How LINE's engineering team tackles security

LINE security is open with their improvement efforts, reports Tech in Asia

Bs_logoFounder and CEO Paytm Vijay Shekhar Sharma. Photo: Dalip Kumar
Founder and CEO Paytm Vijay Shekhar Sharma. Photo: Dalip Kumar
Annie Teh
Last Updated : Nov 23 2016 | 4:10 PM IST
Instant messaging apps are an attractive target for malicious attacks. Understandably so — much of our lives are poured into our conversations with others, including our whereabouts, private information, and photographs.

One such app is LINE. Fresh off the IPO boat, the subsidiary of the Naver Corporation boasts 220 million users. 

To support the many new features that LINE has introduced since their IPO, LINE has expended significant resources to construct a scalable architecture that not only supports these features but protects the information transacted each day.

Meet LEGY

At the heart of LINE’s architecture is the Line Event-delivery GatewaY (or LEGY), a custom-built API gateway server that ensures that everyone can use LINE no matter the device or platform.
 
It was created to support the application-layer protocol SPDY (pronounced speedy) used by the app to safely and efficiently transport messages between users.

End-to-end encryption

E2EE ensures that neither potential eavesdroppers nor LINE can decode (or decrypt) an encrypted conversation.
 
Messaging uses dedicated, per-user static ECDH keys; in contrast, voice calls are encrypted by ephemeral ECDH keys, which are generated only when a call begins and discarded once the call ends.
 
Risk Assessment for games
 
Anyone familiar with game production will understand how treacherous game hackers can be. That’s why part of a platform’s security measures exist to assess risk from hacks. Though not exactly a security risk, gamers often worm their way past an app’s mechanics to manipulate the game. 

Crowdsourcing security
 
How LINE's engineering team tackles security
What makes LINE’s security exciting to watch is that they’re very open with their improvement efforts; it’s outlined clearly in their engineers’ blog posts and their encryption white paper.
 
As the open-source community has shown, the culture of learning from each other’s experiences and progression goes a long way to improving your abilities and products. 

This is an excerpt from Tech in Asia. You can read the full article here

Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Access to Exclusive Premium Stories

  • Over 30 subscriber-only stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Nov 23 2016 | 4:10 PM IST