I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…
LinkedIn Intro: Doing the Impossible on iOS
201–210 of 309 posts
Re: LinkedIn Intro: Doing the Impossible on iOS
#202I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…
Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.
I doubt they have a warning when you install this "This is going to let us read all your emails AND the emails of people who communicate with you (without their consent)
...oh yes, and get your username / password for your email accounts"
And if I am communicating with someone who installed this hack then I certainly didn't opt-in.
Re: LinkedIn Intro: Doing the Impossible on iOS
#203Technologically this is straightforward: it uses a proxy server that sits in between you and your actual mailserver. I think the privacy concerns of having your mail (potentially) available over yet another server in exchange for modest convenience makes it unlikely that I would use this, but I'm sure many will find the trade-off acceptable and desirable.
There are lots of concerns: * your local mail client might get different E-mail content every time mail is downloaded, which is not the intent of IMAP, * LinkedIn (hence, the NSA) gets full access to your E-mail, * once people get hooked it's easy to transition to inserting ads, or "more helpful LinkedIn content", I find all this rather disturbing and would never use this service.
You don't have a choice. If the person on the other end is using this service then your emails to them are hoovered.
Re: LinkedIn Intro: Doing the Impossible on iOS
#204I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…
Where in the blog post does it say that your credentials are leaving the device in clear text. I know people don't like LinkedIn but I don't think even they would be dumb enough to do this over http.
Re: LinkedIn Intro: Doing the Impossible on iOS
#205Earlier quoted context omitted.
Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.
Stop signs are opt-in. Ignoring them and/or telling other people to ignore them is a bad idea.
Re: LinkedIn Intro: Doing the Impossible on iOS
#206Earlier quoted context omitted.
Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.
Of course the average user understands that this feature allows LinkedIn to read their email ... right?
Re: LinkedIn Intro: Doing the Impossible on iOS
#207I burst out in laughter at that point. Yeah, that silly presumptuous email client assuming an email is some kind of text message that doesn't change every time you read it!
Re: LinkedIn Intro: Doing the Impossible on iOS
#208Earlier quoted context omitted.
Is your corporation going to fire the users who use this? If not, why not? They are aiding and abetting an outside attacker.
No, in the same way we don't fire people for getting viruses on their computer. Without a reason to believe the action was intentionally designed to cause harm to the business, like cstrat said, education is the best way to handle it. It would be hard to prove malicious intent in a case like this. LinkedIn would be attacking us, the user would just be an attack vector. It's akin to getting phished.
Re: LinkedIn Intro: Doing the Impossible on iOS
#209Earlier quoted context omitted.
There is nothing new about this. Putting a proxy into to modify content is as old as the usage of tcp proxies. What is new here is that they have no shame -- I don't expect software from a reputed company to pipe my email through their servers.
To play the devil's advocate, how is this any different morally from what Gmail (and Outlook, and Yahoo) do with their external emails feature? In each case, you give them the credentials for your other account, they pull the mail and display it in their interface (which, presumably, adds some new features that doesn't exist in the other account. Like conversations and tags.) LinkedIn is doing pretty much the same th…
LinkedIn: moving their content to your e-mail address.
G-mail/Yahoo: Duplicating your content.
LinkedIn: Manipulating your content.
G-mail/Yahoo: E-mail providers.
LinkedIn: Social media provider.
G-mail/Yahoo: uses protocols as intended to provide service.
LinkedIn: uses hacks to provide service.
G-mail/Yahoo: No risk of compromising devices.
LinkedIn: Extreme risk of device compromise. Intentionally circumvents device security features. Multiple potential points of security breach (at proxy server, at web server, through rendering engine).
No comparison, really.