Live data from Hacker News

LinkedIn password leak

usblog.kaspersky.com

131–140 of 218 posts

Re: LinkedIn password leak

#131
post #50

1: Change your password. RIGHT NOW. If you’re not sure how strong your password is, test sample passwords with our password checker here. Seriously? Keep in mind that these estimates are based on some bogus entropy estimation. If a password hacking guy runs the correct dictionary past the hashes you password generates, it might be as small, well, as the first one tried. For example, run the passphrase Ph'nglui mglw'n…

So, being one of the people who hovers around laymanship when it comes to these questions, how hard is it to crack a randomly generated 25 character string with 5 digits and 5 symbols? This is typically what I would use for a website.

Do you actually generate your strings randomly, or do you rely on yourself, a puny human I suppose, to generate it?

Re: LinkedIn password leak

#132

> If you’re not sure how strong your password is, test sample passwords with our password checker here. That is irrelevant in the face of leaked passwords; what matters most in that situation is that your password is something other than your leaked one. If the passwords were leaked due to being stored in plain-text, no amount of complexity would protect them, obviously. Don't use the same password on multiple sites.…

Accounts aren't all created equal. Some of my accounts, such as my domain account at work and my online banking account have real power to screw me over. Some are in the middle, like my LinkedIn account, or my gmail account, since they could be used for social engineering. Some are trivial like my Fark account or my Hacker News account. In that last tier, there's no way it's worth my time to keep rotating those on a regular basis. It wouldn't be even that much of a crime to use the same password on them, since there's virtually no way someone's going to pivot from a Fark account into my bank account. So quit being so dogmatic is what I'm saying.

Re: LinkedIn password leak

#133
post #89

Earlier quoted context omitted.

A password vault ties you to a particular computer or mobile device. It's terribly inconvenient. But it's the best thing that we have today.

keepass + dropbox works ok.

keepass + dropbox is also my choice. There's (unofficial) keepass ports for both android and iOS too which can connect to the dropbox app. I use both and they work fine.

Re: LinkedIn password leak

#135
post #132

> If you’re not sure how strong your password is, test sample passwords with our password checker here. That is irrelevant in the face of leaked passwords; what matters most in that situation is that your password is something other than your leaked one. If the passwords were leaked due to being stored in plain-text, no amount of complexity would protect them, obviously. Don't use the same password on multiple sites.…

Accounts aren't all created equal. Some of my accounts, such as my domain account at work and my online banking account have real power to screw me over. Some are in the middle, like my LinkedIn account, or my gmail account, since they could be used for social engineering. Some are trivial like my Fark account or my Hacker News account. In that last tier, there's no way it's worth my time to keep rotating those on a…

"Some are in the middle, like my LinkedIn account, or my gmail account"

Your email account is the golden key to all other accounts that send "forgot password" links to it.

Re: LinkedIn password leak

#136

As someone who isn't versed in security issues, can anyone explain how security breaches like this one (and Adobe etc.) occur? I'm assuming (and I may be completely wrong) that some kind of software monitors if the database of customer details is being downloaded. If a download is detected, an alert is issued. Does software like this exist? Or there other measure that guard against these data breaches?

a) Basically the cracker acquires access to parts of LinkedIn's database that store user login details, including scrambled versions of passwords. Unfortunately, the algorithm used to do the scrambling is easy to undo. Since the dump is/was being circulated in the underground, anyone with a copy of it and a little bit of time can presumably unscramble the whole list, revealing all passwords stored at the time the dump was generated. Given that so many use the same login/password for multiple sites...

b) There is software (intrusion detection systems/software, or IDS) that does that, but it is rarely present by default. The hows and whys of IDS can be difficult for non-security types to grok, and it can be costly in terms of time, equipment, and money, so it often not encountered.

Re: LinkedIn password leak

#137

Earlier quoted context omitted.

Why not?

I don't like that you have to specify a fixed number of numbers, special chars, etc.

if it's truly random, then you need to if you want to guarantee you have at least 1 of various character classes..

Re: LinkedIn password leak

#138
post #132

Earlier quoted context omitted.

Accounts aren't all created equal. Some of my accounts, such as my domain account at work and my online banking account have real power to screw me over. Some are in the middle, like my LinkedIn account, or my gmail account, since they could be used for social engineering. Some are trivial like my Fark account or my Hacker News account. In that last tier, there's no way it's worth my time to keep rotating those on a…

"Some are in the middle, like my LinkedIn account, or my gmail account" Your email account is the golden key to all other accounts that send "forgot password" links to it.

I don't use it myself but I would think that you wouldn't want your "professional" social network account to fall in the wrong hands either.

Re: LinkedIn password leak

#139
And LinkedIn is now asking me to enter my phone number:

"Add an extra layer of security to your account. Add your phone number."

Leaking my email / password is bad enough; I'm not going to give them my phone number for more damages!

Re: LinkedIn password leak

#140

Earlier quoted context omitted.

That means either a) You're account was not included in the comprised accounts or b) You checked an email different from your LinkedIn account.

I didn't get an email until after I logged into my account with the compromised password. Then it sent me an email and locked my account. Sort of odd way of dealing with the problem. This all happened about 20 minutes ago.

It was just a coincidence that you received the email after you logged into your account. Logging into your account didn't trigger the email to be sent.
Post reply on HN