Why I Just Closed My LinkedIn Account
ripton.net
ripton.net
I've received many recruiter contacts where the position being pitched does seem to logically connect with the experience and skills on my CV.
And then you receive recruiter contacts where it's obvious they're just machine-gunning in the dark, where the jobs being pitched have zero relation to your skills and experience.
There's also some pretty bad recruiter behavior where, if you reply to the initial contact, you've automatically signed up for a massive increase in the volume of communications they send you. I've even had one recruitment firm sign me up for their goddamn company mailing list just for replying to their initial contact.
There's plenty to dislike about tech recruiting. Targeted, sensible contacts are really just the tip of the ice berg.
We expect quality ratings when interacting on Ebay... shouldn't we get them on LinkedIn, which is just another type of peer-to-peer marketplace? They've created something similar with endorsements (for job seekers) but is there anything similar in terms of recruiters?
Alas the core issue in this blog post has nothing to do with the abundance of recruiter contact. Anyone with a Linkedin has already managed to figure out how to manage the difference between spam recruiters and the good guys.
Are you confusing recruiting for a job with someone that does body-shop contracting?
Actually, it's in the recruiter's best interest to maximize the return he gets over all his candidates. If he can place candidates three times as fast by offering them at 50% off their market rate, he makes a bigger total commission.
Edit: I'd also add what tech talent is going to be so unaware of their market value that they'd take 50% of it?
However, the other 90+% of contact I've received I can't appreciate. I've been involved with the CPython project for a while, and I'm on the Python Software Foundation's board. Seeing that sends some of the shotgun recruiters through the roof, trying to "network" with me by sending me bullshit jobs and asking me to share my local contacts. I used to get plenty of messages like, "hey I have this great Django job that you're a perfect fit for." How is this possible when I've never done more than read the Django tutorial, and nowhere on my profile does it mention Django or any other web frameworks? This is a waste of time.
Some skeevy recruiters use the "I already know this person" button when they don't, to avoid paying LinkedIn. Because they're breaking the rules of the site, I think it's correct to call them spammers.
The recruiters who contact without lying to do so aren't spammers, since that's indeed a large part of what the site is for, and you agree to such contact when you join. (And I believe you can turn off such contacts in the preferences, though I can't double-check since I just closed my account.)
I happen to agree, LinkedIn has a greater responsibility to its user base than maximizing conversion on its invite-a-friend feature.
Funny that more and more, email == gmail.
I guess there are a few of us around who still don't use it.
Recruiters have never once helped me out. In fact, one time a recruiter called me for a job I had quit the previous day! I regard recruiters lower than used car salesmen.
Call it sour grapes, but in hindsight it probably would have been a maddening place to work. Each section of the screen you see is built by a separate team with their own attendant functionality, so no matter what team you wind up working with, you're going to be faced with stupid decisions. I just deleted a list of UX problems, but I think we can all come up with our own.
NFW! This is a total pox on linkedin and explains why I've been getting so many requests over the past (forget how long) time period.
Linkedin is becoming the party that everyone is invited to that has no value for anybody.
Yes there is (a lot!) of job-hunting spam on LinkedIn, but when you need a job the spam can help. Even if you don't, it's useful to have a public place with an email address for professional contacts to find you, in case you switch firms.
https://developers.google.com/gmail/xoauth2_protocol
In practice, I don't know any other email provider who does this.
Being primarily a Gmail user I never realized that LinkedIn will ask for a password directly when it doesn't recognize a service associated with the domain.
The site appears to spend some time trying to do something with the bogus credentials I provided. Now I'm really curious what that something is.
I'm wondering if you might be overlooking the connection gains to bad wording in LinkedIn's part. "Give us your password, it's secure" is pretty dumb language if you tell me. My understanding is that they supply you with the ability to use 3rd party APIs to gather your email contacts from various sources. That is not really giving your password to them -per say-.
(Someone else noted that Gmail has a contacts API, so if you use Gmail then they can harvest your contacts without actually getting your password. Which is much better, though still kind of rude to your friends.)
The password leak from last year was really a leak of the password hashes. I'm pretty sure they didn't store passwords in plaintext.
I think the backlash was because they didn't salt the hashes and only used one iteration of SHA1 instead of a more appropriate hash function.
That being said, this doesn't really change the OP's point. Which was, "secure my ass"
But a lot of people really dislike the service and I completely support that choice of theirs, but so far I haven't seen a lot of discussion about the service the people wanted when they joined but didn't get. Is it 'view only' (as in I want to view other people but no one can view me!) or maybe (no contact) as in only my contacts can email me?
As the author points out, LinkedIn doesn't have a very good track record on security, plus giving out your email password isn't a very good practice in any situation. Unfortunately, because of LinkedIn's clout among professionals, many people are unwittingly putting their online identities at risk.
In the end, the author doesn't close his LinkedIn account because of recruiters, but rather as a protest against this bad practice.
I bet somebody got a really nice bonus for that feature. http://blogs.msdn.com/b/oldnewthing/archive/2006/11/01/92244...
Fair enough. He didn't enter his password, it isn't required to use the service. It is only useful for discovering more people via your contacts (and perhaps to spam them as you, that would be bad).
So they implement a feature poorly. Why the hate? The automatic climate control on my Subaru sucks dead gophers through a hose, but I don't translate the fact that Subaru let an crappy design get of an auxiliary feature get into production with "the car sucks, I'm selling it." Especially if my use of it doesn't require a lot of climate management (which it doesn't in California). I might think differently if the car wouldn't start unless the windows were up and the climate control engaged on automatic, that would cause me to sell it.
So I'm confused about the LinkedIn rant a bit.
Many people aren't. Phishing is a real problem.
When "legitimate" sites start doing slimy, insecure things like asking for third-party passwords, three things happen. One, those "legitimate" sites have the power to do things that most users don't really want them to, like spam their entire contact list as them. Two, it becomes harder for unsophisticated users to distinguish legitimate sites from phishing sites. Three, it means that if a criminal breaks into a "legitimate" site, there's more valuable information there for him to steal.
Does the author want to fix LinkedIn? Do they want a different service (or the same service done differently?) or a nearly the same service? It is easy to be dismissive of this form of rant, and sometimes that is actually the best response. But if there is something to learn here[1] that would be good too.
I suspect I'm overthinking it and the author was just venting.
[1] I get the 'here is another exemplar of stupid design' thought as well.
> They should know better than to put their marketing plans ahead of their users' security. They're not going to learn about security until it costs them users. So, scratch one user.
I think this is a reasonable justification, and I imagine the point was to get others to do the same.
when you read the news do you ask yourself: "what's the call to action of this article?"
Always.
Do I expect this to accomplish much? Not really. But I'm no longer part of the problem.
O_O
i would feel better if they go through the trouble mint does to store credentials:
http://www.quora.com/How-do-mint-com-and-similar-websites-av...
but i doubt they do
No, they would only need to have the plain text for the brief period when they're using your password to log in to your e-mail. So they could store it encrypted in their database and decrypt it when needed.
Especially when said social network has had major data breaches in the past. What could possibly go wrong?
Stupid whiners!
Might I add that LinkedIn has implemented the same stalker features that make it just as creepy as online dating websites...
Can you imagine if Facebook had a "who's been viewing your profile" page? It'd be gg.
Not to mention the NSA would be overloaded with 'suspicious activity'.
There is a 10 message / api-key / day limit using the linkedin messaging API I think http://developer.linkedin.com/documents/throttle-limits still annoying getting spammed.
LinkedIn seems like a prime example of what happens when you substitute good product design for a series of A/B tested micro-optimisations. The net effect is a shitty product that gets worse and worse...
If you will never need LinkedIn, that's fine. If you might, then you're only hurting yourself.
The point, I believe, is announcing the act in a public forum. Whether or not OP stops using LinkedIn is moot.
Breaking off the business relationship is another thing altogether - it hurts you much more than it hurts the monopoly provider, and it weakens your ability to influence.
It would be a harder choice if the business in question were providing a more valuable service. If I were a recruiter, or a freelancer who was constantly looking for jobs, then it would be harder to dump LinkedIn. I'd like to think I'd do it anyway on principle, though.
Let's take your post at heart, and we'll ignore the part about phishing (ironic, considering your own site's setup).
Your assertion is mostly paranoia, what could happen, and what LinkedIn shouldn't do. LinkedIn should not ask for your email password, despite that being a way to access email. Now, I'm not suggesting you hand over your email password without thought, but you do hand out your email password.
You hand out your email password to any email client you choose to use, with the hope that it doesn't share out that password to anyone else. After all, just as a LinkedIn employee could steal your password, so could a Google or Apple employee as well. I mean, Google even asks for the password to other email accounts if you want to use Gmail for non-Gmail accounts. And let's hope that no browser is tracking anything. It might be open source, but have you checked the source code?
Sounds crazy.
So leave LinkedIn. But really, it's a rant, and not even a good rant at that. And we didn't even talk about glass houses.
You don't intend to steal anything, but you could, making you just as guilty as LinkedIn. That is to say, not guilty of anything.
Your laziness is not our laziness, and your apathy is not our apathy.
I had to contact costumer support twice to remove two email addresses from their databases.
Fortunately mass emails or notifications without a single-click unsubscribe button are forbidden now.
Maybe they wouldn't have actually stored my password locally, but there's no way for a user to know that for sure.
But the answer to your question is "we have no idea."
Then what's the problem? That is certainly not phishing...
So use platform for what it's good for, but do not rely your business on it.
Gleb
It may or may not be a good idea, but it isn't phishing.
It may be phishing for a less nefarious cause, but how's the average enduser supposed to know the difference? We need to plant the meme that any site asking for another site's password is always wrong.
Note that I'm not saying it's a good practice, but you need to come up with another name for it than "phishing", because that one's already taken.
LinkedIn is a _great_ business development tool. Want to know the name of the person at company X who could use your product? LinkedIn is awesome for that.
But time and time again, the main thing one hears about LinkedIn is the (systemically encouraged) abuse of the system by spammy recruiters, not the ‘business networking’ it should be a haven for.
A significant move away from the traditional recruitment paradigm as a whole is the only thing that will make LinkedIn enjoyable to use. When traditional recruiters aren’t the best way to find talent, LinkedIn will be free to grow and prosper as a business networking community.
We’re trying to solve this problem at Mighty Spring (https://www.mightyspring.com). Whereas on LinkedIn your information is public and ripe for recruiter abuse, Mighty Spring profiles are only visible to the public in a cleansed, anonymous form. Behind the safe walls of our system, our users are free to indicate their career aspirations, explore new opportunities, and accept incoming interview requests (from first party companies only, not agency recruiters). Externally, the profiles are anonymous, so no one even knows you are a member of the community unless you choose to reveal your information specifically to them and accept an interview.
We’re in private beta now, but are already successfully connecting our users with great companies -- all at each user's discretion, of course! We’d love to help all of you solve your problems with LinkedIn, so we’ll live-monitor signups coming from Hacker News and expedite beta invites to all you guys. Definitely let us know if you have feedback or questions. My email is in my profile.
Would I write a blog post about it even if I did? No.
I'm not surprised that MySpace or Facebook does it, but those sites are so transparently bad that I never considered joining them, so it didn't affect me personally.