Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

191–200 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#191

To HN commenters: If you don't trust LinkedIn, fine. Don't use it. But please, don't assume that LinkedIn is universally not trusted, the same way you assume that Microsoft is universally hated. This is a neat feature, and I'm sure that many people trust LinkedIn enough to think that the trade-off is worth it. Would you prefer to not have the choice to have access to this feature, and prevent others from having it to…

"Would you prefer to not have the choice to have access to this feature, and prevent others from having it too?"

Yes, I would prefer that. LinkedIn has not shown itself to be a particularly good or careful actor in the past, and now, even if I don't opt in to this, my email to people using this feature runs through LinkedIn servers. There are always third parties between me and the person I'm emailing, but as the number increases, the likelihood of compromise or failure of delivery increases.

Re: LinkedIn Intro: Doing the Impossible on iOS

#192
post #15

Earlier quoted context omitted.

Of course. They can send as you too, which given their spammy record is quite a huge issue. They will also be storing your IMAP password in plaintext.

We don't store passwords or emails. Checkout our pledge of privacy: https://intro.linkedin.com/micro/privacy

I am sure you do store sender/recipient information and relationships between recipients - even if they are not connected...

Re: LinkedIn Intro: Doing the Impossible on iOS

#193
I see a lot of people (understandably) getting upset about the MITM aspect of this. But almost as surprising to me was the fact that you can load an iframe in an email with apparently no warning or notification to the user. This seems like its asking for exploitation, even without the ability to run JavaScript.

Re: LinkedIn Intro: Doing the Impossible on iOS

#194
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

Where in the blog post does it say that your credentials are leaving the device in clear text. I know people don't like LinkedIn but I don't think even they would be dumb enough to do this over http.

Re: LinkedIn Intro: Doing the Impossible on iOS

#195

This is a truly awesome hack. Good job! The value for LinkedIn to vacuum up my email is immense! They'll know everyone I email and the content of the emails as well. They'll know where I shop and what I purchase. If I send a private email to a friend who has this installed, I've now unknowingly bcc'ed LinkedIn. Not only that, but they know this for the entire history of my email account! The person I stopped emailing…

Maybe we should be discussing Apple's closed-ass OS instead of harping on the only workaround that could possibly exist. Such "creative" measures wouldn't need to be taken if it was simple for a user to augment their email app.

Re: LinkedIn Intro: Doing the Impossible on iOS

#196

This is a truly awesome hack. Good job! The value for LinkedIn to vacuum up my email is immense! They'll know everyone I email and the content of the emails as well. They'll know where I shop and what I purchase. If I send a private email to a friend who has this installed, I've now unknowingly bcc'ed LinkedIn. Not only that, but they know this for the entire history of my email account! The person I stopped emailing…

Maybe we should be discussing Apple's closed-ass OS instead of harping on the only workaround that could possibly exist. Such "creative" measures wouldn't need to be taken if it was simple for a user to augment their email app.

> if it was simple for a user to augment their email app

You don't really think it's ever "simple" for a user to augment their email app?

Plugins are hard to implement on both ends, and they complicate otherwise simple apps. Open source is also hard, because every codebase is different in many and often unpredictable ways from others. Not even an experienced programmer would always be able to crack open the source to a mobile email client and make this sort of modification.

Re: LinkedIn Intro: Doing the Impossible on iOS

#197
post #67
post #14

Earlier quoted context omitted.

There are lots of concerns: * your local mail client might get different E-mail content every time mail is downloaded, which is not the intent of IMAP, * LinkedIn (hence, the NSA) gets full access to your E-mail, * once people get hooked it's easy to transition to inserting ads, or "more helpful LinkedIn content", I find all this rather disturbing and would never use this service.

> * LinkedIn (hence, the NSA) gets full access to your E-mail, What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.

Yes, Google has your email, but not your credentials. A breach of your email exposes all the email you have now. Bad, yes. A breach of your credentials exposes all the email you get until you change them, and if you don't know to change them...

Re: LinkedIn Intro: Doing the Impossible on iOS

#198
post #191

To HN commenters: If you don't trust LinkedIn, fine. Don't use it. But please, don't assume that LinkedIn is universally not trusted, the same way you assume that Microsoft is universally hated. This is a neat feature, and I'm sure that many people trust LinkedIn enough to think that the trade-off is worth it. Would you prefer to not have the choice to have access to this feature, and prevent others from having it to…

"Would you prefer to not have the choice to have access to this feature, and prevent others from having it too?" Yes, I would prefer that. LinkedIn has not shown itself to be a particularly good or careful actor in the past, and now, even if I don't opt in to this, my email to people using this feature runs through LinkedIn servers. There are always third parties between me and the person I'm emailing, but as the num…

Common socialist thinking. People on top know better, therefore they should limit the freedom of the plebs.

Consider yourself lucky that you trust Google. Otherwise, imagine how risky it would be for you to email most people!

Paranoia is a hell of a disease. Probably the mental disorder of this era. Just look at all the drama that surrounds the NSA and "privacy".

In an alternative reality, people would probably pay for companies to spread their information publicly. And you know what? I'm confident that this reality is our future.

Learn to fight for the right things. Pro-tip: it's not privacy.

Re: LinkedIn Intro: Doing the Impossible on iOS

#200

Earlier quoted context omitted.

I work in enterprise information security, and my team agreed upon hearing this news that if this was used on our email system, we would consider it a MITM attack . Whether or not the end user opted in, the corporation did not. So, in the context of use in environments where your email address is not fully owned by you, attack would be a valid word. Otherwise, I agree that it's a MITM but not an attack.

Is your corporation going to fire the users who use this? If not, why not? They are aiding and abetting an outside attacker.

No, in the same way we don't fire people for getting viruses on their computer. Without a reason to believe the action was intentionally designed to cause harm to the business, like cstrat said, education is the best way to handle it. It would be hard to prove malicious intent in a case like this. LinkedIn would be attacking us, the user would just be an attack vector. It's akin to getting phished.
Post reply on HN