I'm assuming (and I may be completely wrong) that some kind of software monitors if the database of customer details is being downloaded. If a download is detected, an alert is issued. Does software like this exist? Or there other measure that guard against these data breaches?
LinkedIn password leak
21–30 of 218 posts
Re: LinkedIn password leak
#22Do we know how strong their hashing scheme was? Edit: SHA-1... You'd think a site as big as linkedin would have strong hashing...
Just read about it being sha-1 (source: http://www.pcworld.com/article/257045/security/6-5m-linkedin... ).
Edit: "Motherboard conversed with someone at LeakedSource who claimed that they managed to crack 90 percent of the LinkedIn passwords within three days. Though LinkedIn says it has hashed and salted its stored passwords for several years now"
http://venturebeat.com/2016/05/18/linkedin-resets-passwords-...
Re: LinkedIn password leak
#23> test sample passwords with our password checker here. Do NOT do that with your exact password though :)
Link: https://password.kaspersky.com/ I'm impressed by the password cracking estimation with the Tianhe-2 Supercomputer. A 10-character password containing uppercase letters, lowercase letters, and numbers, which is estimated at a 4 year crack with a Macbook Pro, takes 31 seconds on the supercomputer.
Is even the basic ratio/multiplier correct? Supercomputer is 1,000,000x faster than a 2012 MacBook Pro? I tried a few random strings and saw ratios as high as 3,000,000 - why would the ratio change based on the password? Probably because the number is nonsense.
Re: LinkedIn password leak
#24Earlier quoted context omitted.
Just read about it being sha-1 (source: http://www.pcworld.com/article/257045/security/6-5m-linkedin... ).
Sha-1 with the hashes salted. Edit: "Motherboard conversed with someone at LeakedSource who claimed that they managed to crack 90 percent of the LinkedIn passwords within three days. Though LinkedIn says it has hashed and salted its stored passwords for several years now" http://venturebeat.com/2016/05/18/linkedin-resets-passwords-...
Re: LinkedIn password leak
#25Re: LinkedIn password leak
#26Do we know how strong their hashing scheme was? Edit: SHA-1... You'd think a site as big as linkedin would have strong hashing...
Re: LinkedIn password leak
#27Why don't they invalidate the passwords all at once instead of letting -- someone -- use the potentially compromised passwords again...
Re: LinkedIn password leak
#28Woo, I created my LinkedIn profile in 2015, so I should be safe since the leak is supposedly from 2012. If anyone else isn't sure when they made their LinkedIn, you can see your join date here (ctrl+f "Member since"): https://www.linkedin.com/psettings/
Linkedin should probably be the one warning me about this, but I never heard of this before.
Edit: filtered as Spam, nevertheless they should have locked my account.
Re: LinkedIn password leak
#29Do we know how strong their hashing scheme was? Edit: SHA-1... You'd think a site as big as linkedin would have strong hashing...
Just read about it being sha-1 (source: http://www.pcworld.com/article/257045/security/6-5m-linkedin... ).
"What's also troubling security researchers is that the password database contains entirely unique passwords. It's unclear whether the people who leaked the password file have more passwords that have not surfaced online. The file may, for example, be an attempt to crowd source the hacking of some of the more difficult passwords."
Well Per Thorsheim called that one!
Re: LinkedIn password leak
#30Considering the amount of "growth hacking" LinkedIn use (used?) to so, sending too many emails to too many people this breach can be much more dangerous than usual. People raises eyebrows when they get phishing emails but when it comes purposely from LinkedIn and vouched for by your social and professional circle it could get much more credible and easy to fall.