Live data from Hacker News

LinkedIn password leak

usblog.kaspersky.com

51–60 of 218 posts

Re: LinkedIn password leak

#51

I got an email from them this morning about this, it just smells like all their other junkmail begging me to +1 their active users. Why don't they invalidate the passwords all at once instead of letting -- someone -- use the potentially compromised passwords again...

Users that may no longer have access to the email on that account would have a very difficult time regaining access. But overall definitely a better idea than letting a massive number of users get locked out by someone with the hacked credentials

Then what good is sending out the warning via email?

Re: LinkedIn password leak

#53
post #51

Earlier quoted context omitted.

Users that may no longer have access to the email on that account would have a very difficult time regaining access. But overall definitely a better idea than letting a massive number of users get locked out by someone with the hacked credentials

Then what good is sending out the warning via email?

Because the people who do have access to their email are warned.

Re: LinkedIn password leak

#54
post #10
post #7

Earlier quoted context omitted.

Linkedins support site URLs (hosted by custhelp.com) used to look something like this http://linkedin.custhelp.com/cgi-bin/*linkedin.cfg*/php/endu... I know custhelp used to be particularly insecure right around when this hack happened, as I myself discovered several vulnerabilities back then. >Also, when you say '"confusion"', do you mean it was feigned? Partly. From what I recall it took them quite a while to own u…

Ah...I assumed that a leak happening via third-party would be an excuse for a company to be legit confused at first and then breathe a sigh of relief because that means they can blame someone else in the press release. Though I guess that's tricky when people start asking about why their data is being given in bulk to a third party in the first place...

Doesn't matter. If your logo is on the product, it's your fault. Full stop.

Re: LinkedIn password leak

#55

Who cares if their LinkedIn account gets hacked? In my case they'll be able to see 500+ recruitment agents I've never heard of as my 'contacts'.

I think password reuse is the big deal. Lots of people use the same passwords on more important accounts, which they would mind losing.

I know of a company that experienced a data breach (one that was reported in the news) due to an employee using the same password on linkedin as on their company account.

Re: LinkedIn password leak

#56
post #55

Earlier quoted context omitted.

I think password reuse is the big deal. Lots of people use the same passwords on more important accounts, which they would mind losing.

I know of a company that experienced a data breach (one that was reported in the news) due to an employee using the same password on linkedin as on their company account.

Was linkedin verified to be the source of the password or is this just speculation?

Re: LinkedIn password leak

#57
post #50

1: Change your password. RIGHT NOW. If you’re not sure how strong your password is, test sample passwords with our password checker here. Seriously? Keep in mind that these estimates are based on some bogus entropy estimation. If a password hacking guy runs the correct dictionary past the hashes you password generates, it might be as small, well, as the first one tried. For example, run the passphrase Ph'nglui mglw'n…

As an aside, it can be so difficult to get this across to folks who aren't in the infosec headspace. I've seen even technical, computer science types absolutely not get that their ad-hoc memorable password "but no one would EVER guess that!" schemes are probably much more vulnerable than they estimate. Nevermind, even, true computing laypersons.

Re: LinkedIn password leak

#58

I got an email from them this morning about this, it just smells like all their other junkmail begging me to +1 their active users. Why don't they invalidate the passwords all at once instead of letting -- someone -- use the potentially compromised passwords again...

Incredible... The email says:

"We've recently noticed a potential risk to your LinkedIn account coming from outside LinkedIn."

That's almost as bad as saying "we take security very seriously" after a hack!

Re: LinkedIn password leak

#59
post #18

> test sample passwords with our password checker here. Do NOT do that with your exact password though :)

Link: https://password.kaspersky.com/ I'm impressed by the password cracking estimation with the Tianhe-2 Supercomputer. A 10-character password containing uppercase letters, lowercase letters, and numbers, which is estimated at a 4 year crack with a Macbook Pro, takes 31 seconds on the supercomputer.

Damn, my desktop is a total of 80000000000/3000000=26666.6666667 times faster than the Tianhe-2 supercomputer!

More realistically though, Kaspersky just really sucks at password cracking.

Re: LinkedIn password leak

#60
post #9
post #7

Earlier quoted context omitted.

Linkedins support site URLs (hosted by custhelp.com) used to look something like this http://linkedin.custhelp.com/cgi-bin/*linkedin.cfg*/php/endu... I know custhelp used to be particularly insecure right around when this hack happened, as I myself discovered several vulnerabilities back then. >Also, when you say '"confusion"', do you mean it was feigned? Partly. From what I recall it took them quite a while to own u…

Wow, just looking at that URL is cause for concern.

Oh yeah, it was vulnerable to the exact RCE bug you'd guess at first glance.

In fact, the hack coincides perfectly with that php-cgi bug being released. Coincidence?

Post reply on HN