LinkedIn's new mobile app called 'A dream for attackers'

Advertisement
By Nicole Perlroth, The New York Times | Updated: 25 October 2013 10:04 IST
Security researchers are calling LinkedIn's new mobile app, Intro, a dream come true for hackers or intelligence agencies.

"I'm flabbergasted by this," Richard Bejtlich, the chief research officer at the computer security company Mandiant, said in an interview Wednesday. "I can't believe someone thought this was a good idea."

Intro is an email plug-in for iOS users that pulls LinkedIn profile information into emails so that the sender's job title appears front-and-center in emails on a user's iPhone or iPad.

Some bloggers have hailed it as a smart play by LinkedIn to get more mobile action and to get users to stop thinking of the service as a static website they visit every couple of years to update their employment status.

Advertisement

But security researchers have taken issue with the way the app works. Intro redirects email traffic to and from users' iPhones and iPads through LinkedIn's servers, then analyzes and scrapes those emails for relevant data and adds pertinent LinkedIn details.

Advertisement

Researchers liken that redirection to a "man-in-the-middle attack" in which hackers, or more recently, intelligence agencies, intercept Internet traffic en route to its destination and do what they will with it.

Iranian hackers used that tactic to intercept dissidents' Gmail accounts in 2011, by hacking into DigiNotar, a Dutch certificate authority. The National Security Agency is accused of using such tactics to snoop on Google traffic, according to recent revelations by Edward Snowden.

Advertisement

Security researchers say LinkedIn essentially does the same thing in the name of a new mobile feature.

"'But that sounds like a man-in-the-middle attack!' I hear you cry," Bishop Fox, a security consulting group, wrote in a blog post. "Yes. Yes it does. Because it is. That's exactly what it is. And this is a bad thing. If your employees are checking their company email, it's an especially bad thing."

Advertisement

LinkedIn has responded to some of those concerns in an amended blog post Thursday. The company notes that customers must opt in to the app and that, once they do, their email is encrypted to and from LinkedIn's servers. The company also notes that LinkedIn does not store any email on its servers.

But researchers note that, in order for LinkedIn to stick changes into an email, they must decrypt it and then encrypt it again en route to its recipient, adding a new layer of insecurity to email in transit.

"I worry LinkedIn is not going to treat this as the holy grail for people's email, even though it is," Bejtlich said. "The risk is that you essentially trust a box, run by LinkedIn, with your email. It's a target for someone that wants to get to your email. All the fears people now have about email - that they will be intercepted by intelligence agencies for instance - are present."

LinkedIn has not had the best security profile. After the service was hacked last year, 6 million user passwords popped up on a Russian message board, revealing that the company used only bare basic security protocols. And last month, the company became the target of a class-action suit by users who said it was improperly accessing their data.

Bishop Fox, the security consulting firm, called the app "a dream for attackers" and enumerated specific concerns in a blog post. Among them: By giving LinkedIn access to their emails, users may be waiving their rights to attorney-client privilege. The consultancy also warned users that, by opting into Intro, they may be "in gross violation" of their employer's security policies.

"I don't think people who use this are seriously thinking about the implications of LinkedIn seeing and changing their email," Bejtlich noted. "These changes are done in the name of a feature, or speed, but it just completely breaks the idea that email traffic is going where it should go and no place else."

© 2013, The New York Times News Service

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Internet, LinkedIn, apps
Advertisement

Related Stories

Popular Mobile Brands
  1. Top 5 Tech Gadgets to Decorate Your Home This Diwali
  2. The Conjuring: Last Rites Is Now Streaming Online: Know Where to Watch the Horror Movie
  1. Ryugu Samples Reveal Ancient Water Flow on Asteroid for a Billion Years
  2. Scientists Create Most Detailed Radio Map of Early Universe Using MWA
  3. Mayor of Kingstown Season 4 OTT Release: Know When, Where to Watch Jeremy Renner's Crime Drama
  4. Our Fault Is Streaming Now: Know All About This Gabriel Guevara and Nicole Wallace Starrer
  5. The Conjuring: Last Rites Is Now Streaming Online: Know Where to Watch the Latest Installment from the Horror Franchise
  6. Delhi Crime Season 3 OTT Release: Know When to Watch This Shefali Shah Thriller Series
  7. Vast Space to Launch Haven-1, the World’s First Private Space Station in 2026
  8. Atmospheric Carbon Dioxide Soars to 424PPM, Marking Biggest Yearly Jump Ever
  9. Black Hole Tears Star Apart, Sends Out Powerful Flares Six Months Later
  10. Shakthi Thirumagan OTT Release: When, Where to Watch Vijay Antony-Starrer Action Thriller Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.