1. Welcome! Please take a few seconds to create your free account to post threads, make some friends, remove a few ads while surfing and much more. ClutchFans has been bringing fans together to talk Houston Sports since 1996. Join us!

LinkedIn Hacked - Change your password NOW

Discussion in 'BBS Hangout' started by JeopardE, Jun 6, 2012.

  1. JeopardE

    JeopardE Member

    Joined:
    Jun 29, 2006
    Messages:
    7,418
    Likes Received:
    246
    Guys,

    Russian hackers have hacked LinkedIn and stolen about 6.5 million passwords. Go change your password now.

    http://www.reddit.com/r/technology/comments/unt92/russian_hackers_claim_to_have_65m_linkedin/

    It's a list of unsalted SHA1 hashes. The ones that have already been cracked have the first few digits changed to 0s. I downloaded the list and checked for mine -- regrettably mine was there AND it had been cracked. Feel quite ashamed right about now.

    EDIT: I mentioned this in another post but I agree that it should be said here -- this is particularly important if you use the same password for other sites, like your email account. Hackers will try to use your cracked password to glean as much information about you as they can from popular web sites, and then use that for identity theft. That's what makes password lists like this so valuable on the black market. If you have an account on LinkedIn, regardless of whether your password was published or not, you need to go change it now -- to something much more secure.
     
    #1 JeopardE, Jun 6, 2012
    Last edited: Jun 6, 2012
    2 people like this.
  2. rhadamanthus

    rhadamanthus Member

    Joined:
    Nov 20, 2002
    Messages:
    14,304
    Likes Received:
    596
    Thanks for the heads up.
     
  3. Butterfingers

    Butterfingers Member

    Joined:
    Aug 20, 2007
    Messages:
    1,841
    Likes Received:
    115
    Damn I was just about to make a linkedin account lol...
     
    1 person likes this.
  4. 713

    713 Member

    Joined:
    May 6, 2011
    Messages:
    5,821
    Likes Received:
    926
    what is linkedin?
     
  5. mvpcrossxover

    mvpcrossxover Member

    Joined:
    Aug 13, 2008
    Messages:
    32,023
    Likes Received:
    15,927
    what's LinkedIn?
     
  6. napalm06

    napalm06 Huge Flopping Fan

    Joined:
    Sep 30, 2008
    Messages:
    26,930
    Likes Received:
    30,546
    Oh, shoot. They're going to steal my mediocre resume.
     
  7. ashiin

    ashiin Member

    Joined:
    Aug 23, 2009
    Messages:
    2,054
    Likes Received:
    112
    It's like a formal/business Facebook.
     
  8. Haymitch

    Haymitch Custom Title

    Joined:
    Dec 22, 2005
    Messages:
    28,371
    Likes Received:
    24,021
    Wait. Change my LinkedIn password or change the password for every site that has the same password as my LinkedIn account?
     
  9. AMS

    AMS Member

    Joined:
    Oct 8, 2003
    Messages:
    9,646
    Likes Received:
    218
    Thanks for the heads up.
     
  10. mvpcrossxover

    mvpcrossxover Member

    Joined:
    Aug 13, 2008
    Messages:
    32,023
    Likes Received:
    15,927
    i see, i don't use so i no worry
     
  11. JeopardE

    JeopardE Member

    Joined:
    Jun 29, 2006
    Messages:
    7,418
    Likes Received:
    246
    If I were you I would change it on every site you know that has that same password. Odds are that they can link it to your email address, and if so there's no stopping them.
     
  12. Haymitch

    Haymitch Custom Title

    Joined:
    Dec 22, 2005
    Messages:
    28,371
    Likes Received:
    24,021
    Dang.

    I always thought Eatern Promises was overrated, but now I flat-out hate it.
     
  13. JeopardE

    JeopardE Member

    Joined:
    Jun 29, 2006
    Messages:
    7,418
    Likes Received:
    246
    So that's your password? I just checked and Eastern is in fact on the list. What's your email btw? :)
     
  14. geeimsobored

    geeimsobored Member

    Joined:
    Aug 20, 2005
    Messages:
    8,968
    Likes Received:
    3,389
    They seriously didn't salt passwords. Isn't that pretty elementary nowadays. I thought doing that was standard practice.
     
  15. JeopardE

    JeopardE Member

    Joined:
    Jun 29, 2006
    Messages:
    7,418
    Likes Received:
    246
    I know. Utterly inexcusable for a site of that size and a publicly traded company. At the very least you should be using SHA256 with a salt. Did nobody learn from Sony's PSN fiasco?
     
  16. Air Langhi

    Air Langhi Contributing Member

    Joined:
    Aug 26, 2000
    Messages:
    21,943
    Likes Received:
    6,696
    They got the hashes. It isn't the same as the password. So usually what you do is have a salt and use that salt to hash the password. The hashing function like sha2 acts as a one way function so that y=f(x). However whereas in most functions you can solve for x the hashing function makes it very difficult to solve for x.

    When you use a password they don't save the actual password, or they shouldn't. They should save f(password+salt). In this case brute force computing all the possible hashes will take a very long time.

    As long as you aren't using a simple password you should be ok.
     
  17. SwoLy-D

    SwoLy-D Member

    Joined:
    Jul 20, 2001
    Messages:
    37,618
    Likes Received:
    1,456
    Do you also "no worry" about A.I.D.S. or H.I.V. because you're not having secks? :p

    ;)
     
  18. Air Langhi

    Air Langhi Contributing Member

    Joined:
    Aug 26, 2000
    Messages:
    21,943
    Likes Received:
    6,696
    Didn't realize they didn't do salt and used sha1. I am changing my password.
     
  19. JeopardE

    JeopardE Member

    Joined:
    Jun 29, 2006
    Messages:
    7,418
    Likes Received:
    246
    They didn't use a salt. Also, about half the passwords have been cracked already (don't know if they're using brute force or not). My password was a non-dictionary password with numbers in it, although admittedly not very long, and it had been cracked.
     
  20. geeimsobored

    geeimsobored Member

    Joined:
    Aug 20, 2005
    Messages:
    8,968
    Likes Received:
    3,389
    Where did you go to find out if it had been cracked?
     

Share This Page

  • About ClutchFans

    Since 1996, ClutchFans has been loud and proud covering the Houston Rockets, helping set an industry standard for team fan sites. The forums have been a home for Houston sports fans as well as basketball fanatics around the globe.

  • Support ClutchFans!

    If you find that ClutchFans is a valuable resource for you, please consider becoming a Supporting Member. Supporting Members can upload photos and attachments directly to their posts, customize their user title and more. Gold Supporters see zero ads!


    Upgrade Now