30 ms·
If you've used this particular contact system before, you'll know that your e-mail login information won't pass through LinkedIn's servers. A popup from your e-
by iheart2code 13y ago
If you've used this particular contact system before, you'll know that your e-mail login information won't pass through LinkedIn's servers. A popup from your e-mail provider's server asks you to grant LinkedIn access to your contacts via that provider's APIs.
- dripton 13y agoLinkedIn showed my email address on their web page, and provided a box under it to type my email password. Maybe they wouldn't have actually stored my password locally, but there's no way for a user to know that for sure.
- iheart2code 13y agoAh, I use GMail, which allows that the type of functionality I mentioned. I didn't see that it behaves differently with other providers.
- deleted 13y ago[deleted]
- draq 13y agoFacebook also asks for permission to import your email contacts from other providers. For GMX, Skype, mail.ru and "other email service", you need to provide a password. It really depends on whether the target site implemented OAuth, OpenID or etc.
- ValentineC 13y agoHow does Linkedin store the email password? Plaintext since they can't send hashes across?
- sejje 13y agoThey hopefully don't store it. If they do, hopefully it would be in a reversible hash. But the answer to your question is "we have no idea."
- diminoten 13y agoSo they do use Google's API to do this, and not a direct password authentication. Then what's the problem? That is certainly not phishing...
- dripton 13y agoNot everyone uses Gmail. The fallback is to ask for your email password. Really.