Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

171–180 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#171
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

It's funny, I read all through that with my rose tinted glasses thinking they'd created a local IMAP server on the phone, which would have been clever (and, I think, doable)... in fact I was running this perception until "Our proxy server is written in Ruby using EventMachine, which allows it to efficiently handle many concurrent IMAP connections"

And I thought, why the heck would one phone be issuing so many concurrent IMAP connections. Oh my naiveté.

Re: LinkedIn Intro: Doing the Impossible on iOS

#173

Earlier quoted context omitted.

Not that we should trust anybody, but let's not forget that LinkedIn already has a history of losing user credentials: http://www.pcworld.com/article/257045/6_5m_linkedin_password...

No, they don't, and you keep posting that they do despite being proven wrong several times in the past. They lost hashed passwords which are not user credentials.

> "hashed passwords"

Take a wild guess at what they are storing this time around.

Re: LinkedIn Intro: Doing the Impossible on iOS

#175
post #121

Earlier quoted context omitted.

I tend to agree that no sane person with minimal technical knowledge would balk at this. I already know that Yahoo! sells the email addresses of the people I exchange even one email with to LinkedIn and I am repulsed by this. LI then turns around and offers them as connections. I should note I am always logged out from LI to prevent even more evil from them. LI is just evil and should be eradicated.

I think you might be forgetting that by e-mailing said person, you become part of their contacts too. Should that person decide to import or sync their contacts in linkedin, a relationship between you and that person is established on their server. ie: it's an _undirected_ edge between you and your contact, which they seem to use to display stuff back to you.

no, no, no. Reddit's Razor: if a corporation could be doing something evil, they are doing that something.

Re: LinkedIn Intro: Doing the Impossible on iOS

#176
I believe this is somewhat a defensive tactics. Let's write a sugar-flavored article about how neat their hack is before someone said "wait a minute! WTF?!".

To all those who consider this a cool hack - it's not. It's ugly as hell. Sometimes you need to do this kind of shit to get the job done, it's true, but you know this is kind of thing that you look at after couple of month and think "Oh God, I should get a another job. They shouldn't force me to create THIS. Oh God, I feel so miserable.".

Re: LinkedIn Intro: Doing the Impossible on iOS

#177
post #87

Earlier quoted context omitted.

Thanks for this comment, nostromo. You've managed to address privacy problems with the Linkedin Intro while praising the technical solution. This is a great example of constructive criticism that I, for one, would like to see more on HN. Constant raging decreases the efficiency of knowledge transfer and community building. Maybe one such comment / thread would be enough to significantly increase quality of a discussi…

My sarcasm processing engine had a coredump. I have no idea who is sincere anymore in this thread. Please turn on sarcasm tags so I should know whether to agree/disagree, be pissed, etc.

It's safest just to be pissed at everyone.

Re: LinkedIn Intro: Doing the Impossible on iOS

#178
post #84

Earlier quoted context omitted.

The "attack" part of "man in the middle attack" refers to the fact that it is done secretly and generally with ill intentions. LinkedIn is not being secretive (and we can speculate about their intentions). If everything that's in the middle of something is a man in the middle attack, then that would include your home router.

I work in enterprise information security, and my team agreed upon hearing this news that if this was used on our email system, we would consider it a MITM attack . Whether or not the end user opted in, the corporation did not. So, in the context of use in environments where your email address is not fully owned by you, attack would be a valid word. Otherwise, I agree that it's a MITM but not an attack.

Is your corporation going to fire the users who use this? If not, why not? They are aiding and abetting an outside attacker.

Re: LinkedIn Intro: Doing the Impossible on iOS

#179
post #44

Is this a MITM attack wrapped as an App?

Not just MITM, MITM + DDOS! Now you have 220,000,000 LinkedIn users all running their email traffic through LinkedIn's proxy. I'm sure they have the bandwidth and CPU to handle that.

No, this is an opt in service, so only users who enabled this feature are using the proxy.
Post reply on HN