Live data from Hacker News

LinkedIn password leak

usblog.kaspersky.com

41–50 of 218 posts

Re: LinkedIn password leak

#41

I got an email from them this morning about this, it just smells like all their other junkmail begging me to +1 their active users. Why don't they invalidate the passwords all at once instead of letting -- someone -- use the potentially compromised passwords again...

Users that may no longer have access to the email on that account would have a very difficult time regaining access. But overall definitely a better idea than letting a massive number of users get locked out by someone with the hacked credentials

Re: LinkedIn password leak

#42
post #28

Earlier quoted context omitted.

2009... Awesome. Linkedin should probably be the one warning me about this, but I never heard of this before. Edit: filtered as Spam, nevertheless they should have locked my account.

I received multiple emails this morning from LinkedIn advising me to change my password.

I received none.

Re: LinkedIn password leak

#43

Do we know how strong their hashing scheme was? Edit: SHA-1... You'd think a site as big as linkedin would have strong hashing...

Why would you think that? Linkedin isn't really known for substance or integrity are they? Also didn't it come to light that they didn't use salts either?

LinkedIn has a solid security team today. That was probably not the case when this breach apparently happened, though. Just because the dump leaked today has SHA-1 hashes, doesn't mean that's what they're doing now.

Re: LinkedIn password leak

#44
post #20

Earlier quoted context omitted.

The email did say why: "We've recently noticed a potential risk to your LinkedIn account coming from outside LinkedIn. Just to be safe, you'll need to reset your password the next time you log in."

Yeah, that's vague garbage. What it should have said was: "Our password database was stolen and we fucked when we tried to roll our own password hashing. Your password is likely compromised and you should change it. If you use the password on multiple websites, you should change it everywhere."

Even better, they have you click the "Forgot your password" link, as if it was your fault.

Re: LinkedIn password leak

#45
post #43

Earlier quoted context omitted.

Why would you think that? Linkedin isn't really known for substance or integrity are they? Also didn't it come to light that they didn't use salts either?

LinkedIn has a solid security team today. That was probably not the case when this breach apparently happened, though. Just because the dump leaked today has SHA-1 hashes, doesn't mean that's what they're doing now.

They should have never been doing that. And they regardless of what team they have, they have a terrible perception.

Re: LinkedIn password leak

#46

Do we know how strong their hashing scheme was? Edit: SHA-1... You'd think a site as big as linkedin would have strong hashing...

Why would you think that? Linkedin isn't really known for substance or integrity are they? Also didn't it come to light that they didn't use salts either?

If you look at Cory Scott's linked-in profile, you can see that there was NO security team before he was hired. None. The breach happened before he arrived, and he is now having to deal with a four year old breach. He has built a substantial team from nothing and from what I can tell is doing all the right things.

Re: LinkedIn password leak

#47
post #43

Earlier quoted context omitted.

LinkedIn has a solid security team today. That was probably not the case when this breach apparently happened, though. Just because the dump leaked today has SHA-1 hashes, doesn't mean that's what they're doing now.

They should have never been doing that. And they regardless of what team they have, they have a terrible perception.

I'm not invested in changing your opinion of LinkedIn. I'm not a fan either. I'm just clarifying that the team there now didn't have anything to do with what happened in (apparently) 2012, and I would not count on your assumptions of what they're doing with passwords as being valid anymore.

Re: LinkedIn password leak

#49

Who cares if their LinkedIn account gets hacked? In my case they'll be able to see 500+ recruitment agents I've never heard of as my 'contacts'.

I think password reuse is the big deal. Lots of people use the same passwords on more important accounts, which they would mind losing.

Re: LinkedIn password leak

#50
1: Change your password. RIGHT NOW. If you’re not sure how strong your password is, test sample passwords with our password checker here. Seriously?

Keep in mind that these estimates are based on some bogus entropy estimation. If a password hacking guy runs the correct dictionary past the hashes you password generates, it might be as small, well, as the first one tried. For example, run the passphrase Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn1 past the kaspersky bruteforce estimator, you get 10,000 centuries. But this is clearly false, as inicated in http://arstechnica.com/security/2013/08/thereisnofatebutwhat.... They clearly "cracked" this in far less time: "in a matter of minutes".

Post reply on HN