Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Catherina

(35,568 posts)
Wed Jun 6, 2012, 12:16 PM Jun 2012

6.5 million LinkedIn passwords leaked online

Source: The Independent

KEVIN RAWLINSON WEDNESDAY 06 JUNE 2012

Nearly 6.5 million passwords belonging to users of the professional social networking site LinkedIn have been leaked online, according to reports.

Users are being urged to change their login details over fears that, if confirmed, the leak would compromise vast amounts of personal data, including contact information. The information was reportedly posted as encrypted on a Russian hackers’ website and 300,000 are said to have been decrypted, with work ongoing, according to the respected technology blog The Next Web.

LinkedIn, which faced criticism recently after it was revealed that its mobile app was sending certain information from users’ phones back to the company without their knowledge, posted a message on Twitter saying it was looking into the reports, which are as yet unconfirmed.

A file containing 6,458,020 encoded passwords was posted online, and hackers across the world are said to be collaborating to decipher them.

...

http://www.independent.co.uk/news/uk/crime/65-million-linkedin-passwords-leaked-online-7820696.html

Read more: http://www.independent.co.uk/news/uk/crime/65-million-linkedin-passwords-leaked-online-7820696.html



Change your passwords. CNET is also reporting this with a little more technical detail http://news.cnet.com/8301-1009_3-57448079-83/millions-of-linkedin-passwords-reportedly-leaked-online/
30 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
6.5 million LinkedIn passwords leaked online (Original Post) Catherina Jun 2012 OP
As soon as I heard this, the password changing commenced. GreenPartyVoter Jun 2012 #1
Just changed mine as well. Esse Quam Videri Jun 2012 #4
Me, too. But what good does a LinkedIn PW do a hacker? Honeycombe8 Jun 2012 #23
Lots of people re-use passwords. boppers Jun 2012 #26
This may not be as bad as it sounds... Ron Obvious Jun 2012 #2
You need to learn about rainbow tables. boppers Jun 2012 #27
I'm not an expert... Ron Obvious Jun 2012 #28
Good for me - I refused to do LinkedIn Woody Woodpecker Jun 2012 #3
Do you think that's a good idea? DaveJ Jun 2012 #20
Sigh. eggplant Jun 2012 #5
My sentiments exactly. Sigh. NT KaryninMiami Jun 2012 #8
Deleted my LinkedIn account at the same time as my Facebook. daaron Jun 2012 #6
Thanks for the link, Catherina! I'm changing mine right now. slackmaster Jun 2012 #7
Oh ... Auggie Jun 2012 #9
Went to change my password or delete account. louis-t Jun 2012 #10
Can anyone tell me what the hell LinkedIn DOES? Is it Myspace/Facebook for adults, or what? MADem Jun 2012 #11
Social networking on a professional level Catherina Jun 2012 #12
...and it works very well for people in IT and related fields slackmaster Jun 2012 #13
It's very useful professionally. drm604 Jun 2012 #15
My work colleagues loved it Catherina Jun 2012 #17
It's like putting your rolodex/file-o-fax on the net, basically. MADem Jun 2012 #16
It's a professional networking site. Honeycombe8 Jun 2012 #24
Just changed mine. Thanks. drm604 Jun 2012 #14
thank you..... dhill926 Jun 2012 #18
They got mine BadGimp Jun 2012 #19
LinkedIn notified customers who it knew to be affected slackmaster Jun 2012 #22
I never use cell phone apps SemperEadem Jun 2012 #21
Like LinkedIn, eHarmony is hacked; 1.5 million passwords stolen Eugene Jun 2012 #25
Ahhh... Time to whip out the rainbow tables... octothorpe Jun 2012 #29
Looks as if just the hashes were released... Which means they can't link your password hash to you octothorpe Jun 2012 #30

Honeycombe8

(37,648 posts)
23. Me, too. But what good does a LinkedIn PW do a hacker?
Wed Jun 6, 2012, 08:24 PM
Jun 2012

It's a PW to a site where you don't buy anything (most don't), don't have credit card or other information like that on there.

The most they could get from me is my email address (which isn't even my main email address).

 

Ron Obvious

(6,261 posts)
2. This may not be as bad as it sounds...
Wed Jun 6, 2012, 12:37 PM
Jun 2012

After all, these are encrypted passwords. Presumably a lot of them will be vulnerable from dictionary and baby name list attacks, but if you use strong passwords with mixed case, alphanumeric and punctuation mixed symbols you'd be better off. It's not that those are impossible to crack, they're just not the low-hanging fruit that many of the other passwords represent.

boppers

(16,588 posts)
27. You need to learn about rainbow tables.
Wed Jun 6, 2012, 10:34 PM
Jun 2012

Much more efficient than dictionary attacks, and include silliness like "P455w.rd", and other super-common mixed case, mixed character, "hard" passwords...

http://en.wikipedia.org/wiki/Rainbow_table

 

Ron Obvious

(6,261 posts)
28. I'm not an expert...
Thu Jun 7, 2012, 02:07 AM
Jun 2012

My knowledge on this topic is pretty out of date, so thanks for the link to the article. It seems that these are precomputed hashing sequences to help speed up the computation of the hash value. I've heard conflicting reports on whether LinkedIn salted their hashes (which would make those precomputed table sequences useless, I assume).

I also didn't actually know that you could have significant value in having precomputed hashing sequences singe changing as little as one bit seems to yield radically different hashes to me.

 

Woody Woodpecker

(562 posts)
3. Good for me - I refused to do LinkedIn
Wed Jun 6, 2012, 12:41 PM
Jun 2012

Saw it once, didn't like it, didn't look back.

Stupid recruiters are still trying to get me to use LinkedIn. No thanks.

Either you see my resume, or you move on.

DaveJ

(5,023 posts)
20. Do you think that's a good idea?
Wed Jun 6, 2012, 06:54 PM
Jun 2012

I work in technology, so maybe it's different for me. But I was just joking yesterday about how funny it would be if I got another job at a web development company and said all I know is some old technology, and said to them on my first day "that's all I know, and that all I do." It would be kind of ridiculous to avoid new technology and new ways of doing things. In my field at least.

louis-t

(23,292 posts)
10. Went to change my password or delete account.
Wed Jun 6, 2012, 01:55 PM
Jun 2012

Site is bombarded with people trying to do same. Can't even get on.

MADem

(135,425 posts)
11. Can anyone tell me what the hell LinkedIn DOES? Is it Myspace/Facebook for adults, or what?
Wed Jun 6, 2012, 02:16 PM
Jun 2012

I keep getting odd invitations, purportedly from my friends, to "join" the stupid thing--I figure the LinkedIn creeps have data-mined the mailboxes of my friends. I am not curious enough to join to find out, but I am wondering what is the advantage of the site? What purpose does it serve?

Catherina

(35,568 posts)
12. Social networking on a professional level
Wed Jun 6, 2012, 02:22 PM
Jun 2012


I'm so glad I never accepted any of those invitations either.
 

slackmaster

(60,567 posts)
13. ...and it works very well for people in IT and related fields
Wed Jun 6, 2012, 02:31 PM
Jun 2012

I found it to be a wonderful source of job leads last time I was looking.

I've also used it to re-connect with a bunch of former co-workers and classmates.

Catherina

(35,568 posts)
17. My work colleagues loved it
Wed Jun 6, 2012, 03:20 PM
Jun 2012

and I see its good points but it seemed so invasive.

If I were looking for a job, I'd probably change my tune in a hurry.

MADem

(135,425 posts)
16. It's like putting your rolodex/file-o-fax on the net, basically.
Wed Jun 6, 2012, 02:51 PM
Jun 2012

People can read yours, and you can read theirs..! TMI for me!

All this "sharing!"

I'm glad I'm retired!

Honeycombe8

(37,648 posts)
24. It's a professional networking site.
Wed Jun 6, 2012, 08:33 PM
Jun 2012

If anyone in your business is looking for you, your business information will be there. People can email you through that site, but they don't have your email address, so that stays private. You "connect" with others, and then pics of others who are connected to your connection pop up as possible new connections for you. The purpose of connections is to network, as well as to stay in touch with co-workers and colleagues, when you're maybe not close enough to be friends.

If you are looking for a new job, a lot of employers check LinkedIn to see if you have a presence there. You can post your resume there, or in your profile just give the basics of your training, education, and work history, as well as a photo.

I recently changed jobs, and several people were able to locate me at my new employer because of my updated LinkedIn profile.

There is a slight social aspect to it, in that you can join groups that are based on common interests. Most of them are occupational or professional groups (like I joined several technie groups). Those are good places to post a question; people there are likely to know the answer. Also, there are social groups, like the Organic Gardening group, etc.

It's not like Facebook at all. It's mainly a business site for people to maintain a professional presence.

BTW, my new employer checked me out on LinkedIn before hiring me. He also checked to make sure I did not have a Facebook account, or at least anything inappropriate on a Facebook account. But I don't have a Facebook account.

BadGimp

(4,015 posts)
19. They got mine
Wed Jun 6, 2012, 03:56 PM
Jun 2012

Already getting spam as a result

Yikes

LinkedIN is the single most valuable site for me as it relates to my career...

 

slackmaster

(60,567 posts)
22. LinkedIn notified customers who it knew to be affected
Wed Jun 6, 2012, 08:24 PM
Jun 2012

BTW, even if some scumbags got your SHA1 hashed password it's unlikely they were able to unscramble it. It's not impossible, and the likelihood is inversely proportional to the complexity of the password.

Eugene

(61,872 posts)
25. Like LinkedIn, eHarmony is hacked; 1.5 million passwords stolen
Wed Jun 6, 2012, 08:35 PM
Jun 2012

Source: Los Angeles Times

http://www.latimes.com/business/technology/la-fi-tn-eharmony-hacked-linkedin-20120606,0,4578300.story

Like LinkedIn, eHarmony is hacked; 1.5 million passwords stolen

By Salvador Rodriguez

June 6, 2012, 4:56 p.m.

EHarmony, the popular online dating site, was the target of a password hacking attack that resulted in 1.5 million stolen passwords, most of which have been cracked.

The attack is believed to be by the same hacker who stole 6.5 million passwords from LinkedIn, the career-oriented social network.

The hacker posted two lists containing the 8 million passwords on the website insidepro.com, on which the user goes by the name of "dwdm."

The larger list contained some passwords LinkedIn has now confirmed as belonging to its social network. and a significant number of the passwords on the smaller list contained the words "eHarmony" or "harmony," according to Ars Technica.

[font size=1]-snip-[/font]


Read more: http://www.latimes.com/business/technology/la-fi-tn-eharmony-hacked-linkedin-20120606,0,4578300.story

octothorpe

(962 posts)
29. Ahhh... Time to whip out the rainbow tables...
Thu Jun 7, 2012, 02:22 AM
Jun 2012

Now watch some big targets change their linkedin password, but not bother changing passwords to other things using the same passwords...

octothorpe

(962 posts)
30. Looks as if just the hashes were released... Which means they can't link your password hash to you
Thu Jun 7, 2012, 02:42 AM
Jun 2012

so even if they do get a hit, they don't know who to use it on. Of course someone may have the emails, but is keeping them to themselves.

Also, I would avoid any site that offers to check to see if your hash in the leaked list. You might simply be helping them figure out your plain-text password quicker than usual, and you may also leave a way for them to link that password to you.

Latest Discussions»Latest Breaking News»6.5 million LinkedIn pass...