Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

161–170 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#161
To HN commenters:

If you don't trust LinkedIn, fine. Don't use it.

But please, don't assume that LinkedIn is universally not trusted, the same way you assume that Microsoft is universally hated.

This is a neat feature, and I'm sure that many people trust LinkedIn enough to think that the trade-off is worth it. Would you prefer to not have the choice to have access to this feature, and prevent others from having it too?

I don't see this kind of reaction when 99% of other services ask access to a third-party API. Why is this so different? Is it because they have access to emails? What makes email SO MUCH more important than any other data to be in a category of their own? I don't think you can draw a line, and it's pure subjectivity.

Surely, the service itself is not a problem. Google would do the same thing, and you would all think it's the best thing since sliced bread? Why? Because most people already trust Google with their emails (and everything else), and accept that they know everything about them.

So please, don't criticize the solution, don't blame the hack (unless you can suggest a better way to do it). The only good reason not to use it is for lack of trust for LinkedIn, and nothing else.

I've had enough of your drama-seeking behaviors, and I don't think I'm the only one. Grow up.

Re: LinkedIn Intro: Doing the Impossible on iOS

#163
post #110
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.

Stop signs are opt-in. Ignoring them and/or telling other people to ignore them is a bad idea.

Re: LinkedIn Intro: Doing the Impossible on iOS

#164
post #93

I've been talking to a number of startups whose products hinge on access to a user's email inbox. Now here is LinkedIn doing this too. This trend is kind of disturbing to me, I can't really imagine a future where most of the services I use require access to all of my personal e-mail. It's quite scary.

LinkedIn is a public company whose product is actually very simple and whose maintenance and improvement does not really require the number of employees they have. Initiatives like this spawn from boredom in that kind of environment, because the product slack goes all the way up the chain. The Iron Law[1] says that the programmers are going to be bored, the product managers and creatives with input will approve and s…

Um that part about LinkedIn's product being simple... what??

Re: LinkedIn Intro: Doing the Impossible on iOS

#165
post #132

Looks to me like Apple has some security to tighten up. I definitely don't think you should be able to do most of this stuff, but you can't really fault LinkedIn I don't think. They made something that adds value to their product and it got approved by Apple. Either way, the hacks are cool ones and I'm glad Linked-in did this write up. Keep 'em coming. EDIT: not an app apparently.

This isn't an app and Apple has no involvement in approving it. RTA - it's an IMAP proxy that injects some css/html stuff to each of your emails.

Ah wow didn't realize that. In their FAQ it said "tap the Intro app icon" to add a new account so I assumed it was an app.

Re: LinkedIn Intro: Doing the Impossible on iOS

#166
post #110

Earlier quoted context omitted.

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.

> Nerd outrage hyperbole much? How is that even close to a valid response to someone that's exercising critical thinking?

It's a blaming statement, which means he's not.

Re: LinkedIn Intro: Doing the Impossible on iOS

#167
post #113

Earlier quoted context omitted.

This service shouldn't exist. It breaks the very concept of email security. They're marketing it as though it's safe. Want hyperbole? Imagine Bayer marketing heroin as safe because you know, it's opt-in.

Want hyperbole? Compare an opt in social network to heroin.

Why the hell not? Heroin from Bayer would not have the quality control issues Heroin typically has.

It only becomes problematic when you consider that the user is getting themselves into a situation that they do not fully understand and potentially cannot easily back themselves out of.

With drugs that have a high potential to cause harm, we typically force the consumer to consult a professional before allowing them to proceed. Tech is still in the era of patent medicines.

Re: LinkedIn Intro: Doing the Impossible on iOS

#168
post #64

Not only does it obliterate users' security but it introduces a potentially unreliable point of failure. Sometimes the hack is worse than the problem it solves. I hope they're being extremely upfront with users about how this works, not that most users will really understand the implications...

Good point re point of failure. If LinkedIn doesn't put a lot of resources into the proxy servers, mail delivery could be very slow or fail completely. I"m still impressed with the creativity from a technical standpoint.

Even if it has a lot of resources behind it, if it experienced an outage, the end user would be unaware that their mail service is still up, and since they didn't change the settings, they wouldn't know they could remove the proxy to access their mail until the outage is resolved.

Re: LinkedIn Intro: Doing the Impossible on iOS

#169
post #102
post #67

Earlier quoted context omitted.

> * LinkedIn (hence, the NSA) gets full access to your E-mail, What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? My major concern is that if I provide Linkedin my credentials, I now have doubled my attack surface for intrusion by non-governmental actors.

>What if I believe that Google (hence the NSA) already has access to my Gmail? What's the cost to my privacy if it's already lost? Can I have your gmail and password? If not, why not?

I believe they use OAuth for Gmail and Google Apps, much like Mailbox.

Re: LinkedIn Intro: Doing the Impossible on iOS

#170
post #27

Earlier quoted context omitted.

If you think about the reach Linked in has, combine that with each contact the linked in user has and you have a very fast database of emails that can be misused.

Isn't that the whole point of Rapportive? They're the only company I can think of that has successfully solved the "social profile matching" problem that I can think of off the top of my head.

Ark does, and with significantly more data.
Post reply on HN