LinkedIn has had a rough week, not only were they caught transmitting sensitive calendar data in plain text to their servers from their iOS app, but a recent security breach has also left more than a few passwords exposed.
The optional calendar feature in the iOS app aims to match up attendees with their LinkedIn profiles. The problem is that to do so, the app transmits sensitive contact, time, place, and dial-in meeting details without any kind of hashing (although it is sent over SSL encryption). The worst part is that the guys who found the privacy breach say LinkedIn doesn't even need to do things this way in order to retain calendar sync functionality. LinkedIn has been fairly unapologetic about their implementation of the feature, claiming that unlike Path they don't store any of the meeting information on their servers. Still, they released an update yesterday that removed the transmission of meeting notes of calendar events.
As for the passwords, LinkedIn hasn't offered much information as to how or where the breach occurred, but they've automatically reset the password of affected users. LinkedIn has also pledged to add some extra security measures, such as hashing and salting their current password databases.
Considering their membership is predominantly business professionals, this security hooplah is definitely embarrassing and could cost LinkedIn some hard-to-regain credibility. It's unfortunate that Apple didn't catch LinkedIn's calendar gap through the App Store approval process, but the SSL tunnel might have hidden the lack of salting in SHA-1.
That said, how comfortable are you with the idea that other apps on your iPhone or iPad might be sending your data off somewhere in plain text after you've given them permission to access your calendar? What about contacts? Does iOS need a more granular permissions system? How would you feel if your friends were unwittingly sending off personal information about you to a server from their iPhone without your permission?
(Rene and the folks from Tech News Today discussed this on a podcast yesterday, check it out for more.)
We may earn a commission for purchases using our links. Learn more.
Elevate your Apple Watch with this elegant bracelet-style Wearlizer band
This pretty rhinestone-enhanced Apple Watch bangle bracelet looks more like jewelry on your wrist than a health and fitness band.
Ukraine's Foreign Minister alludes to resolution over Apple Maps and Crimea
Ukraine's Foreign Minister Vadym Prystaiko has hinted at a resolution to the Apple Maps Crimea controversy, after meeting with Apple VP Lisa Jackson at Davos.
macOS Catalina bug sees displays reset to max brightness after sleep
Some users are reporting their macOS Catalina machines are setting themselves to maximum brightness after waking from sleep
Don't lose important data on your Mac, make sure to back it up!
One of the most important things you should be doing with your Mac is backing up all of its data. Here are some of our favorite solutions for backing up your most important files, should anything ever happen.