Live data from Hacker News

The Facts about LinkedIn Intro

blog.linkedin.com

61–63 of 63 posts

Re: The Facts about LinkedIn Intro

#61
post #44
post #42

Earlier quoted context omitted.

For me there are a few reasons: 1) Google has a proven track record with email and email security (Gmail) over many years now 2) LinkedIn has a bad reputation for security 3) Most of the people I know who use LinkedIn probably wouldn't even have thought "how does this work". I don't like that any company can "get away with" something like this that could put so many peoples' jobs at risk. It feels shady and unfair.

Exactly. I have never heard of Google sending emails on my behalf through gmail without me knowing about it.

Except to, uh, the NSA

Re: The Facts about LinkedIn Intro

#62
I hate the way LinkedIn handles criticism. Most of the discussion I've seen has centered on the concept, not the implementation. Instead of trying to allay concerns about the concept, LinkedIn spends the whole, defensive post chiding commentators for "inaccuracies and misperceptions" and proceeds to humblebrag about how thorough its security precautions were.

Re: The Facts about LinkedIn Intro

#63
post #2

Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know. Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part. (And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excel…

I'm not going to use Intro, but I have to ask, how is giving LinkedIn access to my email account any worse than giving access to Google, Yahoo, or Microsoft--by virtue of using their webmail?

A secret is kept secret by sharing it only with someone you trust, and with the smallest number of people possible. Ultimately, you have to share your credentials with your email provider, because they have to authenticate you in order to gain access to the information stored on their systems. Each additional party you share your credentials with increases your attack surface.

Given the number of security disclosures -- oops, someone got our database full of passwords, but don't worry, they're MD5 hashed -- that have occurred over the last couple of years, I'd be extremely cautious of that practice.

Post reply on HN