Read a comment the other day wondering about what if two(or more) programs did this. Would you end up with a chain of proxies between you and the mail server? From the excellent Old New Thing blog: http://blogs.msdn.com/b/oldnewthing/archive/2005/06/07/42629...
Reminiscent of the insane 100-layered iframe issue with ad networks all jousting each other for the coveted impression when the page loads.
The Facts about LinkedIn Intro
31–40 of 63 posts
Re: The Facts about LinkedIn Intro
#32I think that is the problem. The security team should have said: "Stop. This is an insanely stupid idea. No matter how we implement it, let's just not do this."
Instead they tried to make the best of it.
I feel sorry for those folks. I bet in their heart they all know it is an utterly stupidly designed product that should never have seen the light of day.
Re: The Facts about LinkedIn Intro
#33Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…
Thanks, that was the thing I was most curious about: has LinkedIn really started taking security seriously and does it have any idea what it's doing? Because for those of us not following the ins and outs closely, going from "we don't salt our passwords" to "we want all of your email to pass through us" didn't just sound ill-advised; it sounded crazy.
Re: The Facts about LinkedIn Intro
#34Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…
> Cory also postdates LinkedIn's security drama; he was brought in after the credential leak Thanks, that was the thing I was most curious about: has LinkedIn really started taking security seriously and does it have any idea what it's doing? Because for those of us not following the ins and outs closely, going from "we don't salt our passwords" to "we want all of your email to pass through us" didn't just sound ill-…
Re: The Facts about LinkedIn Intro
#35Why not talk to Apple or Google and make this a reality in some other way? Surely it can't be hard for a company like LinkedIn, about as important as Facebook, to ask Apple or Google to provide some way of hooking into a third party application or well documented API? It might take longer and be a bit more complicated but it must be a better way to go about this than MITM.
Why should Apple/Google be gatekeepers (and potential sources of arbitrarily long delay, complication or strategic-veto)? What about the N other IMAP providers? Talking about a more generalized hook-in API is a good idea, but not in strict preference to proxying-tricks. Rather, it makes sense as a parallel or subsequent followup, after the value has been prototyped and proven.
Re: The Facts about LinkedIn Intro
#36Re: The Facts about LinkedIn Intro
#37Bishop Fox is a glorified gossip queen of a security company. What type of engineers, or so called hackers just make stupidly false claims without actually knowing what is going on behind the scenes. This is the software industry, not the Kim Kardashian, Honey Boo boo entertainment industry folks... Get the facts straight, or get a new job.
Why was your account created 30 minutes ago just to post two comments on this story?
Re: The Facts about LinkedIn Intro
#38I'd argue the best way to deliver this would be by working with mail providers not by subverting them. LinkedIn could open itself up and allow people to query names and profile information (probably would have to be opt-in) given an email address. A client would just send information an email address, and LinkedIn would hand back name and (public) profile information. If the client chooses to send their own email address, LinkedIn could send back a richer set of information including connections. The email client would then display the information in a way that it knows best.
The whole idea is so simple and straightforward that I cannot help but think LinkedIn's ultimate goal is not to just know who is sending emails to whom but also what they are saying. Cory Scott may know that the implementation is solid but I doubt he knows the motivations of his corporate overlords.
Perhaps LinkedIn should put a badge on all profiles of members who have opted in to the Intro service so I can cut all ties with them.
Re: The Facts about LinkedIn Intro
#39Earlier quoted context omitted.
Reminiscent of the insane 100-layered iframe issue with ad networks all jousting each other for the coveted impression when the page loads.
Sounds interestering, any more info about this