Earlier quoted context omitted.
> * LinkedIn (hence, the NSA) gets full access to your E-mail, What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.
Before every email as yourself "if this email went public, would anyone care?" If I ever answer "yes", I don't send it. I either call or meet in person assuming we're not too remote.
LinkedIn Intro: Doing the Impossible on iOS
181–190 of 309 posts
Re: LinkedIn Intro: Doing the Impossible on iOS
#182Earlier quoted context omitted.
Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.
That's not quite true, in that all the emails I send to people who have opted in are now available to LinkedIn. You have no way of totally opting out without encrypting all your email.
Re: LinkedIn Intro: Doing the Impossible on iOS
#183Earlier quoted context omitted.
What exactly were you expecting? I think it's a neat hack using some clever tricks.
There is nothing new about this. Putting a proxy into to modify content is as old as the usage of tcp proxies. What is new here is that they have no shame -- I don't expect software from a reputed company to pipe my email through their servers.
Re: LinkedIn Intro: Doing the Impossible on iOS
#184I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…
Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.
Re: LinkedIn Intro: Doing the Impossible on iOS
#185How (and Why) You Should Block LinkedIn Access to your Exchange Server Organization http://exchangeserverpro.com/blocking-linkedin-access-to-you... > I ran some tests with two brand new mailboxes, and it seems that LinkedIn > accesses both the Contacts and the Sent Items. technical details: http://www.adamfowlerit.com/2013/06/02/linkedin-securityinfo...
Re: LinkedIn Intro: Doing the Impossible on iOS
#186Earlier quoted context omitted.
I think you might be forgetting that by e-mailing said person, you become part of their contacts too. Should that person decide to import or sync their contacts in linkedin, a relationship between you and that person is established on their server. ie: it's an _undirected_ edge between you and your contact, which they seem to use to display stuff back to you.
no, no, no. Reddit's Razor: if a corporation could be doing something evil, they are doing that something.
Their iphone app used to slurp up your data without authorization: http://arstechnica.com/apple/2012/06/your-iphone-calendar-is...
Furthermore:
LinkedIn: The Creepiest Social Network
https://news.ycombinator.com/item?id=5680680
LinkedIn opts 100 million users into sharing information with ads
https://news.ycombinator.com/item?id=2872030
LinkedIn is Evil
Re: LinkedIn Intro: Doing the Impossible on iOS
#187Re: LinkedIn Intro: Doing the Impossible on iOS
#188Earlier quoted context omitted.
Apple has blocked apps for a lot less than providing a feature that intercepts users' email and email password to circumvent Apple's own sandboxing and inject content into their mailbox...
What could they do about it? Not allow you to create a mail account that points to linkedin.com as the server?
Re: LinkedIn Intro: Doing the Impossible on iOS
#189Earlier quoted context omitted.
> * LinkedIn (hence, the NSA) gets full access to your E-mail, What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.
>What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? Can I have your gmail and password? If not, why not?
Re: LinkedIn Intro: Doing the Impossible on iOS
#190Earlier quoted context omitted.
I work in enterprise information security, and my team agreed upon hearing this news that if this was used on our email system, we would consider it a MITM attack . Whether or not the end user opted in, the corporation did not. So, in the context of use in environments where your email address is not fully owned by you, attack would be a valid word. Otherwise, I agree that it's a MITM but not an attack.
Is your corporation going to fire the users who use this? If not, why not? They are aiding and abetting an outside attacker.
I would think the responsibility falls back onto IT to educate users - and to block connections from LI to the mail server.