Can't any email sender spoof the sender identity in various ways, e.g., from name, signature, and sure this picture badge thing?
Can't any email sender spoof the sender identity in various ways, e.g., from name, signature, and sure this picture badge thing?
Anyway the point of the post is that if you just add the badge thing you will end up with two different badges, which the user would obviously find suspicious. Instead, the way LinkedIn rewrites messages is exploited to get only a single badge but manipulate its content (and/or the message content). Since the message looks authentic (it’s been filtered by LinkedIn) it gives the user a false sense of security, which makes a naïve phising attempt into a very effective one. After all the point of the message rewriting was to give the impression that LinkedIn Intro is an extension to the actual email client.