Live data from Hacker News

The Facts about LinkedIn Intro

blog.linkedin.com

1–10 of 63 posts

Re: The Facts about LinkedIn Intro

#2
Cory Scott was a director at Matasano, ran our west coast office, and is as trustworthy an appsec person as I know.

Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part.

(And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excellent).

I would tend to believe anything he says about this or any other LinkedIn system he's worked on.

That said, I would still under no circumstances give LinkedIn access to my mail spool, or any other third party.

I'm also a little queasy about the idea of "norming" these kinds of systems. Look at how much work LinkedIn put into securing Intro, and ask whether any startup will have the means to do the same. I doubt it.

Re: The Facts about LinkedIn Intro

#7

Is linking to their privacy policy supposed to be comforting in some way? "We promise that the only thing we do with your data is what we said we do inside this huge legal document."

To be fair the document is well presented and much easier to read than most other privacy statements I've seen. The pledge of privacy is succinct too: https://intro.linkedin.com/micro/privacy

Re: The Facts about LinkedIn Intro

#10
post #3

That article misses the key point; a MITM proxy for mail is the actual problem, no matter how well implemented it is.

Agreed. The third party to defend against is not only an intruder to LinkedIn, but LinkedIn itself.

If there are "misperceptions" about Intro, let us include LinkedIn's own misperception of how some of us view account security.

Post reply on HN