hosted version of this wouldn't be that bad. Imagine that you write the same proxy, and it injects data grabbed from the various API's its hooked up to.

This. The tech described is pretty neat... Give you my email creds? Hell no. But _I_ could do all that myself. I think that would be one way that linkedin could save this - release an easy to set up open source version, say one click to a heroku instance or something. Then one could add all sorts of smart stuff into their own emails.

Re: LinkedIn Intro: Doing the Impossible on iOS

#160
post #110
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.

Opt in or opt out doesn't matter (think average user understanding of what is going on here, really). Things like this just should not exist.
Post reply on HN