Live data from Hacker News

The Facts about LinkedIn Intro

blog.linkedin.com

41–50 of 63 posts

Re: The Facts about LinkedIn Intro

#41
post #19

Why do the billion dollar companies just not get that people can see through double speak now. Let´s look at the double speak here, which intends to give a statement weight even though it has zero weight. On the left side original statement with zero weight, after the slash how the statement would have weight 1. We isolated Intro in a separate network segment and implemented a tight security perimeter across trust bo…

Your proposed change to 4. is a statement that no one could ever honestly make.

Re: The Facts about LinkedIn Intro

#42

After the previous discussion, I kept wondering why I didn't trust LinkedIn with my email, but did trust Google. Google is actually much more terrifying in that they have more information about me than any other entity (Search, Gmail, Google Analytics, Chrome, GChat, etc.) Yet, I tend not to give it much thought. Some people are upset about LinkedIn spam - but that's never been a problem for me. I haven't figured out…

For me there are a few reasons:

1) Google has a proven track record with email and email security (Gmail) over many years now

2) LinkedIn has a bad reputation for security

3) Most of the people I know who use LinkedIn probably wouldn't even have thought "how does this work". I don't like that any company can "get away with" something like this that could put so many peoples' jobs at risk. It feels shady and unfair.

Re: The Facts about LinkedIn Intro

#43
post #32

"When the LinkedIn Security team was presented with the core design of Intro, we made sure we built the most secure implementation we believed possible." I think that is the problem. The security team should have said: "Stop. This is an insanely stupid idea. No matter how we implement it, let's just not do this." Instead they tried to make the best of it. I feel sorry for those folks. I bet in their heart they all kn…

Maybe they did, but they aren't going to tell us how the internal debate played out. That's not how it works. Security teams can make recommendations and can escalate to upper management if need be, but they don't make the final call on new products. Ultimately it's the CEO who decides whether a risk is worth taking.

Re: The Facts about LinkedIn Intro

#44
post #42

After the previous discussion, I kept wondering why I didn't trust LinkedIn with my email, but did trust Google. Google is actually much more terrifying in that they have more information about me than any other entity (Search, Gmail, Google Analytics, Chrome, GChat, etc.) Yet, I tend not to give it much thought. Some people are upset about LinkedIn spam - but that's never been a problem for me. I haven't figured out…

For me there are a few reasons: 1) Google has a proven track record with email and email security (Gmail) over many years now 2) LinkedIn has a bad reputation for security 3) Most of the people I know who use LinkedIn probably wouldn't even have thought "how does this work". I don't like that any company can "get away with" something like this that could put so many peoples' jobs at risk. It feels shady and unfair.

Exactly. I have never heard of Google sending emails on my behalf through gmail without me knowing about it.

Re: The Facts about LinkedIn Intro

#45
post #41
post #19

Why do the billion dollar companies just not get that people can see through double speak now. Let´s look at the double speak here, which intends to give a statement weight even though it has zero weight. On the left side original statement with zero weight, after the slash how the statement would have weight 1. We isolated Intro in a separate network segment and implemented a tight security perimeter across trust bo…

Your proposed change to 4. is a statement that no one could ever honestly make.

Correct, which makes "Intro" and all other third party apps, which reroute entire communication channels, untenable ones.

Re: The Facts about LinkedIn Intro

#46
By now this is a complete clusterfuck.

The core idea behind this "service" of injecting LI info into any mail is broken. No security theater around it will change that.

LI should have worked with Apple to come up with a way to embed this kind of info natively into the mail app. And if that is not possible, add an email inbox to their LI app, so that the email header would be post-processed within the app. Make people use LI as their mail client (who knows, maybe someone would have liked this).

But injecting crap into the normal iOS mail app? What a strange approach.

Re: The Facts about LinkedIn Intro

#48
After reading original announcement and this follow up post, and comments here. I find my self looking at it in a binary scenario - do they think they did a better job securing intro after the account breach - possibly, is the risk of letting one MORE entity (in addition to gmail with recent developments in mind) read thru your mails for marginal - at least for me - gain worth it? A solid NO.

Re: The Facts about LinkedIn Intro

#49
post #15
post #2

Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…

Your last point nails it. I can't help but think there are a good number of people now angling to build similar hacks in a much less rigorous fashion and then build entire companies around this hack. The next year is already, from my vantage point, lining up to be a year full of "give us OAuth access to your GMail account" products. This adds another vector for this type of product. In any case, users are not going t…

If Steve Sinofsky is to be believed, this is the natural order of things:

http://blog.learningbyshipping.com/2013/10/25/on-the-exploit...

Re: The Facts about LinkedIn Intro

#50
What worries me here is not trusting a third party with mail - we all already do that, this is the nature of SMTP.

The issue is that LinkedIn wants to provide mail services without saying it's your mail provider.

If you want to be a mail host, be a mail host. Don't half ass it by pretending you're offering a value added service to someone else's MX.

Convince me there's a reason to use your mail service. Show me there's a reason to trust you. I evaluate it and decide if I want to switch. This process works. It's proven. We expect things out of MXs.

No one knows how to evaluate an MX proxy on a consumer basis. There's no reason to change this. I don't care if you're LinkedIn or anyone else.

This smacks of shortcut taking. Don't trust them.

Post reply on HN