Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

181–190 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#181
post #73
post #67

Earlier quoted context omitted.

> * LinkedIn (hence, the NSA) gets full access to your E-mail, What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.

Before every email as yourself "if this email went public, would anyone care?" If I ever answer "yes", I don't send it. I either call or meet in person assuming we're not too remote.

That may work for outgoing mail, but this is reading incoming mail, which you have considerably less control over.

Re: LinkedIn Intro: Doing the Impossible on iOS

#182
post #118
post #110

Earlier quoted context omitted.

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.

That's not quite true, in that all the emails I send to people who have opted in are now available to LinkedIn. You have no way of totally opting out without encrypting all your email.

For all you know, I (or anyone else you email) could have a simple "forward all email to root@nsa.gov" filter running. If you don't want the second party to share your email with a third party, don't send the second party an email.

Re: LinkedIn Intro: Doing the Impossible on iOS

#183
post #157
post #97

Earlier quoted context omitted.

What exactly were you expecting? I think it's a neat hack using some clever tricks.

There is nothing new about this. Putting a proxy into to modify content is as old as the usage of tcp proxies. What is new here is that they have no shame -- I don't expect software from a reputed company to pipe my email through their servers.

To play the devil's advocate, how is this any different morally from what Gmail (and Outlook, and Yahoo) do with their external emails feature? In each case, you give them the credentials for your other account, they pull the mail and display it in their interface (which, presumably, adds some new features that doesn't exist in the other account. Like conversations and tags.) LinkedIn is doing pretty much the same thing.

Re: LinkedIn Intro: Doing the Impossible on iOS

#184
post #110
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.

Of course the average user understands that this feature allows LinkedIn to read their email... right?

Re: LinkedIn Intro: Doing the Impossible on iOS

#185
post #83

How (and Why) You Should Block LinkedIn Access to your Exchange Server Organization http://exchangeserverpro.com/blocking-linkedin-access-to-you... > I ran some tests with two brand new mailboxes, and it seems that LinkedIn > accesses both the Contacts and the Sent Items. technical details: http://www.adamfowlerit.com/2013/06/02/linkedin-securityinfo...

If LinkedIn changes their User-Agent string then they're right back in again.

Re: LinkedIn Intro: Doing the Impossible on iOS

#186

Earlier quoted context omitted.

I think you might be forgetting that by e-mailing said person, you become part of their contacts too. Should that person decide to import or sync their contacts in linkedin, a relationship between you and that person is established on their server. ie: it's an _undirected_ edge between you and your contact, which they seem to use to display stuff back to you.

no, no, no. Reddit's Razor: if a corporation could be doing something evil, they are doing that something.

These "social" big data companies have a history of doing evil (or sometimes, stepping right up to that line) and $LKND certainly isn't in business to be altruistic.

Their iphone app used to slurp up your data without authorization: http://arstechnica.com/apple/2012/06/your-iphone-calendar-is...

Furthermore:

LinkedIn: The Creepiest Social Network

https://news.ycombinator.com/item?id=5680680

LinkedIn opts 100 million users into sharing information with ads

https://news.ycombinator.com/item?id=2872030

LinkedIn is Evil

https://news.ycombinator.com/item?id=220138

Re: LinkedIn Intro: Doing the Impossible on iOS

#187
Interesting hack. So since you inject that social info at the time of the email, that means if someone gets a new job, it will still show the old employer info / position in the older emails... right? What made you guys do this instead of your own mail app like Mailbox?

Re: LinkedIn Intro: Doing the Impossible on iOS

#188

Earlier quoted context omitted.

Apple has blocked apps for a lot less than providing a feature that intercepts users' email and email password to circumvent Apple's own sandboxing and inject content into their mailbox...

What could they do about it? Not allow you to create a mail account that points to linkedin.com as the server?

Apple could yank the certificate that LinkedIn is using for configuration profiles, which would make installation significantly more difficult for the average user.

Re: LinkedIn Intro: Doing the Impossible on iOS

#189
post #102
post #67

Earlier quoted context omitted.

> * LinkedIn (hence, the NSA) gets full access to your E-mail, What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.

>What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? Can I have your gmail and password? If not, why not?

You can have my gmail and password, but only if you promise to spam me and show me ads.

Re: LinkedIn Intro: Doing the Impossible on iOS

#190

Earlier quoted context omitted.

I work in enterprise information security, and my team agreed upon hearing this news that if this was used on our email system, we would consider it a MITM attack . Whether or not the end user opted in, the corporation did not. So, in the context of use in environments where your email address is not fully owned by you, attack would be a valid word. Otherwise, I agree that it's a MITM but not an attack.

Is your corporation going to fire the users who use this? If not, why not? They are aiding and abetting an outside attacker.

Given that a lot of users are technically unaware of what they are doing, it would be akin to firing someone for falling for one of those pop ups that offers to do a free virus scan. If you are a pharmaceutical sales rep and you read that LI blog post, you probably think it is perfectly safe...

I would think the responsibility falls back onto IT to educate users - and to block connections from LI to the mail server.

Post reply on HN