AfterDawn: Tech news

LinkedIn: Browser plugin does not hack our service

Written by James Delahunty @ 01 Apr 2014 6:03 User comments (1)

LinkedIn: Browser plugin does not hack our service LinkedIn has responded to reports about a browser plug-in that claimed to be able to hack e-mail addresses of any users.
The Sell Hack browser plug-in can be installed in Chrome, Safari or Firefox, and it adds a "Hack In" button to every LinkedIn profile that you visit. It claims that with just a click of this button, it can dump the e-mail address information associated with the profile.

Early reports suggested that the tool somehow compromises LinkedIn's system to dump the e-mail addresses. However, at closer look, the plug-in clearly does not work for every profile that you try, whereas it appears to work for profiles of well known individuals.

That led quickly to more skeptical-types assuming that the plug-in is using some other means to find information available elsewhere about a particular user.

According to LinkedIn's senior manager of corporate communications, Krista Canfield, no LinkedIn data has been compromised by the plug-in, and the e-mail addresses that are revealed are not done so through any breach, bug or vulnerability with the site.



LinkedIn warns users on the risks of the plug-in

On Monday, Canfield confirmed that the service had sent a cease and desist letter to address "several violations," and she warned against users installing the plugin.

"We advise LinkedIn members to protect themselves and to use caution before downloading any third-party extension or app," Canfield told Yahoo Tech, reports Alyssa Bereznak. "Often times, as with the SellHack case, extensions can upload your private LinkedIn information without your explicit consent."

That seems like reasonable advice for more than just this particular plug-in.

Sell Hack defends itself

The individuals behind Sell Hack describe themselves as "dads from the midwest", and object to being described as sneaky, nefarious, no good, or not "legitimate". They confirmed the cease and desist letter sent from LinkedIn, and that Sell Hack no longer works with LinkedIn.

"We only processed publicly visible data from LinkedIn based on your profile permissions...all of which has been deleted."

At the same time, it has been a mixed bag for them as they have had more signups today than the first 60 days of availability combined, and that they are working on a better product that complies with LinkedIn's terms of service.


Sources & Recommended Material:
Original report from Yahoo Tech: https://www.yahoo.com/tech/...
Response from Sell Hack: http://blog.sellhack.com/
Analysis by security analyst Graham Cluley: http://grahamcluley.com/2014/04/sellhack-linkedin/

Tags: LinkedIn
Previous Next  

1 user comment

12.4.2014 21:15

I HATE Linkedin!

It benefits recruiters only. They build a massive list of prospective job hunters off this crappy site.

I wish Linkedin died forever and was shutdown. I promise nobody would miss it!

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive