Live data from Hacker News

The Facts about LinkedIn Intro

blog.linkedin.com

31–40 of 63 posts

Re: The Facts about LinkedIn Intro

#31
post #21
post #9

Read a comment the other day wondering about what if two(or more) programs did this. Would you end up with a chain of proxies between you and the mail server? From the excellent Old New Thing blog: http://blogs.msdn.com/b/oldnewthing/archive/2005/06/07/42629...

Reminiscent of the insane 100-layered iframe issue with ad networks all jousting each other for the coveted impression when the page loads.

Sounds interestering, any more info about this

Re: The Facts about LinkedIn Intro

#32
"When the LinkedIn Security team was presented with the core design of Intro, we made sure we built the most secure implementation we believed possible."

I think that is the problem. The security team should have said: "Stop. This is an insanely stupid idea. No matter how we implement it, let's just not do this."

Instead they tried to make the best of it.

I feel sorry for those folks. I bet in their heart they all know it is an utterly stupidly designed product that should never have seen the light of day.

Re: The Facts about LinkedIn Intro

#33
post #2

Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…

> Cory also postdates LinkedIn's security drama; he was brought in after the credential leak

Thanks, that was the thing I was most curious about: has LinkedIn really started taking security seriously and does it have any idea what it's doing? Because for those of us not following the ins and outs closely, going from "we don't salt our passwords" to "we want all of your email to pass through us" didn't just sound ill-advised; it sounded crazy.

Re: The Facts about LinkedIn Intro

#34
post #2

Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…

> Cory also postdates LinkedIn's security drama; he was brought in after the credential leak Thanks, that was the thing I was most curious about: has LinkedIn really started taking security seriously and does it have any idea what it's doing? Because for those of us not following the ins and outs closely, going from "we don't salt our passwords" to "we want all of your email to pass through us" didn't just sound ill-…

I have no professional relationship with LinkedIn and all signs I can see point to them taking security as seriously as any other Large West Coast Tech Company --- which, if you're wondering, is actually a pretty high bar compared to the Fortune 1000.

Re: The Facts about LinkedIn Intro

#35
post #22
post #12

Why not talk to Apple or Google and make this a reality in some other way? Surely it can't be hard for a company like LinkedIn, about as important as Facebook, to ask Apple or Google to provide some way of hooking into a third party application or well documented API? It might take longer and be a bit more complicated but it must be a better way to go about this than MITM.

Why should Apple/Google be gatekeepers (and potential sources of arbitrarily long delay, complication or strategic-veto)? What about the N other IMAP providers? Talking about a more generalized hook-in API is a good idea, but not in strict preference to proxying-tricks. Rather, it makes sense as a parallel or subsequent followup, after the value has been prototyped and proven.

call me cynical, but I bet it was discussed, and overruled on the point that this system allows them get access to all your juicy email under the pretence that "we can't do it any other way"

Re: The Facts about LinkedIn Intro

#36
An advantageous move for LinkedIn might be to just launch it's own email service and compete with Gmail. So many add-ons and hacks exist to add LinkedIn capabilities to existing email, it might be worth it on their part to do it the Right Way.

Re: The Facts about LinkedIn Intro

#37

Bishop Fox is a glorified gossip queen of a security company. What type of engineers, or so called hackers just make stupidly false claims without actually knowing what is going on behind the scenes. This is the software industry, not the Kim Kardashian, Honey Boo boo entertainment industry folks... Get the facts straight, or get a new job.

Their blog post said as much; that LinkedIn gave very little background about what's going on behind the scenes. This post doesn't actually address much.

Why was your account created 30 minutes ago just to post two comments on this story?

Re: The Facts about LinkedIn Intro

#38
Let's take a step back at what value LinkedIn Intro is supposed to give to me. What would be a better way to deliver this value?

I'd argue the best way to deliver this would be by working with mail providers not by subverting them. LinkedIn could open itself up and allow people to query names and profile information (probably would have to be opt-in) given an email address. A client would just send information an email address, and LinkedIn would hand back name and (public) profile information. If the client chooses to send their own email address, LinkedIn could send back a richer set of information including connections. The email client would then display the information in a way that it knows best.

The whole idea is so simple and straightforward that I cannot help but think LinkedIn's ultimate goal is not to just know who is sending emails to whom but also what they are saying. Cory Scott may know that the implementation is solid but I doubt he knows the motivations of his corporate overlords.

Perhaps LinkedIn should put a badge on all profiles of members who have opted in to the Intro service so I can cut all ties with them.

Re: The Facts about LinkedIn Intro

#39
post #31
post #21

Earlier quoted context omitted.

Reminiscent of the insane 100-layered iframe issue with ad networks all jousting each other for the coveted impression when the page loads.

Sounds interestering, any more info about this

I'm exaggerating of course but if you go onto most popular websites and really dig into their ads you'll see that you basically hop through a large number of layers of various ad exchanges before you get to the actual server that serves the ad. Usually via a series of nested iframes.
Post reply on HN