Skip to content

Comment on What LinkedIn Could Learn From OKCupid and Others

Comments

Something Linkedin ought to be taken to task for (Which they continue to get away with) -- phishing:

Linkedin will show you a login-like screen with your email address pre-populated and a password prompt. Two dangerous things can happen: 1) a user can absent-mindedly assume they're at their email login page and type in their email password (less likely) 2) a user can absent-mindedly assume that this is the Linkedin login page and type in their Linkedin password.

The problem with (1) (and 2 if your email password is the same as your linkedin password) is that you've just given Linkedin access to your email contact list. Then Linkedin can shoot an email to all your contacts letting them know you're on Linkedin / etc.

To me this is a form of phishing that countless less-tech-savvy folks are getting caught up in and should not be OKAY in the industry.

I'm almost certain LinkedIn doesn't try to use your username/password you use for the site to access your email. Triggering millions of password failures on gmail/yahoo/etc. is not something that they would risk.

During signup, if you are on one of the major webmail services, it will explicitly ask you to authorize yourself on them so it can get your contacts however.

Having worked there and specifically as product manager for the Who Viewed My Profile portion, I can tell you that they take privacy very seriously.

No it explicitly asks if you'd like Linkedin to search your email contacts by filling out the email address and password fields below. It pre-populates the email address from your linkedin email login address. Thus without reading what the fields are for, it's very easy to assume you've simply been logged out of Linkedin and need to re-log-in. Upon doing so Linkedin will try one time to login to your email (Gmail and other web email clients do this too -- to grab contacts from older email accounts but they don't use this phishing-style approach). If your email password happens to be your Linkedin password, Linkedin will have access to your email contacts without you realizing it. And more embarrassing: Linkedin may send an email to your contacts mentioning you (they used to do this, maybe not as much anymore). Don't you remember getting all those Linkedin invite emails from your 'friends'? how do you think those got sent? Do you really think your friends intentionally typed in your email address so Linkedin could spam you?

That's not what the OP said. Linkedin presents a form on the front page after you're logged in that specifically asks you to enter your password so that you can search your e-mail contacts.

But many people might interpret that as a LinkedIn log-in form (not realizing that they are already logged in). If LinkedIn just had an ad there asking people to click a button to then fill out their e-mail address/password, they would likely have much fewer people let LinkedIn look at their e-mail account.

This is much more legit than just trying the Linkedin account username/password to access the e-mail account, but it is still a form of phishing.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.