5 ms·
LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text
- deleted 14y ago[deleted]
- philip1209 14y agoI don't believe that this is an egregious error.
- davidmp 14y agoAt least it's opt-in.
- joering2 14y ago> "It’s unlikely, given its reputation, that the service is using it for any nefarious means" yes, of course, and CEO Mr. Reid Hoffman hangs out at 2012 Bilderberg meeting [1] (that officially does not exist, and its just a "conspiracy theory") only because he adores a company of a bunch of old farts. move along, nothing to see here! [1] http://theintelhub.com/2012/05/31/bilderberg-2012-official-participant-list/ http://theintelhub.com/2012/05/31/bilderberg-2012-official-p...
- rjsamson 14y agoThis is off topic, but the next web really needs to make an effort to properly credit images. They've been called out on this a number of times before, but the way they credit image sources is just plain wrong. In this article, for example, at the very bottom of the page is a generic link that says SOURCES: IMAGE CREDIT. With this particular image, the photographer very clearly says "please, kindly credit me (Nan Palmero) with the photo and link back here" - nowhere do they credit him by name. A quick check of all of the other publications using her photo do properly credit her by name, but the next web can't be bothered. If the author of this article is reading - PLEASE CREDIT THE PHOTOGRAPHER
- madrona 14y agoTNW rips off more than just pictures.
- rjsamson 14y agoAgreed (although this article appears to contain some original reporting), but their neglect for proper image attribution is especially egregious. It is most bothersome to me because all they have to do is mention the guy's name and they get to use his image free of charge, but instead they resort to some sort of half-hidden generic link-back.
- mpanzarino 14y agoI've made a change to credit the image more prominently with the photographer's name. As a photographer myself, who does offer images under a CC license, I understand the importance of crediting. It was not my intention to slight them in any way. And you'll find that a good many of the articles that we publish contain original reporting. Thank you for reading.
- rjsamson 14y agoThanks Matthew - glad to see you're willing to make that change. I noticed a number of other TNW articles from today also using the same anonymous attribution, one of which was another of yours (http://thenextweb.com/apple/2012/06/05/apple-tv-5-0-2-software-update-released-for-2nd-gen-and-1080p-models/ http://thenextweb.com/apple/2012/06/05/apple-tv-5-0-2-softwa...). If you'd take a moment to fix the attribution and mention something to your colleagues as well that would be awesome. A couple of the other articles I noticed are here: http://thenextweb.com/insider/2012/06/06/bid-for-a-dinner-with-sean-parker-on-ebay-right-now-proceeds-go-to-cancer-research/ http://thenextweb.com/insider/2012/06/06/bid-for-a-dinner-wi... http://thenextweb.com/apps/2012/06/05/trickster-for-mac-helps-you-find-all-of-your-recently-used-apps-and-files/ http://thenextweb.com/apps/2012/06/05/trickster-for-mac-help... http://thenextweb.com/media/2012/06/05/tvs-status-quo-may-be-strong-but-technology-will-change-it-soon-whether-the-industry-is-ready-or-not/ http://thenextweb.com/media/2012/06/05/tvs-status-quo-may-be... http://thenextweb.com/apps/2012/06/05/here-are-the-winners-of-the-appsfire-app-star-awards-for-2012/ http://thenextweb.com/apps/2012/06/05/here-are-the-winners-o... Thanks!
- cletus 14y agoThis is only tangentially related but I really don't understand why anyone cares so highly about their contact list. Does it really matter? Why does it matter? Concerns about spam seem anachronistic (in that you have to deal with spam and services like Gmail have become pretty good at countering it). Is it just privacy? If so, I'm confused.
- MiguelHudnandez 14y agoPerhaps it is a trust issue. When I get someone's contact information, I expect to be consciously aware any time I give that information to someone else. "Would Alice want Bob to have her contact information? She gave it to me, but that doesn't give me the right to share it with others--it's hers." It seems like asking an assistant to go through your contacts to prepare for a meeting, and while he's at it, he copies them all to his computer so he can do a better job. A little creepy and maybe acceptable. At best it's not what you asked for.
- mark242 14y agoWhile this is not a direct violation of California law SB1386, it is not a long distance to be able to argue that the companies in question are acquiring unauthorized personal information. While we're not talking SSN, driver's license, etc etc., the definition of PII is only going to expand over time. Basically, if I don't have a personal contract with LinkedIn, it is extremely thin ice for them to be collecting my e-mail address just because I was invited to one of your meetings.
- gurkendoktor 14y agoOut of principle, an app must not collect what it doesn't need. If the programmer thinks nothing sensitive should be in there, it's still not ok. Unrelated example because you mention the contact list - people who put passwords in there as phone numbers. What really got to me though are notes. Notes! Of course no user should write "make that fat ass invest in us" in their appointment notes, but that is not how privacy works.
- gurkendoktor 14y ago
- Bjoern 14y agoWhy would they choose to transmit the data in plaintext rather than use SSL? Lazy?
- MehdiEG 14y agoPutting aside the issue that much of this data shouldn't have been sent anywhere in the first place, I'll never understand why, in 2012, SSL is still not used by default when sending any sensitive or private data across the network. It's even more puzzling when we're talking about background data upload when the potential SSL handshake latency isn't going to pose any UX issue. This has boggled my mind for years actually. Why?
- 0x0 14y agoMaybe it's not an issue for LinkedIn, but the iOS app submission process requires developers to do a lot of paperwork with several governments (US, France) for export compliance when using any kind of crypto. I can easily see smaller developers deciding to go for HTTP instead of HTTPS just to avoid dealing with all that bureaucracy.
- MehdiEG 14y agoI should go back and take a look at the exact wording of the Apple App Store rules but I never had problems submitting apps that use SSL. There's one step of the submission process that asks about the use of cryptography and I've always picked the option that doesn't require submitting any additional paperwork - never had problems. I forgot the exact wording but I always worked under the assumption that SSL isn't what Apple is talking about when they ask about the use of cryptography. If developers had to file paperwork with various governments just to use SSL in their app, then simply using one of the many third party APIs that require SSL (e.g. the Foursquare API) or even just embedding a web browser view that may end up loading an https URL would require the developer to go through the paperwork route to get their app approved. That wouldn't make sense.
- 0x0 14y agoYou would think so, but I've never been able to find a definitive answer, in public at least. Some forum posts seem to imply you should answer YES if you utilize HTTPS/SSL even if it's just through the iOS standard frameworks. Whether anyone _really_ cares remains to be seen. The vague wording is probably Apple's way to C.Y.A. should any problems arise later.
- malpern 14y agoWe've just posted a response about what we do and don't do. http://blog.linkedin.com/2012/06/06/mobile-calendar-feature/ http://blog.linkedin.com/2012/06/06/mobile-calendar-feature/ Important point, all data is shared of SSL.
- nodata 14y ago> Important point, all data is shared of SSL. What does that mean? Since comments are disabled on your blog, can you tell us which data was _not_ sent over SSL? (and if that has been fixed now)
- 89a 14y agoWhy would anyone be shocked at this? They already spam anyone unfortunate to be in the Address Book of someone who signs up for this awful service and connects with their gmail whatever.
- brudgers 14y agoWhat I find interesting is how Linkedin's approach to their mobile app was treated as technological savvy a month ago. http://venturebeat.com/2012/05/02/linkedin-ipad-app-engineering/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Venturebeat+%28VentureBeat%29#s:1-linkedin-ipad http://venturebeat.com/2012/05/02/linkedin-ipad-app-engineer... http://news.ycombinator.com/item?id=3920368 http://news.ycombinator.com/item?id=3920368
- gshakir 14y agoI am deeply disturbed by this. Now I know how the connection suggestions show up like they have a fancy algorithm.