Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

241–250 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#241

I don't understand why trusting LI with all your email is worse than trusting Google with all your email. Sure, if you do it for your corporate email, you may be violating the rules of your employer, but that's between you and your employer, and not enough reason to keep others from using an amazingly useful service for their own personal email. Lost in all this discussion is just how awesome Rapportive is - the desk…

> I don't understand why trusting LI with all your email is worse than trusting Google with all your email.

This is like trusting LI and Google with all your email. trusting any 2 parties with your email is less secure than trusting 1 party with it. This increases when only 1 of them is in the business of providing email. What is the other party's interest, and does this conflict with your trust?

Re: LinkedIn Intro: Doing the Impossible on iOS

#242

Earlier quoted context omitted.

To play the devil's advocate, how is this any different morally from what Gmail (and Outlook, and Yahoo) do with their external emails feature? In each case, you give them the credentials for your other account, they pull the mail and display it in their interface (which, presumably, adds some new features that doesn't exist in the other account. Like conversations and tags.) LinkedIn is doing pretty much the same th…

G-mail/Yahoo: moving your content to your e-mail address. LinkedIn: moving their content to your e-mail address. G-mail/Yahoo: Duplicating your content. LinkedIn: Manipulating your content. G-mail/Yahoo: E-mail providers. LinkedIn: Social media provider. G-mail/Yahoo: uses protocols as intended to provide service. LinkedIn: uses hacks to provide service. G-mail/Yahoo: No risk of compromising devices. LinkedIn: Extrem…

Everything they do differently is irrelevant as long as the user is asking them to do those things. If Gmail starts showing me fetish porn that's bad, if a fetish porn site does the same thing it's fine.

The only relevant difference is security/privacy, in which Google may be more trustworthy but even that is debatable, regardless of which side of the debate you land on.

Re: LinkedIn Intro: Doing the Impossible on iOS

#243

Holy fucking shit Batman! Assuming I read this correctly LinkedIn will now have access to all of your emails, your email credentials, and will now have the ability to both spoof your email, and MITM all incoming mail (banking etc). I was actually impressed at some of the little hacks they found, until they dropped this on me halfway through the blog. My jaw hit the ground. This is probably the most blatant disregard…

I completely agree. I'm absolutely disgusted by this.

Re: LinkedIn Intro: Doing the Impossible on iOS

#244
post #211

Earlier quoted context omitted.

There are good ways to remove 95%+ of the content even if you forward/reply from a different account. We'll talk about this in an upcoming post.

95% != 100%. So there's a nontrivial chance that if I'm connected to someone in LinkedIn whose profile is "private", then if I forward a message from him (containing this LinkedIn flair) to some third party (who is not connected to him), then I could expose his profile details to the third party? That's a privacy lawsuit just waiting to happen.

Every time I get an email from LinkedIn with updates on private profiles of people I am connected to I could forward that email to anyone, is that a privacy lawsuit waiting to happen too?

Re: LinkedIn Intro: Doing the Impossible on iOS

#245
post #44

Is this a MITM attack wrapped as an App?

Not just MITM, MITM + DDOS! Now you have 220,000,000 LinkedIn users all running their email traffic through LinkedIn's proxy. I'm sure they have the bandwidth and CPU to handle that.

By that logic isn't every popular website/service in the world a "DDOS problem" because it attracts lots of traffic?

Re: LinkedIn Intro: Doing the Impossible on iOS

#246
post #240

For all those calling this a "hack", it is not. It is simply a "man in the middle" attack. It is wrong. It is a total violation of trust. It is gross.

I would only say that it is a violation of trust if they somehow installed the certificate on your phone when installing the linkedIn app... If a user knowingly installs this, with the understanding that linkedin is essentially a proxy for their entire email ecosystem - then they are knowingly trusting linkedin. To be honest, I can see this being used by sales reps. They are often interested in connecting to people a…

1) Your average user has no idea what an iOS cert is doing.

2) Your average IT department in any publicly traded company would NEVER let this fly.

3) Any general council would shat all over this. No one likes fighting with lawyers, and this is a battle I'd never put on my plate.

It's odd to assume generic users understands IMAP or what a proxy is. Remember how Apple makes products for dumb people? Yeah. They ran a campaign on that.

On top of all of this, they have a "if you're a Google Apps admin" section where the only way to block it is to disable ALL OAuth applications.

No self-respecting CTO/CIO would let this occur in an organization they hope to responsibly grow.

Re: LinkedIn Intro: Doing the Impossible on iOS

#247
post #89

Earlier quoted context omitted.

Which parts would Apple have an issue with? The proxy server is the only part I can think of. Using images, CSS, and iframes in Mail is presumably a very deliberate feature.

Apple has blocked apps for a lot less than providing a feature that intercepts users' email and email password to circumvent Apple's own sandboxing and inject content into their mailbox...

Uhm... Apple doesn't whitelist nor blacklist services -- read: TCP connections to whoever you want. LinkedIn, in this case, is well within Apple's TOS/EULA.

I think you're confused about the policies on their app store.

Re: LinkedIn Intro: Doing the Impossible on iOS

#248

Earlier quoted context omitted.

What could they do about it? Not allow you to create a mail account that points to linkedin.com as the server?

Apple could yank the certificate that LinkedIn is using for configuration profiles, which would make installation significantly more difficult for the average user.

Apple, to my knowledge, has never revoked a single cert for config profiles since they're rarely used outside of the mobile dev market.

Any examples of them doing what you have proposed?

Re: LinkedIn Intro: Doing the Impossible on iOS

#249

The privacy outrage around this is nonsensical. Over 500 million people trust Google with complete and indefinite access to their email. The leap from trusting no external email providers to trusting Gmail is much greater than this incremental step of trusting LinkedIn as well. The risk is similar to trusting an established company to automatically backup your emails, and smaller than trusting startups like Greplin (…

With your claim, why not make your e-mail public? If you're not worried about Google -- who is already in bed with the NSA -- and you're not worried about LinkedIn -- who is proposing to proxy ALL your e-mails -- then just setup a script to auto-dump every single e-mail you get to GitHub.

Win Win! You get to act like privacy isn't a real threat, and you validate your point!

Re: LinkedIn Intro: Doing the Impossible on iOS

#250
post #164

Earlier quoted context omitted.

LinkedIn is a public company whose product is actually very simple and whose maintenance and improvement does not really require the number of employees they have. Initiatives like this spawn from boredom in that kind of environment, because the product slack goes all the way up the chain. The Iron Law[1] says that the programmers are going to be bored, the product managers and creatives with input will approve and s…

Um that part about LinkedIn's product being simple... what??

Yes. Users with friends, an activity feed, and job classifieds are all solved problems that many underemployed web developers could throw a prototype together in weeks or a few months. Tack on that pointless skills voting junk and webboards as desired. Did I miss anything?

The fact that they have stockholders means they always have to do something: Google and driverless cars, Musk going to Mars, Facebook going phone...this IMAP hijacking is LinkedIn's current something that they have to come up with to have a story to tell investors so that they don't think LinkedIn is "stagnating."

Post reply on HN