Live data from Hacker News

LinkedIn Intro: Doing the Impossible on iOS

engineering.linkedin.com

201–210 of 309 posts

Re: LinkedIn Intro: Doing the Impossible on iOS

#201
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

Is it illegal wire-tapping under US law if you enable the service voluntarily?

Re: LinkedIn Intro: Doing the Impossible on iOS

#202
post #110
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.

Like your average user is going to know the implications of opting into this service.

I doubt they have a warning when you install this "This is going to let us read all your emails AND the emails of people who communicate with you (without their consent)

...oh yes, and get your username / password for your email accounts"

And if I am communicating with someone who installed this hack then I certainly didn't opt-in.

Re: LinkedIn Intro: Doing the Impossible on iOS

#203
post #14

Technologically this is straightforward: it uses a proxy server that sits in between you and your actual mailserver. I think the privacy concerns of having your mail (potentially) available over yet another server in exchange for modest convenience makes it unlikely that I would use this, but I'm sure many will find the trade-off acceptable and desirable.

There are lots of concerns: * your local mail client might get different E-mail content every time mail is downloaded, which is not the intent of IMAP, * LinkedIn (hence, the NSA) gets full access to your E-mail, * once people get hooked it's easy to transition to inserting ads, or "more helpful LinkedIn content", I find all this rather disturbing and would never use this service.

> I find all this rather disturbing and would never use this service.

You don't have a choice. If the person on the other end is using this service then your emails to them are hoovered.

Re: LinkedIn Intro: Doing the Impossible on iOS

#204
post #75

I don't think I've ever gagged quite like that while reading a technical article describing a "neat hack". At first I'm thinking, oh, I wonder how they convinced Apple to let them use some private APIs, and then... curiosity turns to revulsion as soon as I saw that proxy diagram. Good god... LinkedIn MITM IMAP. That is truly terrifying. How would you even go about installing that on the user's phone? Oh, that's in th…

Where in the blog post does it say that your credentials are leaving the device in clear text. I know people don't like LinkedIn but I don't think even they would be dumb enough to do this over http.

How are they going to log in to your email account to MITM it, exactly, other than sending your password in cleartext to them? I'm not saying the connection itself is cleartext, but that they will be storing your email password in cleartext(!) to access your account at your email provider...

Re: LinkedIn Intro: Doing the Impossible on iOS

#205
post #110

Earlier quoted context omitted.

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.

Stop signs are opt-in. Ignoring them and/or telling other people to ignore them is a bad idea.

wat

Re: LinkedIn Intro: Doing the Impossible on iOS

#206
post #110

Earlier quoted context omitted.

Nerd outrage hyperbole much? This is an OPT IN service. You know, only for people who WANT to use it? If it causes you this degree of apoplexy, you are in luck: you don't have to use it.

Of course the average user understands that this feature allows LinkedIn to read their email ... right?

I don't think the average user understands that at all.

Re: LinkedIn Intro: Doing the Impossible on iOS

#208

Earlier quoted context omitted.

Is your corporation going to fire the users who use this? If not, why not? They are aiding and abetting an outside attacker.

No, in the same way we don't fire people for getting viruses on their computer. Without a reason to believe the action was intentionally designed to cause harm to the business, like cstrat said, education is the best way to handle it. It would be hard to prove malicious intent in a case like this. LinkedIn would be attacking us, the user would just be an attack vector. It's akin to getting phished.

I agree, and I think the major email providers should block it. Maybe Google can just cut off their API access and stop using LinkedIn for recruiting. That ought to get their attention.

Re: LinkedIn Intro: Doing the Impossible on iOS

#209
post #157

Earlier quoted context omitted.

There is nothing new about this. Putting a proxy into to modify content is as old as the usage of tcp proxies. What is new here is that they have no shame -- I don't expect software from a reputed company to pipe my email through their servers.

To play the devil's advocate, how is this any different morally from what Gmail (and Outlook, and Yahoo) do with their external emails feature? In each case, you give them the credentials for your other account, they pull the mail and display it in their interface (which, presumably, adds some new features that doesn't exist in the other account. Like conversations and tags.) LinkedIn is doing pretty much the same th…

G-mail/Yahoo: moving your content to your e-mail address.

LinkedIn: moving their content to your e-mail address.

G-mail/Yahoo: Duplicating your content.

LinkedIn: Manipulating your content.

G-mail/Yahoo: E-mail providers.

LinkedIn: Social media provider.

G-mail/Yahoo: uses protocols as intended to provide service.

LinkedIn: uses hacks to provide service.

G-mail/Yahoo: No risk of compromising devices.

LinkedIn: Extreme risk of device compromise. Intentionally circumvents device security features. Multiple potential points of security breach (at proxy server, at web server, through rendering engine).

No comparison, really.

Post reply on HN