Live data from Hacker News

The Facts about LinkedIn Intro

blog.linkedin.com

11–20 of 63 posts

Re: The Facts about LinkedIn Intro

#12
Why not talk to Apple or Google and make this a reality in some other way?

Surely it can't be hard for a company like LinkedIn, about as important as Facebook, to ask Apple or Google to provide some way of hooking into a third party application or well documented API?

It might take longer and be a bit more complicated but it must be a better way to go about this than MITM.

Re: The Facts about LinkedIn Intro

#13
Bishop Fox is a glorified gossip queen of a security company. What type of engineers, or so called hackers just make stupidly false claims without actually knowing what is going on behind the scenes. This is the software industry, not the Kim Kardashian, Honey Boo boo entertainment industry folks... Get the facts straight, or get a new job.

Re: The Facts about LinkedIn Intro

#14
After the previous discussion, I kept wondering why I didn't trust LinkedIn with my email, but did trust Google.

Google is actually much more terrifying in that they have more information about me than any other entity (Search, Gmail, Google Analytics, Chrome, GChat, etc.) Yet, I tend not to give it much thought.

Some people are upset about LinkedIn spam - but that's never been a problem for me. I haven't figured out a good answer to this yet.

Re: The Facts about LinkedIn Intro

#15
post #2

Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…

Your last point nails it. I can't help but think there are a good number of people now angling to build similar hacks in a much less rigorous fashion and then build entire companies around this hack. The next year is already, from my vantage point, lining up to be a year full of "give us OAuth access to your GMail account" products. This adds another vector for this type of product. In any case, users are not going to care about security and just tap "OK", so it's kind of scary that this train is really moving now. Imagine if Facebook (or the Next Facebook) required e-mail access and this was normalized.

I think it may have been a bit short-sighted for LinkedIn to post a developer-focused, "hey look at what we did" kind of post around Intro, regardless of how properly they implemented it behind the scenes.

Re: The Facts about LinkedIn Intro

#19
Why do the billion dollar companies just not get that people can see through double speak now.

Let´s look at the double speak here, which intends to give a statement weight even though it has zero weight. On the left side original statement with zero weight, after the slash how the statement would have weight

1. We isolated Intro in a separate network segment and implemented a tight security perimeter across trust boundaries./ Doesn't say anything at all again

2. REDUCED exposure to third-party monitoring services and tracking/PREVENT exposure to third-party monitoring services and tracking

3. We also had iSEC Partners, a well-respected security consultancy, perform a line-by-line code review of the credential handling and mail parsing/insertion code./ That statement isn't saying anything at all

4. make sure identified vulnerabilities WERE ADDRESSED/ make sure there are NO vulnerabilities

5. we make sure we NEVER persist the mail contents to our systems in an unencrypted form. And once the user has retrieved the mail, the encrypted content is DELETED from our systems./ These two words have weight.

6. MINIMIZE exposure/REMOVE exposure

7. We WORKED TO HELP ENSURE/ We ENSURE

Overall, Linked avoids using terminology that is actually a commitment except for 5. Fortunately, people picked up on double speak and Linkedin has managed to corrupt trust with its users further.

Somebody should fire the person that think sthis kind of "clarification" gets back their user's trust.

Re: The Facts about LinkedIn Intro

#20

Is linking to their privacy policy supposed to be comforting in some way? "We promise that the only thing we do with your data is what we said we do inside this huge legal document."

To be fair the document is well presented and much easier to read than most other privacy statements I've seen. The pledge of privacy is succinct too: https://intro.linkedin.com/micro/privacy

[deleted]
Post reply on HN