Earlier quoted context omitted.
For me there are a few reasons: 1) Google has a proven track record with email and email security (Gmail) over many years now 2) LinkedIn has a bad reputation for security 3) Most of the people I know who use LinkedIn probably wouldn't even have thought "how does this work". I don't like that any company can "get away with" something like this that could put so many peoples' jobs at risk. It feels shady and unfair.
Exactly. I have never heard of Google sending emails on my behalf through gmail without me knowing about it.
The Facts about LinkedIn Intro
61–63 of 63 posts
Re: The Facts about LinkedIn Intro
#62Re: The Facts about LinkedIn Intro
#63Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…
I'm not going to use Intro, but I have to ask, how is giving LinkedIn access to my email account any worse than giving access to Google, Yahoo, or Microsoft--by virtue of using their webmail?
Given the number of security disclosures -- oops, someone got our database full of passwords, but don't worry, they're MD5 hashed -- that have occurred over the last couple of years, I'd be extremely cautious of that practice.