Skip to main content

Experts say LinkedIn’s new Intro app comes with huge security holes

how to use LinkedIn
Image used with permission by copyright holder

It’s only been a day since we first introduced you to LinkedIn’s new Intro app for the iPhone that gives emails a more professional edge – in a nutshell, all it does is provide Mail app users an extended introduction to a person sending them messages by showing their LinkedIn bio – but already, some security experts are calling shenanigans, claiming that the new product actually “hijacks” your email.

According to security consulting firm Bishop Fox, LinkedIn Intro actually reconfigures your device so that all your emails go through LinkedIn’s servers. “Once you install the Intro app, all of your emails, both sent and received, are transmitted via LinkedIn’s servers. LinkedIn is forcing all your IMAP and SMTP data through their own servers and then analyzing and scraping your emails for data pertaining to … whatever they feel like,” the company wrote on their blog.

The post went on to enumerate a list of reasons why installing Intro is a big mistake, some of them related to the possible repercussions of unwittingly surrendering the contents of your email to a third-party participant. If you use your work email on your phone, you may be unintentionally violating your company’s policy by using the plug-in; if you regularly correspond with people who usually offer confidentiality in correspondences – like your doctor, lawyer, or therapist – using the feature may relinquish certain legal privileges.

To address these security concerns, LinkedIn added an update to their blog post announcing the new service to ensure that people know at least two important things: That users have to opt into the service before any email encryption happens and that LinkedIn does not store any user emails on its servers.

intro
Image used with permission by copyright holder

Researchers were quick to refute LinkedIn’s claims, saying that “in order for LinkedIn to stick changes into an e-mail, they have to decrypt it and then encrypt it again en route to its recipient, adding a new layer of insecurity to e-mail in transit.”

Considering LinkedIn’s seemingly bad reputation when it comes to user data security – 6.5 million usernames and passwords were leaked to a Russian hacker website, and they suffered a major lawsuit because of it – this latest development does not bode well for the social career site. Unless LinkedIn offers a more acceptable and transparent explanation of how Intro works that security experts accept, it almost doesn’t seem worth it to enable the new feature – just go to LinkedIn if you really want to find out more about people on a professional capacity.

Jam Kotenko
Former Digital Trends Contributor
When she's not busy watching movies and TV shows or traveling to new places, Jam is probably on Facebook. Or Twitter. Or…
Bluesky barrels toward 1 million new sign-ups in a day
Bluesky social media app logo.

Social media app Bluesky has picked nearly a million new users just a day after exiting its invitation-only beta and opening to everyone.

In a post on its main rival -- X (formerly Twitter) -- Bluesky shared a chart showing a sudden boost in usage on the app, which can now be downloaded for free for iPhone and Android devices.

Read more
How to make a GIF from a YouTube video
woman sitting and using laptop

Sometimes, whether you're chatting with friends or posting on social media, words just aren't enough -- you need a GIF to fully convey your feelings. If there's a moment from a YouTube video that you want to snip into a GIF, the good news is that you don't need complex software to so it. There are now a bunch of ways to make a GIF from a YouTube video right in your browser.

If you want to use desktop software like Photoshop to make a GIF, then you'll need to download the YouTube video first before you can start making a GIF. However, if you don't want to go through that bother then there are several ways you can make a GIF right in your browser, without the need to download anything. That's ideal if you're working with a low-specced laptop or on a phone, as all the processing to make the GIF is done in the cloud rather than on your machine. With these options you can make quick and fun GIFs from YouTube videos in just a few minutes.
Use GIFs.com for great customization
Step 1: Find the YouTube video that you want to turn into a GIF (perhaps a NASA archive?) and copy its URL.

Read more
I paid Meta to ‘verify’ me — here’s what actually happened
An Instagram profile on an iPhone.

In the fall of 2023 I decided to do a little experiment in the height of the “blue check” hysteria. Twitter had shifted from verifying accounts based (more or less) on merit or importance and instead would let users pay for a blue checkmark. That obviously went (and still goes) badly. Meanwhile, Meta opened its own verification service earlier in the year, called Meta Verified.

Mostly aimed at “creators,” Meta Verified costs $15 a month and helps you “establish your account authenticity and help[s] your community know it’s the real us with a verified badge." It also gives you “proactive account protection” to help fight impersonation by (in part) requiring you to use two-factor authentication. You’ll also get direct account support “from a real person,” and exclusive features like stickers and stars.

Read more