3 ms·
That’s a serious statement! Do you have direct knowledge of this, or is it just gossip?
by genmon 5y ago
That’s a serious statement! Do you have direct knowledge of this, or is it just gossip?
- notyourwork 5y ago100% agree, pretty bold claim to make without support.
- ittan 5y agoHaven't heard about LinkedIn trying to login using social media, but LinkedIn has a feature that does contact import. LinkedIn asks me to sync my contact/address book information from another source. After the import runs they show you connections that match your contacts sometimes in the connections tab. https://www.linkedin.com/help/linkedin/answer/1278/syncing-contacts-from-other-address-books-and-sources https://www.linkedin.com/help/linkedin/answer/1278/syncing-c...
- TechBro8615 5y agoThis was a well known fact during the years 2012 - 2015. It's not like it was hidden. LinkedIn asked you to enter your GMail password in a form on their website. It didn't require any sleuthing – you just had to log into LinkedIn and you could see for yourself. The reason they implemented it that way is because Google did not yet provide APIs to facilitate contact import. As Google adopted more secure standards like OAuth, LinkedIn started using the official GMail API features like "import contacts," rather than logging into your account on your behalf. People underestimate just how far privacy/security have come since 2013 (pre-Snowden), when even major websites still used HTTP on their payment portals. Someone could sit in a coffeeshop with FireSheep and alter your Amazon order. Privacy enhancing features like OAuth, TLS, and 2FA have only become widespread in the last 7-8 years.
- rootusrootus 5y agoWhat you're describing is them asking you to give them the password explicitly so they could log in and get your contact list. GP suggested they did this behind the scenes by trying the password you use with their service. That's a pretty big claim.
- TechBro8615 5y agoOh, yeah I see what you're saying. They didn't "guess" your GMail password as far as I know (although I wouldn't put it past them, especially back then). Giving them your password so they can login on your behalf is just as egregious, IMO. Then again, Plaid did the same thing with your bank account and created a multi-billion dollar business out of it.
- windmark 5y agoHaving the user enter their password for connecting to Gmail is very different to having the service try the passwords themselves. The service shouldn't even have the password in clear text to begin with. Until OP provides proof I doubt this claim from such a big service like LinkedIn.
- extra88 5y ago> LinkedIn asked you to enter your GMail password in a form on their website. That is entirely different than what was claimed. The claim was platforms were running "credential stuffing" attacks against their own users by attempting logins to other platforms by guessing that they use the same email address and password for both.