Live data from Hacker News

The Facts about LinkedIn Intro

blog.linkedin.com

51–60 of 63 posts

Re: The Facts about LinkedIn Intro

#51
post #2

Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…

maybe so, but Cory's post says (minus the bullshit):

All the claims are totally correct, but we tried super duper hard (though we sure as hell aren't going to put our money on the line if we're wrong) to make this secure. And if we don't keep this up, or if we do get hacked? Ain't our problem.

Re: The Facts about LinkedIn Intro

#52
post #47
post #3

That article misses the key point; a MITM proxy for mail is the actual problem, no matter how well implemented it is.

Isn't this the exact same approach taken by Mailboxapp, proxying your IMAP server?

Does this reduce the problem in any way?

Re: The Facts about LinkedIn Intro

#53
post #51
post #2

Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…

maybe so, but Cory's post says (minus the bullshit): All the claims are totally correct, but we tried super duper hard (though we sure as hell aren't going to put our money on the line if we're wrong) to make this secure. And if we don't keep this up, or if we do get hacked? Ain't our problem.

I don't see any bullshit in that post at all. What bullshit do you see? Maybe I can spot terms of art that you missed.

I also don't see him saying "ain't our problem" anywhere.

Re: The Facts about LinkedIn Intro

#54
post #32

"When the LinkedIn Security team was presented with the core design of Intro, we made sure we built the most secure implementation we believed possible." I think that is the problem. The security team should have said: "Stop. This is an insanely stupid idea. No matter how we implement it, let's just not do this." Instead they tried to make the best of it. I feel sorry for those folks. I bet in their heart they all kn…

This is the essence of application, or any security: the tension between features and security.

Re: The Facts about LinkedIn Intro

#55
post #47

Earlier quoted context omitted.

Isn't this the exact same approach taken by Mailboxapp, proxying your IMAP server?

Does this reduce the problem in any way?

The idea that this is a "problem" is subjective; if the value prop is compelling and there is sufficient trust established, someone should be free to use Mailboxapp OR Intro.

Re: The Facts about LinkedIn Intro

#56
post #32

"When the LinkedIn Security team was presented with the core design of Intro, we made sure we built the most secure implementation we believed possible." I think that is the problem. The security team should have said: "Stop. This is an insanely stupid idea. No matter how we implement it, let's just not do this." Instead they tried to make the best of it. I feel sorry for those folks. I bet in their heart they all kn…

Maybe they did, but they aren't going to tell us how the internal debate played out. That's not how it works. Security teams can make recommendations and can escalate to upper management if need be, but they don't make the final call on new products. Ultimately it's the CEO who decides whether a risk is worth taking.

[deleted]

Re: The Facts about LinkedIn Intro

#57
post #55

Earlier quoted context omitted.

Does this reduce the problem in any way?

The idea that this is a "problem" is subjective; if the value prop is compelling and there is sufficient trust established, someone should be free to use Mailboxapp OR Intro.

The problem doesn't ever go away - if you're using Mailboxapp, you're forever going to be vulnerable; you're free to use them and accept that risk, of course, but it's still a security problem with that service.

There is no such thing as 'sufficient trust estabilished' - trusting Mailboxapp right now doesn't in any way imply that it will be trustworthy enough for your needs (however large or small) after, say, a year. If you're using software X, for example, then you can think about renewing trust only when going to software X+1; but with such a service they can go from 'doing only good things' to 'intentially selling you out' at any arbitrary time.

For example, look at what's happening at Buffer. By using intro or Mailboxapp, you've just added another company whose decisions may screw you up, and that is a problem.

Re: The Facts about LinkedIn Intro

#58
post #53
post #51

Earlier quoted context omitted.

maybe so, but Cory's post says (minus the bullshit): All the claims are totally correct, but we tried super duper hard (though we sure as hell aren't going to put our money on the line if we're wrong) to make this secure. And if we don't keep this up, or if we do get hacked? Ain't our problem.

I don't see any bullshit in that post at all. What bullshit do you see? Maybe I can spot terms of art that you missed. I also don't see him saying "ain't our problem" anywhere.

>What bullshit do you see?

The biggest issue is the title: "The Facts about...".

Its apparent from the language that the only "facts" discussed are couched in non-falsifiable language, are in the past-tense, and self-referential.

___________

We made sure we built

We isolated

We performed

and we worked...to make sure

We made sure

we make sure we never persist

We worked to help ensure

____________

Although its not clear the author would have picked the language for the title himself (was likely PRs).

Re: The Facts about LinkedIn Intro

#59
post #53
post #51

Earlier quoted context omitted.

maybe so, but Cory's post says (minus the bullshit): All the claims are totally correct, but we tried super duper hard (though we sure as hell aren't going to put our money on the line if we're wrong) to make this secure. And if we don't keep this up, or if we do get hacked? Ain't our problem.

I don't see any bullshit in that post at all. What bullshit do you see? Maybe I can spot terms of art that you missed. I also don't see him saying "ain't our problem" anywhere.

Its a response that doesn't address most of the criticisms and attempts to deflect them into an argument about how supposedly secure their systems are instead of addressing the concerns about the system period.

And not only the post but the linked privacy policy consist entirely of weasel language. eg:

   Do you store my email or my password?
   LinkedIn servers will temporarily cache information in order to provide you 
   with the fastest service possible. Here are the full details:
   
   During installation, the servers temporarily cache your password in order to 
   add a new Mail account to your device. Your password is only cached for the 
   length of time it takes to install Intro, and never for more than 2 hours. 
   Typically, your password is cached for no more than 1 minute.
   During usage, the servers may temporarily cache your emails in order to make 
   emails download faster. When your device starts to download a mail folder, 
   such as your inbox, the servers will pre-emptively download and cache recent 
   messages in that folder. A few seconds later, when your device downloads the 
   individual messages, the servers will provide the cached messages. Your 
   messages are only cached until your device downloads them, and never for 
   more than 1 hour. Typically, your messages are cached for no more than a few 
   minutes.
   All cached information is held securely to industry standards. Each piece of 
   data is encrypted with a key that is unique to you and your device, and the 
   servers themselves are secured and monitored 24/7 to prevent any 
   unauthorized access.

where someone not an asshole would answer

"yes"

Re: The Facts about LinkedIn Intro

#60
post #2

Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…

I'm not going to use Intro, but I have to ask, how is giving LinkedIn access to my email account any worse than giving access to Google, Yahoo, or Microsoft--by virtue of using their webmail?
Post reply on HN