Database is available here https://disk.yandex.net/disk/public/?hash=pCAcIfV7wxXCL/YPhO... (Source: twitter, haven't looked at it myself)
6.5 Million LinkedIn Password Hashes Leaked
11–20 of 547 posts
Re: 6.5 Million LinkedIn Password Hashes Leaked
#12> - With a computer of 8,000 NOK (~ 1400 USD), you can do a few hundred million attempts per second. Are you kidding me? LinkedIn stored their passwords using (salted) SHA1 using no iterations? Jesus.
Re: 6.5 Million LinkedIn Password Hashes Leaked
#13I've just downloaded the database linked and it only contains the hashed passwords, not the account usernames / e-mail addresses. I wonder if someone has the account details to match up otherwise you've no idea which password belongs to who, and you'd hope that LinkedIn would have lockout functionality.
Re: 6.5 Million LinkedIn Password Hashes Leaked
#14The forum they are talking about apparently (found using google) http://forum.insidepro.com/viewtopic.php?p=96122&sid=133...
The Hacker News effect seems to have taken the forums off-line. If you need a quick DDOS and don't have a botnet handy, just post the link here!
Re: 6.5 Million LinkedIn Password Hashes Leaked
#15The forum they are talking about apparently (found using google) http://forum.insidepro.com/viewtopic.php?p=96122&sid=133...
The Hacker News effect seems to have taken the forums off-line. If you need a quick DDOS and don't have a botnet handy, just post the link here!
A saved copy of my local cache...
Re: 6.5 Million LinkedIn Password Hashes Leaked
#16I wonder how many LinkedIn users use the same passwords for all their accounts. The article talks about identity theft and "confidential contacts" but I think the real danger is that people tend to use the same password everywhere. It's their other accounts that might have real value. EDIT - As I think about it, e-mail accounts would be especially valuable as most of your other sites could be compromised using the "r…
Me. Admittedly, it's stupid as hell, but has generally been too much of a pain to do anything else (for things outside of banking, email). I've started to get serious about KeePass lately, but I bet a significant percentage of users take the lazy approach.
E.g. my hacker news account would probably be relatively unproblematic to compromise. If that were to happen, I'd just make a new one though.
Re: 6.5 Million LinkedIn Password Hashes Leaked
#17I've just downloaded the database linked and it only contains the hashed passwords, not the account usernames / e-mail addresses. I wonder if someone has the account details to match up otherwise you've no idea which password belongs to who, and you'd hope that LinkedIn would have lockout functionality.
Agreed. That seems rather useless. How would that happen anyway? The usernames stored in a different database/table from the hashes?
Re: 6.5 Million LinkedIn Password Hashes Leaked
#18I wonder how many LinkedIn users use the same passwords for all their accounts. The article talks about identity theft and "confidential contacts" but I think the real danger is that people tend to use the same password everywhere. It's their other accounts that might have real value. EDIT - As I think about it, e-mail accounts would be especially valuable as most of your other sites could be compromised using the "r…
Me. Admittedly, it's stupid as hell, but has generally been too much of a pain to do anything else (for things outside of banking, email). I've started to get serious about KeePass lately, but I bet a significant percentage of users take the lazy approach.
Re: 6.5 Million LinkedIn Password Hashes Leaked
#19I wonder how many LinkedIn users use the same passwords for all their accounts. The article talks about identity theft and "confidential contacts" but I think the real danger is that people tend to use the same password everywhere. It's their other accounts that might have real value. EDIT - As I think about it, e-mail accounts would be especially valuable as most of your other sites could be compromised using the "r…