Vulnerabilities / Threats
10/28/2013
11:38 AM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

LinkedIn Defends 'Intro' Email Security

LinkedIn responds to user and security expert concerns about new email feature, cites measures it took to make LinkedIn Intro safe.

LinkedIn: 10 Important Changesr
(click image for larger view and for slideshow)
LinkedIn: 10 Important Changes
LinkedIn's newest feature, called Intro, stirred up controversy last week when the professional social network introduced it -- and a few other features -- at an event about its mobile offerings. LinkedIn Intro is an opt-in service that lets you connect on a professional level with people you email every day.

"When people email you, we show you their LinkedIn profile: you can put faces to names, write more effective emails, and establish rapport," LinkedIn said in the announcement. "You can grow your professional network by connecting with them on LinkedIn."

But not everyone was as enthusiastic about it: Security experts were wary, especially in light of LinkedIn's breach last year, which compromised 6.5 million user passwords. To use Intro, users are required to route all emails through LinkedIn's "Intro" servers, which then scan them for certain types of content and temporarily store the passwords to users' external accounts. Security expert Graham Cluley said this sent a shiver down his spine.

[ Learn how to keep your job search private. Read 5 LinkedIn Privacy Settings For Job Hunters. ]

Over the weekend, LinkedIn responded to criticism in a blog post highlighting the measures it took to ensure Intro was safe and secure.

"When the LinkedIn Security team was presented with the core design of Intro, we made sure we built the most secure implementation we believed possible," said Cory Scott, senior manager of information security at LinkedIn. "We explored numerous threat models and constantly challenged each other to consider possible threat scenarios."

LinkedIn described the actions it took prior to Intro's launch. Among them:

-- Isolating Intro in a separate network segment and implementing a security perimeter across trust boundaries;

-- Performing hardening of the external- and internal-facing services and reducing exposure to third-party monitoring services and tracking;

-- Engaging iSEC Partners, a security consultancy, to perform a line-by-line code review of the credential handling and mail parsing/insertion code;

-- Penetration testing the final implementation by LinkedIn's internal team to ensure vulnerabilities were addressed; and

-- Ensuring it had the right monitoring in place to detect potential attacks, react quickly and minimize exposure.

LinkedIn clarified that all communications use SSL/TLS at each point of the email flow between a user's device, LinkedIn Intro and the third-party email system. "When mail flows through LinkedIn Intro, we make sure we never persist the mail contents to our systems in an unencrypted form," Scott said. "And once the user has retrieved the mail, the encrypted content is deleted from our systems."

Scott also addressed rampant concerns from iOS users. "It's important to note that we simply add an email account that communicates with Intro," he said. "The profile also sets up a certificate to communicate with the Intro web endpoint through a web shortcut on the device. We do not change the device's security profile in the manner described in a blog post that was authored by security firm Bishop Fox on Thursday."

LinkedIn's Scott said he and LinkedIn welcome "healthy skepticism and speculation," but LinkedIn felt it was necessary to clarify its practices and correct the misperceptions.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
David F. Carr
50%
50%
David F. Carr,
User Rank: Apprentice
10/29/2013 | 3:13:40 AM
re: LinkedIn Defends 'Intro' Email Security
By nature, social computing leans toward sharing and openness. People join LinkedIn to build their circle of connections not to live the most private life possible.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4774
Published: 2015-05-25
Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 allows remote attackers to hijack the authentication of arbitrary users via vectors involving a FRAME element.

CVE-2014-4778
Published: 2015-05-25
IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.

CVE-2014-6190
Published: 2015-05-25
The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document.

CVE-2014-6192
Published: 2015-05-25
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix10, 6.0.5 before 6.0.5.6, and 6.0.5.5a before 6.0.5.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-8146
Published: 2015-05-25
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (hea...

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.