WEBSITE

Password Hacks Raise User Fears

9/1/2012 3:12:26 AM

Business networking site LinkedIn has confirmed that over six million hashed user passwords were stolen and published on a hacker website earlier this month. According to the company, however, most of the passwords were never decoded, and those that were weren’t successfully linked with an email address to enable hackers to access user’s accounts.

Description: Password hacks raise user fears

Business networking site LinkedIn has confirmed that over six million hashed user passwords were stolen and published on a hacker website earlier this month

Writing on the company’s blog, LinkedIn director Vincente Silveira said: “Yesterday we learned that approximately 6.5m hashed LinkedIn passwords were posted on hacker site. Most of the passwords on the list appear to remain hashed and hard to decode, but unfortunately a small subset of the hashed passwords was decode and published.’

Without that link to email addresses, however, accounts don’t seem to have been compromised. Silveira said the company had not ‘received any verified reports of unauthorized access to any member’s account as a result of this event’.

The passwords that had been decoded were immediately invalidated by the company, and LinkedIn emailed users whose accounts were affected to explain how to change their passwords.

The same hacker also got hold of passwords for dating website eHarmony and posted the encrypted versions online. eHarmony confirmed in a blog post : ‘After investigating reports of compromised passwords, we have found that a small fraction of our user base has been affected.’

In a bad week for online security, UK music and radio site Last.fm reported that its security had also been compromised and said it was ‘investigating the leak of some Last.fm user passwords’ and ‘asking all our users to change their passwords immediately.’

eHarmony claimed it had ‘robust security measures, including password hashing and date encryption, to protect personal information… we also protect our networks with state-of-the-art firewalls, load balancers, SSL and other sophisticated security approaches.’

Description: LinkedINsecurity

LinkedIn security

Clearly those security measures weren’t enough, which is why LinkedIn has been working to improve the security of its users’ date in recent months. Silveira wrote that the company had already made the ‘transition from a password database system that hashed passwords, ie provided an extra layer of protection that is a widely recognized best practice within the industry.’

But Matasano Security researcher Thomas H Ptacek, interviewed by blogger Brian Krebs, said it was a ‘misconception’ that salting would help. ‘The problem is they’re using the wrong kind of algorithm. They use a cryptographic hash, when they need to use a password hash.’ And LinkedIn wasn’t alone in this. ‘Nobody gets this right.’

Other  
 
Top 10
Review : Sigma 24mm f/1.4 DG HSM Art
Review : Canon EF11-24mm f/4L USM
Review : Creative Sound Blaster Roar 2
Review : Philips Fidelio M2L
Review : Alienware 17 - Dell's Alienware laptops
Review Smartwatch : Wellograph
Review : Xiaomi Redmi 2
Extending LINQ to Objects : Writing a Single Element Operator (part 2) - Building the RandomElement Operator
Extending LINQ to Objects : Writing a Single Element Operator (part 1) - Building Our Own Last Operator
3 Tips for Maintaining Your Cell Phone Battery (part 2) - Discharge Smart, Use Smart
REVIEW
- First look: Apple Watch

- 3 Tips for Maintaining Your Cell Phone Battery (part 1)

- 3 Tips for Maintaining Your Cell Phone Battery (part 2)
VIDEO TUTORIAL
- How to create your first Swimlane Diagram or Cross-Functional Flowchart Diagram by using Microsoft Visio 2010 (Part 1)

- How to create your first Swimlane Diagram or Cross-Functional Flowchart Diagram by using Microsoft Visio 2010 (Part 2)

- How to create your first Swimlane Diagram or Cross-Functional Flowchart Diagram by using Microsoft Visio 2010 (Part 3)
Popular Tags
Microsoft Access Microsoft Excel Microsoft OneNote Microsoft PowerPoint Microsoft Project Microsoft Visio Microsoft Word Active Directory Biztalk Exchange Server Microsoft LynC Server Microsoft Dynamic Sharepoint Sql Server Windows Server 2008 Windows Server 2012 Windows 7 Windows 8 Adobe Indesign Adobe Flash Professional Dreamweaver Adobe Illustrator Adobe After Effects Adobe Photoshop Adobe Fireworks Adobe Flash Catalyst Corel Painter X CorelDRAW X5 CorelDraw 10 QuarkXPress 8 windows Phone 7 windows Phone 8
Visit movie_stars's profile on Pinterest.