The Facts about LinkedIn Intro
11–20 of 63 posts
Re: The Facts about LinkedIn Intro
#12Surely it can't be hard for a company like LinkedIn, about as important as Facebook, to ask Apple or Google to provide some way of hooking into a third party application or well documented API?
It might take longer and be a bit more complicated but it must be a better way to go about this than MITM.
Re: The Facts about LinkedIn Intro
#13Re: The Facts about LinkedIn Intro
#14Google is actually much more terrifying in that they have more information about me than any other entity (Search, Gmail, Google Analytics, Chrome, GChat, etc.) Yet, I tend not to give it much thought.
Some people are upset about LinkedIn spam - but that's never been a problem for me. I haven't figured out a good answer to this yet.
Re: The Facts about LinkedIn Intro
#15Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…
I think it may have been a bit short-sighted for LinkedIn to post a developer-focused, "hey look at what we did" kind of post around Intro, regardless of how properly they implemented it behind the scenes.
Re: The Facts about LinkedIn Intro
#16"Error establishing a database connection"
Can't even keep a website up and running, what a very tech savvy company.
Re: The Facts about LinkedIn Intro
#17Re: The Facts about LinkedIn Intro
#18That article misses the key point; a MITM proxy for mail is the actual problem, no matter how well implemented it is.
Re: The Facts about LinkedIn Intro
#19Let´s look at the double speak here, which intends to give a statement weight even though it has zero weight. On the left side original statement with zero weight, after the slash how the statement would have weight
1. We isolated Intro in a separate network segment and implemented a tight security perimeter across trust boundaries./ Doesn't say anything at all again
2. REDUCED exposure to third-party monitoring services and tracking/PREVENT exposure to third-party monitoring services and tracking
3. We also had iSEC Partners, a well-respected security consultancy, perform a line-by-line code review of the credential handling and mail parsing/insertion code./ That statement isn't saying anything at all
4. make sure identified vulnerabilities WERE ADDRESSED/ make sure there are NO vulnerabilities
5. we make sure we NEVER persist the mail contents to our systems in an unencrypted form. And once the user has retrieved the mail, the encrypted content is DELETED from our systems./ These two words have weight.
6. MINIMIZE exposure/REMOVE exposure
7. We WORKED TO HELP ENSURE/ We ENSURE
Overall, Linked avoids using terminology that is actually a commitment except for 5. Fortunately, people picked up on double speak and Linkedin has managed to corrupt trust with its users further.
Somebody should fire the person that think sthis kind of "clarification" gets back their user's trust.
Re: The Facts about LinkedIn Intro
#20Is linking to their privacy policy supposed to be comforting in some way? "We promise that the only thing we do with your data is what we said we do inside this huge legal document."
To be fair the document is well presented and much easier to read than most other privacy statements I've seen. The pledge of privacy is succinct too: https://intro.linkedin.com/micro/privacy