Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

291–300 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#291
post #164

Earlier quoted context omitted.

Um that part about LinkedIn's product being simple... what??

Yes. Users with friends, an activity feed, and job classifieds are all solved problems that many underemployed web developers could throw a prototype together in weeks or a few months. Tack on that pointless skills voting junk and webboards as desired. Did I miss anything? The fact that they have stockholders means they always have to do something : Google and driverless cars, Musk going to Mars, Facebook going phone…

Building _anything_ on that scale is not trivial.

Re: LinkedIn Intro: Doing the Impossible on iOS

#293

Earlier quoted context omitted.

A private self-hosted version of this wouldn't be that bad. Imagine that you write the same proxy, and it injects data grabbed from the various API's its hooked up to.

This. The tech described is pretty neat... Give you my email creds? Hell no. But _I_ could do all that myself. I think that would be one way that linkedin could save this - release an easy to set up open source version, say one click to a heroku instance or something. Then one could add all sorts of smart stuff into their own emails.

Agreed. Imagine if you could have other providers snap into this? It's a shame that they're hacking their way around Apple's walled garden, but a self hosted proxy server is a nifty way to add functionality to email.

Re: LinkedIn Intro: Doing the Impossible on iOS

#294
post #288

Earlier quoted context omitted.

We do block VPN on our corporate network, yes. A VPN is a tunnel that hides user activity from our monitoring and DLP tools and use of VPN from our network to the outside is against policy. Likewise, sharing your credentials with a third party is against policy. The attacker is LinkedIn. The employee is the attack vector. LinkedIn is engaging in a phishing attack.

You didn't explicitly answer whether you consider VPN usage to be a man in the middle attack. I understand banning it (as well as this LinkedIn feature) on a corporate network, but not considering either a man in the middle attack.

VPN is a tunnel, not a MITM. It's used to bypass our monitoring and filtering. You're tunneling out of our network into someone else's, which may have more favorable rules.

This is a MITM, because LinkedIn is intercepting and modifying the traffic between the email server and the client machine, traffic which is supposed to only be read by the recipient. A VPN isn't intercepting traffic, it's used to tunnel traffic. LinkedIn is positioning themselves directly between the traffic source and the destination to read and modify the transmission.

Re: LinkedIn Intro: Doing the Impossible on iOS

#295

I don't understand why trusting LI with all your email is worse than trusting Google with all your email. Sure, if you do it for your corporate email, you may be violating the rules of your employer, but that's between you and your employer, and not enough reason to keep others from using an amazingly useful service for their own personal email. Lost in all this discussion is just how awesome Rapportive is - the desk…

> Curious: does everyone in this thread have equal outrage for those widgets that log into your email clients so that you can invite your friends?

Yes, there has been much rage against that type of service on HN.

Re: LinkedIn Intro: Doing the Impossible on iOS

#296
post #113
post #110

Earlier quoted context omitted.

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.

This service shouldn't exist. It breaks the very concept of email security. They're marketing it as though it's safe. Want hyperbole? Imagine Bayer marketing heroin as safe because you know, it's opt-in.

Not that hard to imagine really given Bayer did market heroin as safe. Is very good for coughs, apparently.

Re: LinkedIn Intro: Doing the Impossible on iOS

#297
post #225

Earlier quoted context omitted.

To be fair, they specifically mention that they use OAuth for Gmail/GApps. It seems like they're aware of this but it's hardly their responsibility to avoid building a hack such as this just because Google are the only provider to allow IMAP access with OAuth. If more e-mail providers would allow such authentication, I'm sure LinkedIn would be happy to extend the support.

It seems like they're aware of this but it's hardly their responsibility to avoid building a hack such as this... Is that so? "Fsck the world, we got a business to run?"

How about "the world isn't perfect and whilst it would be great to live up to our every ideal, our primary responsibility is running a business and providing a great experience for our users who, ultimately, in the vast majority regularly engage in such egregious violations of sensible security protocol that most-anything we do is unlikely to affect them and in cases where it would, said users are usually sufficiently literate to wish to avoid this anyway".

Re: LinkedIn Intro: Doing the Impossible on iOS

#298
post #12

Surely corporate IT departments are going to have a collective heart attack as employees start handing all their email to a third party?

Since this only works with Gmail, Google Apps, Yahoo, AOL, and iCloud, the email is already with a third party.

That is an interesting note, but if the business is using Gmail (http://www.google.com/enterprise/apps/business/products.html) maybe that's because they trust Google's services. Trusting one third party doesn't imply that you trust all third parties.

Re: LinkedIn Intro: Doing the Impossible on iOS

#299
post #297

Earlier quoted context omitted.

It seems like they're aware of this but it's hardly their responsibility to avoid building a hack such as this... Is that so? "Fsck the world, we got a business to run?"

How about "the world isn't perfect and whilst it would be great to live up to our every ideal, our primary responsibility is running a business and providing a great experience for our users who, ultimately, in the vast majority regularly engage in such egregious violations of sensible security protocol that most-anything we do is unlikely to affect them and in cases where it would, said users are usually sufficientl…

That's a pretty long-winded explication of, "it's a race to the bottom."

Re: LinkedIn Intro: Doing the Impossible on iOS

#300
post #110

Earlier quoted context omitted.

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.

Like your average user is going to know the implications of opting into this service. I doubt they have a warning when you install this "This is going to let us read all your emails AND the emails of people who communicate with you (without their consent) ...oh yes, and get your username / password for your email accounts" And if I am communicating with someone who installed this hack then I certainly didn't opt-in.

>And if I am communicating with someone who installed this hack then I certainly didn't opt-in.

This is extremely important and getting lost in the noise.

Post reply on HN