Live data from Hacker News

LinkedIn accesses Gmail contacts via ‘auto-authorization’

thestack.com

21–30 of 49 posts

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#21

If you know about browser security, you know that was is being described is just not possible. Likely that the author had authorized some google importer or something, but simply visiting 2 different websites in 2 tabs would not allow this. Just imagine the insanity if it was possible for another site to read from another tab.

I want to agree with you but I've seen a similar situation with Yahoo mail for someone else, and I confirmed first-hand they had not imported their contacts. So I don't even know what to believe anymore. It makes no sense for this to be possible, but neither does the story everyone is recounting.

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#22

This drives me absolutely nuts. It makes me want to delete my LinkedIn account.

They have been trying to access Outlook accounts for the same reason for years, by asking for your password in a deceptive way. But if this is true it's next-level evil indeed, it seems that Gmail has an open XSS vulnerability, and LinkedIn (and Facebook too?) are using it to outright hack into your account.

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#23
post #4

There is also another option. Suppose, for a moment, that I've sent my friend an email and he/she has allowed LinkedIn access to their Google Contacts, even though I have not...there is no reason LinkedIn wouldn't still show me them as a contact to add, since they know the connection. They just know it from the other side.

Except LinkedIn very explicitly said that doesn't have to be the case, and the article shows examples of LinkedIn suggesting that the author invites non-users from his Gmail contacts to LinkedIn.

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#27
> At a technical level this kind of cross-site cross-pollination is quite achievable with the technical resources available to the major players concerned – supercookies, canvas fingerprinting, and global cookies acting as cross-site intermediaries all offer the possibility of breaking through a website’s sandbox.

Any idea what they're getting at here? All of them just sound like ways to uniquely identify a user.. so being generous I'll assume LinkedIn can always work out my gmail address even if I use another address to sign up.. what next, they hack my account using one of those?

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#28

groan ... grabs pitchfork But seriously though, why does LinkedIn refuse to learn time and time again? There's a line between being aggressive and being outright dishonest and the line isn't all that hard to determine. Uber is often aggressive but rarely are they dishonest in their practices (at least not egregiously from what I know). But at this point LinkedIn is the leader in practices like this and it's not all t…

I don't think there's a lesson to be learned. Their strategy is wildly successful.

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#29
If this is true, then any website could use this same method to access Gmail contacts if you happen to have Gmail open in the same browser session.

Seems unlikely that it really works this way, it would be a huge security hole - spammers and scammers would be using this all the time to harvest addresses.

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#30
post #10

This is hilarious - relevant snippet from support conversation from article: "if you had at any time your LinkedIn account open and accessed any of your emails through the same browser…In order from preventing this from happening again, you will want to be careful to not open up your personal email address in the same browser when you have your LinkedIn account open.’"

followed by: "We are not doing this to invade your privacy, we are doing this to assist you in growing your network."
Post reply on HN