I got an email from them this morning about this, it just smells like all their other junkmail begging me to +1 their active users. Why don't they invalidate the passwords all at once instead of letting -- someone -- use the potentially compromised passwords again...
LinkedIn password leak
41–50 of 218 posts
Re: LinkedIn password leak
#42Earlier quoted context omitted.
2009... Awesome. Linkedin should probably be the one warning me about this, but I never heard of this before. Edit: filtered as Spam, nevertheless they should have locked my account.
I received multiple emails this morning from LinkedIn advising me to change my password.
Re: LinkedIn password leak
#43Do we know how strong their hashing scheme was? Edit: SHA-1... You'd think a site as big as linkedin would have strong hashing...
Why would you think that? Linkedin isn't really known for substance or integrity are they? Also didn't it come to light that they didn't use salts either?
Re: LinkedIn password leak
#44Earlier quoted context omitted.
The email did say why: "We've recently noticed a potential risk to your LinkedIn account coming from outside LinkedIn. Just to be safe, you'll need to reset your password the next time you log in."
Yeah, that's vague garbage. What it should have said was: "Our password database was stolen and we fucked when we tried to roll our own password hashing. Your password is likely compromised and you should change it. If you use the password on multiple websites, you should change it everywhere."
Re: LinkedIn password leak
#45Earlier quoted context omitted.
Why would you think that? Linkedin isn't really known for substance or integrity are they? Also didn't it come to light that they didn't use salts either?
LinkedIn has a solid security team today. That was probably not the case when this breach apparently happened, though. Just because the dump leaked today has SHA-1 hashes, doesn't mean that's what they're doing now.
Re: LinkedIn password leak
#46Do we know how strong their hashing scheme was? Edit: SHA-1... You'd think a site as big as linkedin would have strong hashing...
Why would you think that? Linkedin isn't really known for substance or integrity are they? Also didn't it come to light that they didn't use salts either?
Re: LinkedIn password leak
#47Earlier quoted context omitted.
LinkedIn has a solid security team today. That was probably not the case when this breach apparently happened, though. Just because the dump leaked today has SHA-1 hashes, doesn't mean that's what they're doing now.
They should have never been doing that. And they regardless of what team they have, they have a terrible perception.
Re: LinkedIn password leak
#48Re: LinkedIn password leak
#49Who cares if their LinkedIn account gets hacked? In my case they'll be able to see 500+ recruitment agents I've never heard of as my 'contacts'.
Re: LinkedIn password leak
#50Keep in mind that these estimates are based on some bogus entropy estimation. If a password hacking guy runs the correct dictionary past the hashes you password generates, it might be as small, well, as the first one tried. For example, run the passphrase Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn1 past the kaspersky bruteforce estimator, you get 10,000 centuries. But this is clearly false, as inicated in http://arstechnica.com/security/2013/08/thereisnofatebutwhat.... They clearly "cracked" this in far less time: "in a matter of minutes".