Follow Us

Hacking: LinkedIn strengthens password encryption after last week's leak

Still no word on how hack occurred

LinkedIn has brought the encryption applied to all user passwords up to a more secure standard after last week’s hugely embarrassing password hack, the company has announced.

This will count as a small consolation for anyone affected by the loss of 6.5 million passwords secured in an ‘unsalted’ state using the less secure 160 bit SHA-1 encryption algorithm.

The company said that after discovering the hack on the morning of 6 June, it had disabled published passwords it believed were at risk of exposure by the end of play on 7 June. None of the emails involved included email logins, the company claimed.

“After we disabled the passwords, we contacted members with instructions on how to reset their passwords,” LinkedIn said. “At this time, there have been no reports of compromised LinkedIn accounts as a result of this password theft.”

Importantly, the company said it had now completed an upgrade of the security applied to all accounts whether part of the hack or not which added the use of salted hashes.

Precisely what new security was now being employed – specifically whether 256-bit SHA-2 was part of the upgrade – the company’s announcement is oddly evasive.

“For security reasons, we cannot discuss certain details of our ongoing security upgrades,” it said.

The firm’s small army of security critics might point out that detailing the security standards employed should not render a company vulnerable and indeed most vendors with public membership usually state the encryption standards used as a deterrent.

As to who hacked LinkedIn, how the hack was carried out, and with what real-world effects on member security, the LinkedIn note does not elaborate.

“At this time, LinkedIn cannot release any further information in order to protect our members and due to the ongoing investigation,” the company said.

According to message filtering vendor Cloudmark, an ironic effect of the hack appears to have been that some LinkedIn users discarded legitimate warnings sent by the firm after the attack because they thought they might be criminal spam.

“Over four percent of the people receiving this [warning] email, thought it was spam and sent it straight to the bit bucket. If Linkedin sends out 6.5 million emails, then a quarter of a million people are congratulating themselves on avoiding spam, and still have a compromised Linkedin password,” said Cloudmark’s Andrew Conway.

LinkedIn did say it had disabled all passwords believed to be at risk although again how many of the 6.5 million leaked were deemed worthy of this attention is not clear.

In Conway's view, part of the problem was that LinkedIn automatically opted users into receive email related to their activity and interests, resulting in some users marking the company’s emails as spam simply to stem the tide of unwanted communication.

“Linkedin is like the little boy who cried, ‘wolf.’ By sending too much mail that people are not really interested in, they are getting ignored when they have something important to say,” said Conway




Comments

Brian said: I sorry butthat is not enough Strong passwordssalted or not do not replace the need for other effective security control Peopleneed to be talking less about hashing or salting passwords and more about othersteps that need to be implemented like some form of 2FA were you can telesigninto your account and and have the security knowing you are protected if yourpassword were to be stolen This should be a prerequisite to any system that wants to promote itself as being secureWith this if they were to try to use the stolen password and dont have yourphone nor are on the computer smartphone or tablet you have designatedtrusted they would not be able to enter the account



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Optimise Performance For Global eCommerce

Global is all the rage: eBusiness teams are feverishly building new international initiatives in...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Techworld UK - Technology - Business

Part 2 of your journey to virtualisation

You can still access part 2 of our virtualisation journey - explore how you can improve your servers, storage and networks by developing your infrastructure.

Watch now...
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *