6 ms·
Why I Just Closed My LinkedIn Account
Do not ask for your users's email passwords. It's phishing, pure and simple.
- carlob 13y agoWhy I never had LinkedIn. Back in the good old days the only way to prevent it from spamming you on behalf of your friends was creating an account and then unsubscribing from emails. I had to contact costumer support twice to remove two email addresses from their databases. Fortunately mass emails or notifications without a single-click unsubscribe button are forbidden now.
- mathattack 13y agoDon't most social media sites ask for permission to upload your contacts from elsewhere? The answer (as Nancy Reagan taught us) is to Just Say No. Yes there is (a lot!) of job-hunting spam on LinkedIn, but when you need a job the spam can help. Even if you don't, it's useful to have a public place with an email address for professional contacts to find you, in case you switch firms.
- betenoire 13y agoYes most sites do ask for permission to upload your contacts, but they do it without needing your password. No need to log in as the user anymore to do this. https://developers.google.com/google-apps/contacts/v3/ https://developers.google.com/google-apps/contacts/v3/
- dripton 13y agoNot everyone uses Gmail.
- tomkarlo 13y agoAre the similar token-based schemes for non-Gmail services? Seems like OpenID or the like could provide similar functionality to avoid having to provide your actual password to other services so they can look at your inbox.
- pjscott 13y agoGMail allows you to give OAuth access to your email in an admirably simple way that anybody could adopt: https://developers.google.com/gmail/xoauth2_protocol https://developers.google.com/gmail/xoauth2_protocol In practice, I don't know any other email provider who does this.
- iheart2code 13y agoIf you've used this particular contact system before, you'll know that your e-mail login information won't pass through LinkedIn's servers. A popup from your e-mail provider's server asks you to grant LinkedIn access to your contacts via that provider's APIs.
- dripton 13y agoLinkedIn showed my email address on their web page, and provided a box under it to type my email password. Maybe they wouldn't have actually stored my password locally, but there's no way for a user to know that for sure.
- iheart2code 13y agoAh, I use GMail, which allows that the type of functionality I mentioned. I didn't see that it behaves differently with other providers.
- deleted 13y ago[deleted]
- draq 13y agoFacebook also asks for permission to import your email contacts from other providers. For GMX, Skype, mail.ru and "other email service", you need to provide a password. It really depends on whether the target site implemented OAuth, OpenID or etc.
- ValentineC 13y agoHow does Linkedin store the email password? Plaintext since they can't send hashes across?
- sejje 13y agoThey hopefully don't store it. If they do, hopefully it would be in a reversible hash. But the answer to your question is "we have no idea."
- auctiontheory 13y agoIt's really not practical to stop doing business with every large company with whom you have a disagreement, especially when they are the dominant player in their industry. I'm sure most of us could find a nit to pick with both Apple and Microsoft, not to mention Google. If you will never need LinkedIn, that's fine. If you might, then you're only hurting yourself.
- jemka 13y ago>If you will never need LinkedIn, that's fine. If you might, then you're only hurting yourself. The point, I believe, is announcing the act in a public forum. Whether or not OP stops using LinkedIn is moot.
- dripton 13y agoThat's a pretty defeatist attitude. If nobody complains when companies do bad things, what incentive do they have to stop?
- auctiontheory 13y agoComplaining is one thing - do it, by all means. Breaking off the business relationship is another thing altogether - it hurts you much more than it hurts the monopoly provider, and it weakens your ability to influence.
- dripton 13y agoHonestly, LinkedIn wasn't providing me much utility anyway. Recruiter spam plus the occasional question from an ex-cow-orker who could find me with a Google search anyway. It would be a harder choice if the business in question were providing a more valuable service. If I were a recruiter, or a freelancer who was constantly looking for jobs, then it would be harder to dump LinkedIn. I'd like to think I'd do it anyway on principle, though.
- jabits 13y agoIf you use it, and a few in your network use it too, it can be very useful, both to find opportunities and to see who might be available. Most people change jobs every few years, and this is just another data point used to stay informed. If you are a "lifer" somewhere, it is of no use. The level of spam I receive does not seem excessive. The service is free.
- gexla 13y agoInterestingly, I have received lots of great contacts and work through various sites I use, but never anything through LinkedIn. Different communities gravitate to different channels. For me, I wouldn't miss my LinkedIn account. Though maybe I'm just not trying hard enough.
- codva 13y agoLinkedIn has a new service where they offer to centralize your contact management by importing all your contacts from wherever and giving you one central place to keep track of them. It may or may not be a good idea, but it isn't phishing.
- dripton 13y agoAsking for my email password is phishing, period. It may be phishing for a less nefarious cause, but how's the average enduser supposed to know the difference? We need to plant the meme that any site asking for another site's password is always wrong.
- rglullis 13y agoCancel your Facebook account. They do the same to "find your friends"
- adrr 13y agoCancel all your social network accounts. Everyone does it. They say they don't store email addresses, technically true but they store a hash of it. They use this data to recommend friends/connections. It can also be used to recommend friends/connections when a new user signups during the signup flow.
- dripton 13y ago
- ianstallings 13y agoOh good, another "why I'm taking my ball and going home" article.
- Finster 13y agoI know, right? I mean, complaining about a major social network straight up asking for your email account password is just so WHINY! Especially when said social network has had major data breaches in the past. What could possibly go wrong? Stupid whiners!
- ianstallings 13y agoSo why not just send them an email instead of posting a blog post with a link-bait title like "Why I'm leaving X" and then posting it yourself to HN? Am I supposed to help with this cause? Is there a petition? Should I leave linked in immediately because there is a box that you can voluntarily put your password into? Well I guess I'll just add it to the list of "things I need to be outraged about today".
- HNJohnC 13y agoBecause the author is trying to effect change and that is much easier with a little publicity.
- ianstallings 13y agoI didn't see any mention of actually contacting linked in. Maybe he should start with them.
- chrisbennet 13y agoI'm sure they know that what they are doing is slimey. Asking them to change won't have any effect. Hitting them in the wallet is the only influence he has.
- l0c0b0x 13y agoI don't love LinkedIn, but there really isn't any other platform where to keep professional contacts at the moment (at the same level or close). I get their spam from time to time (join groups, free pro-membership for a month) but not a lot of recruiters, which is great.. and I have a lot of professional contacts. I'm wondering if you might be overlooking the connection gains to bad wording in LinkedIn's part. "Give us your password, it's secure" is pretty dumb language if you tell me. My understanding is that they supply you with the ability to use 3rd party APIs to gather your email contacts from various sources. That is not really giving your password to them -per say-.
- dripton 13y agoNo, there was a password input box. Definitely giving them my password per se. (Someone else noted that Gmail has a contacts API, so if you use Gmail then they can harvest your contacts without actually getting your password. Which is much better, though still kind of rude to your friends.)
- Pxtl 13y agoLinkedIn is everything I would expect from a social network created by and for enterprise software business types. I don't know anybody who actually likes LinkedIn other than recruiters.
- adnam 13y agoI don't understand why people complain about being contacted by recruiters on LinkedIn. It's your public CV and professional contacts; recruiting is what LinkedIn was designed for!
- pietro 13y agoDon't get it, either. What's your CV doing out there, anyway, if you're not trying to be found?
- ry_d 13y agoThe post has nothing to do with public exposure. It has everything to do with identity security via third party integrations.
- dougbarrett 13y agoExactly! I get multiple e-mails a week from recruiters on LinkedIn, and it's not hard at all for me to just kindly decline their offer or ignore it all together. I've never understood the stigma against recruiters, and why you would get mad at someone that wanted to try to place you at a job, that just sounds backwards and unappreciative.
- potatolicious 13y agoI think the frustration doesn't come from recruiters per se, but rather the shotgun-approach recruiters. I've received many recruiter contacts where the position being pitched does seem to logically connect with the experience and skills on my CV. And then you receive recruiter contacts where it's obvious they're just machine-gunning in the dark, where the jobs being pitched have zero relation to your skills and experience. There's also some pretty bad recruiter behavior where, if you reply to the initial contact, you've automatically signed up for a massive increase in the volume of communications they send you. I've even had one recruitment firm sign me up for their goddamn company mailing list just for replying to their initial contact. There's plenty to dislike about tech recruiting. Targeted, sensible contacts are really just the tip of the ice berg.
- edgesrazor 13y agoMy biggest annoyance with LinkedIn is the Endorsement feature. I have people I barely know endorsing me for skills I barely have. Right now my highest endorsement total is for PostgreSQL. While I'm proficient with Postgres, there's other skills I know way better that only have 1 or 2 endorsements. If a recruiter were to contact me (I'm not looking), I'm assuming it would be for db work. It would be a waste of both their time (to contact me) and mine (to respond and apologize that some of my contacts don't understand my job).
- eli_gottlieb 13y agoLinkedIn seems far more sensible once you realize it's a honeypot.
- incision 13y agoInteresting. Being primarily a Gmail user I never realized that LinkedIn will ask for a password directly when it doesn't recognize a service associated with the domain. The site appears to spend some time trying to do something with the bogus credentials I provided. Now I'm really curious what that something is.
- nwh 13y agoI assume it attempts to hit the server with IMAP with the details you provided, then scavenge email addresses from your sent email.
- incision 13y agoRight, that's certainly logical, but if they are doing something like that, particularly considering their big breach last year - wow.
- 8ig8 13y agoIt would be interesting to provide them access to a fake email account and monitor activity.
- richkuo 13y agoGood reasoning here. Might I add that LinkedIn has implemented the same stalker features that make it just as creepy as online dating websites... Can you imagine if Facebook had a "who's been viewing your profile" page? It'd be gg. Not to mention the NSA would be overloaded with 'suspicious activity'.
- scragg 13y agoI was about to post the same thing. I can't believe they get away with having this feature. If I click a Linkedin link on Google, oops I'm logged in, my viewing history is for sale.
- Finster 13y agoWait. In order for this to work, wouldn't they HAVE to store your email password in plain text? O_O
- mariusz331 13y agomhmm. i would feel better if they go through the trouble mint does to store credentials: http://www.quora.com/How-do-mint-com-and-similar-websites-avoid-storing-passwords-in-plain-text http://www.quora.com/How-do-mint-com-and-similar-websites-av... but i doubt they do
- r00fus 13y agoDoes it actually store the password? Perhaps it simply passes it on to the IMAP or CardDAV request to get your contacts?
- miahi 13y agoWho would discard this kind of precious info?
- greenyoda 13y ago"wouldn't they HAVE to store your email password in plain text?" No, they would only need to have the plain text for the brief period when they're using your password to log in to your e-mail. So they could store it encrypted in their database and decrypt it when needed.
- samweinberg 13y agoCan anyone confirm LinkedIn actually sent this email? I mean, straight out asking for your customers' email password is pretty ridiculous.
- dripton 13y agoLinkedIn sent me an email saying I had a new contact. When I clicked the link in the email, it put me on the LinkedIn site. As an afterthought on the "we added your new connection" page, they tried to phish my email password.
- samweinberg 13y agoIt's a shame that a company with an already bad track record in user security would do something so careless yet again.
- just2n 13y agoYes. And on their website they have pop-ups to nag you to do it constantly.
- tlongren 13y agoCongrats man. LinkedIn isn't all that useful to anyone but recruiters anyway. I closed mine long ago because I simply never used it.
- smaili 13y agoYup, same here.
- ChuckMcM 13y agoSigh, so LinkedIn is trying to boost their numbers and you didn't fall for it. Good on you! Why the hate? If you want to get a ton of unsolicited links to connect just put 'VP' in your title. Amazing. I've only got two policies on LinkedIn, one I only link to people I actually know and have worked with already, and two I don't allow { recruiters | sourcers | HR } types to link to me after having a bad experience of one of them trolling all my contacts with "Hey I'm working with Chuck and would like information about what you're up to ..." emails. But a lot of people really dislike the service and I completely support that choice of theirs, but so far I haven't seen a lot of discussion about the service the people wanted when they joined but didn't get. Is it 'view only' (as in I want to view other people but no one can view me!) or maybe (no contact) as in only my contacts can email me?
- rpedroso 13y agoThe complaint wasn't about marketing tactics, or about LinkedIn's quality of service. The complaint was specifically about LinkedIn asking for the passwords to their users' email accounts. As the author points out, LinkedIn doesn't have a very good track record on security, plus giving out your email password isn't a very good practice in any situation. Unfortunately, because of LinkedIn's clout among professionals, many people are unwittingly putting their online identities at risk. In the end, the author doesn't close his LinkedIn account because of recruiters, but rather as a protest against this bad practice.
- danielweber 13y agoI still have to do a double-take when LinkedIn asks me to "login" with my email address and password. I'm already logged in; they mean my email provider's password. I bet somebody got a really nice bonus for that feature. http://blogs.msdn.com/b/oldnewthing/archive/2006/11/01/922449.aspx http://blogs.msdn.com/b/oldnewthing/archive/2006/11/01/92244...
- ChuckMcM 13y ago"The complaint was specifically about LinkedIn asking for the passwords to their users' email accounts." Fair enough. He didn't enter his password, it isn't required to use the service. It is only useful for discovering more people via your contacts (and perhaps to spam them as you, that would be bad). So they implement a feature poorly. Why the hate? The automatic climate control on my Subaru sucks dead gophers through a hose, but I don't translate the fact that Subaru let an crappy design get of an auxiliary feature get into production with "the car sucks, I'm selling it." Especially if my use of it doesn't require a lot of climate management (which it doesn't in California). I might think differently if the car wouldn't start unless the windows were up and the climate control engaged on automatic, that would cause me to sell it. So I'm confused about the LinkedIn rant a bit.
- lumens 13y agoThe main problem with LinkedIn, especially for the HN crowd, is that it’s essentially just go-go-gadget arm for recruiters, who themselves represent a very broken system (http://bit.ly/14gMFnB http://bit.ly/14gMFnB). Modern recruiting is a horrible mess (http://bit.ly/11Jnnez http://bit.ly/11Jnnez), so a social network that encourages and magnifies their actions is of course going to produce pretty terrible results. LinkedIn is a _great_ business development tool. Want to know the name of the person at company X who could use your product? LinkedIn is awesome for that. But time and time again, the main thing one hears about LinkedIn is the (systemically encouraged) abuse of the system by spammy recruiters, not the ‘business networking’ it should be a haven for. A significant move away from the traditional recruitment paradigm as a whole is the only thing that will make LinkedIn enjoyable to use. When traditional recruiters aren’t the best way to find talent, LinkedIn will be free to grow and prosper as a business networking community. We’re trying to solve this problem at Mighty Spring (https://www.mightyspring.com https://www.mightyspring.com). Whereas on LinkedIn your information is public and ripe for recruiter abuse, Mighty Spring profiles are only visible to the public in a cleansed, anonymous form. Behind the safe walls of our system, our users are free to indicate their career aspirations, explore new opportunities, and accept incoming interview requests (from first party companies only, not agency recruiters). Externally, the profiles are anonymous, so no one even knows you are a member of the community unless you choose to reveal your information specifically to them and accept an interview. We’re in private beta now, but are already successfully connecting our users with great companies -- all at each user's discretion, of course! We’d love to help all of you solve your problems with LinkedIn, so we’ll live-monitor signups coming from Hacker News and expedite beta invites to all you guys. Definitely let us know if you have feedback or questions. My email is in my profile.
- MrDOS 13y agoWow, offering to log into an account that holds contact information in order to retrieve those contacts and automatically invite them to connect with you. I'm glad the innovation will both start and stop here – it's a good thing MySpace never did this. Or Facebook. Or any one of a million other services. I'm not trying to detract from the potential severity of anyone actually going ahead and doing it, but OP, is this seriously the first time you've seen something like this? I'm very surprised.
- xauronx 13y agoI think the issue was with it actually asking for the password itself. If it were an OAuth screen he probably wouldn't have blinked. Would I have shaken my head and even MAYBE deleted my account if I were having a bad day? Maybe. Would I write a blog post about it even if I did? No.
- dripton 13y agoI've seen it once before. Udacity did it to me a few years ago when I signed up for a course, and I closed that account too. I'm not surprised that MySpace or Facebook does it, but those sites are so transparently bad that I never considered joining them, so it didn't affect me personally.
- kevjiang 13y ago>> LinkedIn leaked 8 million users' passwords less than a year ago, because they were storing them in the database in plain text. The password leak from last year was really a leak of the password hashes. I'm pretty sure they didn't store passwords in plaintext. I think the backlash was because they didn't salt the hashes and only used one iteration of SHA1 instead of a more appropriate hash function. That being said, this doesn't really change the OP's point. Which was, "secure my ass"
- dripton 13y agoI apologize for the error and have edited the post.
- mrt0mat0 13y agoI don't know if anyone noticed this, but LinkedIn didn't store their passwords in plain text. they were stored in SHA1, with no salt, which is as close to plain text as you can get without being plain text, but there is a difference :)
- dripton 13y agoI apologize for the error and have edited the post.
- gesman 13y agoAll platforms are like hookers - they are generally offering some in-demand service, you might get a nasty bug, you get what you paid for (or not paid for) and they are not obligated to please you. So use platform for what it's good for, but do not rely your business on it. Gleb
- xauronx 13y agoI allowed it to connect to my gmail, hit the uncheck all (for inviting friends) and checked one person. It ended up sending invites to a few hundred people I had only had vague communications with. Apparently "uncheck all" only means for the 10 they're currently showing you. A lot of awkward "do I know you?"'s
- jhandl 13y agoHow long ago was that?
- rhizome 13y agoPossibly orthogonal to this, but in the context of this site I am much less impressed by LinkedIn having interviewed there about six months ago. Though I thought I did pretty well, I didn't get an offer, but having learned the level of detail and expertise they were asking about and requiring of successful candidates, I can now balance that against what I see on the screen and intuit how bad their project designs are. Call it sour grapes, but in hindsight it probably would have been a maddening place to work. Each section of the screen you see is built by a separate team with their own attendant functionality, so no matter what team you wind up working with, you're going to be faced with stupid decisions. I just deleted a list of UX problems, but I think we can all come up with our own.
- deleted 13y ago[deleted]
- 13y ago
- diminoten 13y agoCan't you do what LinkedIn does with your contacts through some kind of Google universal auth API? Why does LinkedIn actually need my freaking password to view my contacts?
- malanj 13y agoI'm very impressed that you actually managed to close your account. Every time I've tried to do that I was sent into some bizarre redirect hell that seemed downright malicious. LinkedIn seems like a prime example of what happens when you substitute good product design for a series of A/B tested micro-optimisations. The net effect is a shitty product that gets worse and worse...
- dripton 13y agoI think I managed to close it. I had to click 4 or 5 times, but the process didn't seem to generate any errors. We'll see.
- jdbernard 13y agoThe only things I supply to LinkedIn are things I would put on a resume and send to strangers. It is a useful service if you can be disciplined about what you share.
- jmcrozzy 13y agoI haven't seen the "Enter password box" and I have a hard time imagining why it would exist. Why would they choose to deal with logging into your email, scraping for email addresses(spawning parallel processes etc), risk blacklisting and (more)user hatred (not to mention trying to prove to google you're not a robot)when there is a perfectly good OAuth(2) protocol/spec that along with good google apis to retrieve this data securely (well: http://hueniverse.com/2012/07/oauth-2-0-and-the-road-to-hell/ http://hueniverse.com/2012/07/oauth-2-0-and-the-road-to-hell...). I agree its still cheap and tacky but not really nefarious. There is a 10 message / api-key / day limit using the linkedin messaging API I think http://developer.linkedin.com/documents/throttle-limits http://developer.linkedin.com/documents/throttle-limits still annoying getting spammed.
- thedufer 13y agoI believe this password box is something you only see if they don't recognize your email address as something that they can interact with via OAuth (i.e. Gmail).
- deleted 13y ago[deleted]