Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?
LinkedIn at one point were continually pressuring people into handing over their email credentials in the name of making it easy to find your contacts. So yeah, LinkedIn have never been exactly a bastion of IT Security.
Have I Been Pwned 2.0
171–180 of 323 posts
Re: Have I Been Pwned 2.0
#172Checking the passwords, "password" has been pwned >21 million times. I don't know what I expected.
Re: Have I Been Pwned 2.0
#173Unfortunately the new UI does not allow to search for leaked phone numbers anymore. The old did (e.g. could check for facebook phone number leak, see https://www.troyhunt.com/the-facebook-phone-numbers-are-now-... ). The new does not let it pass through the input field. Edit: it's also statet in the announcement: > Just one little thing first - we've dropped username and phone number search support from the website B…
The reasons for dropping the feature as outlined in the announcement seem very reasonable to me considering the larger implications.
Re: Have I Been Pwned 2.0
#174on the other hand, they will be great for the api/business pages
Re: Have I Been Pwned 2.0
#175Earlier quoted context omitted.
"Microsoft Regional Director" We can debate semantics but if you describe yourself with a job title attached to a company then I suggest that you have an association which looks rather like ... employment.
It's not a job title, it's some Microsoft program, like their MVP program. The RD site linked from Troy's site isn't loading for me at the moment, but if you search "what is the microsoft regional director program" you get back information making it clear that it's not for MS Employees. https://rd.microsoft.com/en-us/ > The Microsoft Regional Directors program recognizes industry professionals for their cross-platfor…
Re: Have I Been Pwned 2.0
#176Re: Have I Been Pwned 2.0
#177Lots of regular people use Have I Been Pwned and sending them to 1Password is probably the single best thing you could do for them (I know it's a sponsorship - but it's a very complimentary one). I'd make the language around that promo banner stronger (ie. "We strongly recommend") and make it stand out more on the page. So many social media accounts get hacked[0] because of shared passwords and those affected users o…
Re: Have I Been Pwned 2.0
#178Earlier quoted context omitted.
It's actually really easy to do unintentionally. For an intervening middleware, a password field in a JSON object is just like any other field in a JSON object. You may have some kind of logging / tracking / analytics somewhere that logs request bodies. You don't even have to engage in marketing shenanigans for that to be a problem, an abuse prevention system (which is definitely a necessity at their scale) is enough…
A company as big as LinkedIn should have bots continually accessing their site with unique generated passwords etc., and then be searching for those secrets in logging pipelines, bytes on disk, etc. to see where they get leaked. I know much smaller companies that do this. Yes, it's easy to fuck up. But a responsible company implements mitigations. And LinkedIn can absolutely afford to do much more.
If the method works, and it shows that the logging feature Fred got so much credit for is storing passwords, what are the political implications of that? Can our intrepid middle manager steal some of Fred's glory? Or is Fred an ally and it should be carefully handled? Or do they sit on it and wait until an opportune moment to destroy Fred?
This is the kind of reasoning process I think goes on, because I've seen very few large organisations make actually-good technical decisions.
Re: Have I Been Pwned 2.0
#179Re: Have I Been Pwned 2.0
#1802) When clicking "details" on one of the search results, and then the back button, the search results disappear.
3) Other than that, thanks man great service!