Live data from Hacker News

LinkedIn accesses Gmail contacts via ‘auto-authorization’

thestack.com

41–49 of 49 posts

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#42
post #40
post #28

Earlier quoted context omitted.

I don't think there's a lesson to be learned. Their strategy is wildly successful.

The lesson is for users: be wary, click 'decline'

How can we be sure clicking 'Decline' has the behaviour we would expect?

The lesson is: don't use these services.

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#43
post #32

In previous stories[0] it turned out that LinkedIn was siphoning information via their mobile app. For example, if you're on Android and install LinkedIn you're granting the complete set of permissions the app requires plus automatically granting any new permissions the updated app specifies: This app has access to: Identity -find accounts on the device -add or remove accounts Calendar -read calendar events plus conf…

Most people are dumb and apathetic.

Why does that still surprise you?

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#44
post #12
post #6

I vouch for this claim that LinkedIn/Facebook seem to give recommendations to add someone as friend even when there is no chance that they could figure it out using data they have. I don't understand why browsers can't sandbox each tab such that there is no way to share cookies or cache. This is a serious breach of privacy if they are reading friend relationships based on your gmail open in other tabs.

It would not surprise me if one of their signals for recommendations is whether that party has viewed your profile.

That actually makes more sense.

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#45
post #34

If you know about browser security, you know that was is being described is just not possible. Likely that the author had authorized some google importer or something, but simply visiting 2 different websites in 2 tabs would not allow this. Just imagine the insanity if it was possible for another site to read from another tab.

Only if linkedin tab is opened from gmail via target="_blank". But surely gmail has protection against it.

still shouldn't work, since they are on different domains

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#46

Listen - I'm not above accusing LinkedIn of horrible things, but here we are basically taking the word of a call center rep over what we (should) know to be technical limitations of the platform in question. One of 3 things seems to be possible here: 1) The rep is right and gmail has an XSS vulnerability that LinkedIn is using 2) LinkedIn and Google are in bed and sharing this information based on some fingerprint-fo…

It seems to me that you're trying to turn the tables on the subject and pretend that linkedin's contact list abuse is, somehow or for any reason, instead an issue regarding a "cal center rep", which no one likes.

How about focusing on the problem instead of pulling a bait-and-switch?

The fact is linkedin tries incessantly to import contact lists from their users, sometimes in the clear and sometimes through shady dark-patterns.

Everyone who ever used linkedin is well aware of that.

Other social network services also abuse that angle, like facebook.

So, why exactly are you trying to pull the proverbial wool over everyone's eyes by trying to make believe that this issue is about an ill-reputed "call center rep" instead of the clamorous privacy abuse that social network services try to force on their users repeatedly?

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#47

Listen - I'm not above accusing LinkedIn of horrible things, but here we are basically taking the word of a call center rep over what we (should) know to be technical limitations of the platform in question. One of 3 things seems to be possible here: 1) The rep is right and gmail has an XSS vulnerability that LinkedIn is using 2) LinkedIn and Google are in bed and sharing this information based on some fingerprint-fo…

It seems to me that you're trying to turn the tables on the subject and pretend that linkedin's contact list abuse is, somehow or for any reason, instead an issue regarding a "cal center rep", which no one likes. How about focusing on the problem instead of pulling a bait-and-switch? The fact is linkedin tries incessantly to import contact lists from their users, sometimes in the clear and sometimes through shady dar…

I'm trying to focus on he content of the article and not the hundreds of other blog posts about scummy LI behavior. The linked post has nothing to do with dark patterns, which are crappy and LI is clearly guilty of.

I'm not sure what exactly you feel I'm trying to lie about here - my post stated I think that LI conned this guy out of his contacts instead of utilizing some heretofore unknown technology to steal them from a separate browser window.

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#48

Earlier quoted context omitted.

It seems to me that you're trying to turn the tables on the subject and pretend that linkedin's contact list abuse is, somehow or for any reason, instead an issue regarding a "cal center rep", which no one likes. How about focusing on the problem instead of pulling a bait-and-switch? The fact is linkedin tries incessantly to import contact lists from their users, sometimes in the clear and sometimes through shady dar…

I'm trying to focus on he content of the article and not the hundreds of other blog posts about scummy LI behavior. The linked post has nothing to do with dark patterns, which are crappy and LI is clearly guilty of. I'm not sure what exactly you feel I'm trying to lie about here - my post stated I think that LI conned this guy out of his contacts instead of utilizing some heretofore unknown technology to steal them f…

> I'm trying to focus on he content of the article

If you actually had any intention on focusing on the content, you wouldn't had tried to turn the tables with a blatant ad-hominem while turning a blind eye to the issue.

Re: LinkedIn accesses Gmail contacts via ‘auto-authorization’

#49
Hey folks,

As the Product Manager of LinkedIn’s contacts import products, I can confirm that the original explanation was erroneous. The article on thestack.com references a Quora thread that was inaccurate due to misinformation from our representative, which we've corrected. He's also since posted a correction in reply to his answer; see https://www.quora.com/Does-LinkedIn-access-your-email-or-con....

We apologize for any confusion this caused and are working with our reps to ensure we correct any misinformation like this in the future.

We never send invitations without an action from the member. When you add connections you see the following:

-- a description of what occurs when you import your contacts to LinkedIn

-- a page allowing members to unselect contacts from the connection request.

You must go into the address book import page and authenticate the import of your contacts from your email. It does not happen just by being logged into LinkedIn and your email on the same browser.

Moreover, you can view, manage, and delete your imported contacts at any time by going to https://www.linkedin.com/people/contacts.

Thanks,

Barry

Post reply on HN