Boat Drinks  

Go Back   Boat Drinks > General > General Disruption

Reply
 
Thread Tools Display Modes
Old 06-06-2012, 15:30   #1
Del Lardo
Absinthe
 
Del Lardo's Avatar
 
Join Date: Jan 2007
Location: Cambridge
Posts: 2,539
Default Change your LinkedIn password

http://www.zdnet.com/blog/btl/646-mi...d-online/79290

Best be on the safe side............
Del Lardo is offline   Reply With Quote
Old 06-06-2012, 15:50   #2
divine
Moonshine
 
divine's Avatar
 
Join Date: Sep 2007
Location: Southampton
Posts: 3,201
Default

FFS I only signed up about a month ago because people at work were pestering me.
__________________
divine is offline   Reply With Quote
Old 06-06-2012, 16:55   #3
Dazzy_G
Long Island Iced Tea
 
Dazzy_G's Avatar
 
Join Date: Mar 2009
Location: Thurrock, Essex
Posts: 103
Default

Rather annoying, I'd like to know that the hole is patched before I change the password though, other sites will be done though
__________________
Dazzy_G is offline   Reply With Quote
Old 06-06-2012, 20:16   #4
Mark
Screaming Orgasm
 
Join Date: Jul 2006
Location: Newbury
Posts: 15,194
Default

Change it to something temporary (and not used elsewhere) until it's confirmed patched - otherwise you could be going around in circles.

Thankfully the passwords are encrypted, which is a step in the right direction from previous disclosures at least. It's now down to how easy they are to crack. Provided you used a strong password (i.e. not one that can be cracked with a dictionary attack), and they used a sufficiently strong hash (at least SHA-1), then you'll be OK, but better to change it anyway.
Mark is offline   Reply With Quote
Old 06-06-2012, 21:47   #5
Garp
Preparing more tumbleweed
 
Garp's Avatar
 
Join Date: Jun 2006
Location: Hawaii
Posts: 6,038
Default

Encryption / hashing is next to useless without salting, which is what LinkedIn haven't done. Good explanation here: http://www.standalone-sysadmin.com/b...s-compromised/
__________________
Mal: Define "interesting"?
Wash: "Oh, God, oh, God, we're all gonna die"?
Garp is offline   Reply With Quote
Old 06-06-2012, 23:15   #6
Zirax
Goes up to 11!
 
Zirax's Avatar
 
Join Date: Jul 2006
Posts: 4,577
Default

FFS, its not like this is a company listed on the exchange or anything. There needs to be BIG fines for pathetic password storage policies in the modern age.

IIRC there is a part in the DPA about ensuring users information is sufficiently protected?
Zirax is offline   Reply With Quote
Old 07-06-2012, 00:26   #7
Garp
Preparing more tumbleweed
 
Garp's Avatar
 
Join Date: Jun 2006
Location: Hawaii
Posts: 6,038
Default

Under the laws in the US they'll be required to include the details of the hack in their annual filings. Next shareholder meeting promises to be interesting.
__________________
Mal: Define "interesting"?
Wash: "Oh, God, oh, God, we're all gonna die"?
Garp is offline   Reply With Quote
Old 07-06-2012, 14:53   #8
LeperousDust
Bananaman
 
LeperousDust's Avatar
 
Join Date: Jul 2006
Location: Liverpool/Edinburgh
Posts: 4,817
Default

Have a unique password for LinkedIn, as with pretty much every "important" website I use that encompasses my "online presence".

I'll change it slightly for now and hold fire until they sort themselves out. No one company can be trusted at all, which is why I keep my passwords totally unique...

It's terrible companies can't keep a check on security and I don't mean losing the passwords in the first place, I mean actually making sure they're safely guarded even in the wrong hands... It's not a difficult idea, but as with any large companies they tend to be somewhat ignorant

Saying that most users don't take password security seriously either *sigh*...
__________________
LeperousDust is offline   Reply With Quote
Old 07-06-2012, 15:03   #9
Mark
Screaming Orgasm
 
Join Date: Jul 2006
Location: Newbury
Posts: 15,194
Default

So even if they don't think your password has been compromised, you should change it anyway, since the hack affects 6.5m passwords, not 6.5m accounts as the media have reported.

Due to their lack of salts, multiple accounts with the same password have the same hash, and thus you can't guarantee that your account hasn't been compromised because you don't know if someone else happens to have chosen the same password as you (however unlikely you may think that is).

Thankfully, I don't have a LinkedIn account. Dreading when one of my accounts does get compromised though because I only have a small number of passwords across all sites. I've been researching password managers for my phone because I think that's the way I'm going to have to go.

Last edited by Mark; 07-06-2012 at 15:07.
Mark is offline   Reply With Quote
Old 07-06-2012, 15:23   #10
Zirax
Goes up to 11!
 
Zirax's Avatar
 
Join Date: Jul 2006
Posts: 4,577
Default

True, I only used the password for there as I never fully trusted LinkedIn, bit like Facebook.
Zirax is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 00:02.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.