The Facts about LinkedIn Intro
blog.linkedin.com
The Facts about LinkedIn Intro
1–10 of 63 posts
Re: The Facts about LinkedIn Intro
#2Cory also postdates LinkedIn's security drama; he was brought in after the credential leak, which was a good call on LinkedIn's part and sort of a brave move on Cory's part.
(And, full disclosure: iSEC is one of Matasano's sister companies; take this for whatever its worth, but their reputation is excellent).
I would tend to believe anything he says about this or any other LinkedIn system he's worked on.
That said, I would still under no circumstances give LinkedIn access to my mail spool, or any other third party.
I'm also a little queasy about the idea of "norming" these kinds of systems. Look at how much work LinkedIn put into securing Intro, and ask whether any startup will have the means to do the same. I doubt it.
Re: The Facts about LinkedIn Intro
#3Re: The Facts about LinkedIn Intro
#4"We promise that the only thing we do with your data is what we said we do inside this huge legal document."
Re: The Facts about LinkedIn Intro
#5Re: The Facts about LinkedIn Intro
#6Re: The Facts about LinkedIn Intro
#7Is linking to their privacy policy supposed to be comforting in some way? "We promise that the only thing we do with your data is what we said we do inside this huge legal document."
Re: The Facts about LinkedIn Intro
#8Re: The Facts about LinkedIn Intro
#9From the excellent Old New Thing blog: http://blogs.msdn.com/b/oldnewthing/archive/2005/06/07/42629...
Re: The Facts about LinkedIn Intro
#10That article misses the key point; a MITM proxy for mail is the actual problem, no matter how well implemented it is.
If there are "misperceptions" about Intro, let us include LinkedIn's own misperception of how some of us view account security.