Live data from Hacker News

LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

thenextweb.com

11–20 of 43 posts

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#12
post #10

This is only tangentially related but I really don't understand why anyone cares so highly about their contact list. Does it really matter? Why does it matter? Concerns about spam seem anachronistic (in that you have to deal with spam and services like Gmail have become pretty good at countering it). Is it just privacy? If so, I'm confused.

Perhaps it is a trust issue. When I get someone's contact information, I expect to be consciously aware any time I give that information to someone else.

"Would Alice want Bob to have her contact information? She gave it to me, but that doesn't give me the right to share it with others--it's hers."

It seems like asking an assistant to go through your contacts to prepare for a meeting, and while he's at it, he copies them all to his computer so he can do a better job. A little creepy and maybe acceptable. At best it's not what you asked for.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#13
post #8
post #7

Earlier quoted context omitted.

TNW rips off more than just pictures.

Agreed (although this article appears to contain some original reporting), but their neglect for proper image attribution is especially egregious. It is most bothersome to me because all they have to do is mention the guy's name and they get to use his image free of charge, but instead they resort to some sort of half-hidden generic link-back.

I've made a change to credit the image more prominently with the photographer's name.

As a photographer myself, who does offer images under a CC license, I understand the importance of crediting. It was not my intention to slight them in any way.

And you'll find that a good many of the articles that we publish contain original reporting. Thank you for reading.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#14
post #10

This is only tangentially related but I really don't understand why anyone cares so highly about their contact list. Does it really matter? Why does it matter? Concerns about spam seem anachronistic (in that you have to deal with spam and services like Gmail have become pretty good at countering it). Is it just privacy? If so, I'm confused.

While this is not a direct violation of California law SB1386, it is not a long distance to be able to argue that the companies in question are acquiring unauthorized personal information. While we're not talking SSN, driver's license, etc etc., the definition of PII is only going to expand over time.

Basically, if I don't have a personal contract with LinkedIn, it is extremely thin ice for them to be collecting my e-mail address just because I was invited to one of your meetings.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#15
post #8

Earlier quoted context omitted.

Agreed (although this article appears to contain some original reporting), but their neglect for proper image attribution is especially egregious. It is most bothersome to me because all they have to do is mention the guy's name and they get to use his image free of charge, but instead they resort to some sort of half-hidden generic link-back.

I've made a change to credit the image more prominently with the photographer's name. As a photographer myself, who does offer images under a CC license, I understand the importance of crediting. It was not my intention to slight them in any way. And you'll find that a good many of the articles that we publish contain original reporting. Thank you for reading.

Thanks Matthew - glad to see you're willing to make that change. I noticed a number of other TNW articles from today also using the same anonymous attribution, one of which was another of yours (http://thenextweb.com/apple/2012/06/05/apple-tv-5-0-2-softwa...). If you'd take a moment to fix the attribution and mention something to your colleagues as well that would be awesome.

A couple of the other articles I noticed are here:

http://thenextweb.com/insider/2012/06/06/bid-for-a-dinner-wi...

http://thenextweb.com/apps/2012/06/05/trickster-for-mac-help...

http://thenextweb.com/media/2012/06/05/tvs-status-quo-may-be...

http://thenextweb.com/apps/2012/06/05/here-are-the-winners-o...

Thanks!

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#16
post #9
post #6

This is off topic, but the next web really needs to make an effort to properly credit images. They've been called out on this a number of times before, but the way they credit image sources is just plain wrong. In this article, for example, at the very bottom of the page is a generic link that says SOURCES: IMAGE CREDIT. With this particular image, the photographer very clearly says "please, kindly credit me (Nan Pal…

sort of off topic but I used to work at LinkedIn and created the foil wrapped logo'd chocolates being photographed. we used them as a giveaway back at CES in 2010 in the blackberry booth. its cool that the images is offered under CC license and has been included in so many articles about LinkedIn, he should get a photo credit

That's pretty cool actually - small world!

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#17
post #10

This is only tangentially related but I really don't understand why anyone cares so highly about their contact list. Does it really matter? Why does it matter? Concerns about spam seem anachronistic (in that you have to deal with spam and services like Gmail have become pretty good at countering it). Is it just privacy? If so, I'm confused.

Out of principle, an app must not collect what it doesn't need. If the programmer thinks nothing sensitive should be in there, it's still not ok. Unrelated example because you mention the contact list - people who put passwords in there as phone numbers.

What really got to me though are notes. Notes! Of course no user should write "make that fat ass invest in us" in their appointment notes, but that is not how privacy works.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#18
post #10

This is only tangentially related but I really don't understand why anyone cares so highly about their contact list. Does it really matter? Why does it matter? Concerns about spam seem anachronistic (in that you have to deal with spam and services like Gmail have become pretty good at countering it). Is it just privacy? If so, I'm confused.

Out of principle, an app must not collect what it doesn't need. If the programmer thinks nothing sensitive should be in there, it's still not ok. Unrelated example because you mention the contact list - people who put passwords in there as phone numbers. What really got to me though are notes . Notes! Of course no user should write "make that fat ass invest in us" in their appointment notes, but that is not how priva…

Not to mention meeting notes that are under a strict NDA.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#19
post #10

This is only tangentially related but I really don't understand why anyone cares so highly about their contact list. Does it really matter? Why does it matter? Concerns about spam seem anachronistic (in that you have to deal with spam and services like Gmail have become pretty good at countering it). Is it just privacy? If so, I'm confused.

The personal contact info of other individuals is not mine to share. They've entrusted me with their privacy, but it's theirs to continue to hide or share as they will.

Re: LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text

#20
post #10

This is only tangentially related but I really don't understand why anyone cares so highly about their contact list. Does it really matter? Why does it matter? Concerns about spam seem anachronistic (in that you have to deal with spam and services like Gmail have become pretty good at countering it). Is it just privacy? If so, I'm confused.

First off, I will point out: this is not a leak of your contact list, it is a leak of your calendar. You might have a very different perspective of the kind of information you store in your calendar, as it includes (explicitly from the article) meeting notes (in which I can imagine someone even having stored a bunch of sensitive corporate information) and the date/time and location of your upcoming whereabouts.

That said, I will also attempt to answer your question as asked, partly as everyone else is responding to you under the guise "LinkedIn should not get this data", yet, I, generally agree with you: for most people that is the worry of someone who is paranoid. That said, I /can/ come up with legitimate (but unlikely) situations where I'd fear for someone's life based on an address book being accessible from LinkedIn.

However, to me the key problem here is "in plain text": it is one thing for a service that already knows too much about me and the people I work with to know a little more about them, or think about people hacking into LinkedIn (again unlikely), but it is an entirely different thing for everyone sharing the WiFi network I'm on to have my entire contact list: these are people who are actually in a position to take action.

It might be your ex-husband who has been stalking you ever since the divorce, or it might be the creepy guy that hangs out at the comic book shop who seems to have taken slightly too much of an interest in you. It could even be someone running a scam: they go to conferences, intercept as many address books as possible, and try to use the result for some kind of social engineering hack or even identity theft.

If you haven't yet, I thereby implore you to consider "what could I learn about my best friend if I had their entire contact list": looking at it from the vaguely mischievous and voyeuristic stance of it being someone else's data might make it simpler to envision why that person might not want you to know all of that information. If that fails, then try to think about it from the perspective of a thief or an evil employer.

Post reply on HN