Why do the billion dollar companies just not get that people can see through double speak now. Let´s look at the double speak here, which intends to give a statement weight even though it has zero weight. On the left side original statement with zero weight, after the slash how the statement would have weight 1. We isolated Intro in a separate network segment and implemented a tight security perimeter across trust bo…
The Facts about LinkedIn Intro
41–50 of 63 posts
Re: The Facts about LinkedIn Intro
#42After the previous discussion, I kept wondering why I didn't trust LinkedIn with my email, but did trust Google. Google is actually much more terrifying in that they have more information about me than any other entity (Search, Gmail, Google Analytics, Chrome, GChat, etc.) Yet, I tend not to give it much thought. Some people are upset about LinkedIn spam - but that's never been a problem for me. I haven't figured out…
1) Google has a proven track record with email and email security (Gmail) over many years now
2) LinkedIn has a bad reputation for security
3) Most of the people I know who use LinkedIn probably wouldn't even have thought "how does this work". I don't like that any company can "get away with" something like this that could put so many peoples' jobs at risk. It feels shady and unfair.
Re: The Facts about LinkedIn Intro
#43"When the LinkedIn Security team was presented with the core design of Intro, we made sure we built the most secure implementation we believed possible." I think that is the problem. The security team should have said: "Stop. This is an insanely stupid idea. No matter how we implement it, let's just not do this." Instead they tried to make the best of it. I feel sorry for those folks. I bet in their heart they all kn…
Re: The Facts about LinkedIn Intro
#44After the previous discussion, I kept wondering why I didn't trust LinkedIn with my email, but did trust Google. Google is actually much more terrifying in that they have more information about me than any other entity (Search, Gmail, Google Analytics, Chrome, GChat, etc.) Yet, I tend not to give it much thought. Some people are upset about LinkedIn spam - but that's never been a problem for me. I haven't figured out…
For me there are a few reasons: 1) Google has a proven track record with email and email security (Gmail) over many years now 2) LinkedIn has a bad reputation for security 3) Most of the people I know who use LinkedIn probably wouldn't even have thought "how does this work". I don't like that any company can "get away with" something like this that could put so many peoples' jobs at risk. It feels shady and unfair.
Re: The Facts about LinkedIn Intro
#45Why do the billion dollar companies just not get that people can see through double speak now. Let´s look at the double speak here, which intends to give a statement weight even though it has zero weight. On the left side original statement with zero weight, after the slash how the statement would have weight 1. We isolated Intro in a separate network segment and implemented a tight security perimeter across trust bo…
Your proposed change to 4. is a statement that no one could ever honestly make.
Re: The Facts about LinkedIn Intro
#46The core idea behind this "service" of injecting LI info into any mail is broken. No security theater around it will change that.
LI should have worked with Apple to come up with a way to embed this kind of info natively into the mail app. And if that is not possible, add an email inbox to their LI app, so that the email header would be post-processed within the app. Make people use LI as their mail client (who knows, maybe someone would have liked this).
But injecting crap into the normal iOS mail app? What a strange approach.
Re: The Facts about LinkedIn Intro
#47That article misses the key point; a MITM proxy for mail is the actual problem, no matter how well implemented it is.
Re: The Facts about LinkedIn Intro
#48Re: The Facts about LinkedIn Intro
#49Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…
Your last point nails it. I can't help but think there are a good number of people now angling to build similar hacks in a much less rigorous fashion and then build entire companies around this hack. The next year is already, from my vantage point, lining up to be a year full of "give us OAuth access to your GMail account" products. This adds another vector for this type of product. In any case, users are not going t…
http://blog.learningbyshipping.com/2013/10/25/on-the-exploit...
Re: The Facts about LinkedIn Intro
#50The issue is that LinkedIn wants to provide mail services without saying it's your mail provider.
If you want to be a mail host, be a mail host. Don't half ass it by pretending you're offering a value added service to someone else's MX.
Convince me there's a reason to use your mail service. Show me there's a reason to trust you. I evaluate it and decide if I want to switch. This process works. It's proven. We expect things out of MXs.
No one knows how to evaluate an MX proxy on a consumer basis. There's no reason to change this. I don't care if you're LinkedIn or anyone else.
This smacks of shortcut taking. Don't trust them.