LinkedIn's Password Breach and Official Response Dissected

Latest Videos FromTom's Hardware
TOPICS
  • A Bad Day
    I never understood what the IT departments or the higher ups that had full control over what the ITs did were thinking. Did they really think they would get away with weak encryption, or even without encryption?

    Then again, maybe they were completely blind to the news for the past year or were lazy, like an unnamed company that still uses Windows NT 4.0 because the OS still works (so why replace it?).
    Reply
  • oafed
    I think other personal information has gotten in the hands of spammers. I think this for 3 reasons.

    1) An email account I rarely use (but have had for 10 years) was hacked this morning and locked out for sending spam. It had the same password as my LinkedIn account.

    2) My friends gmail informed him that it had blocked someone in Peru who was accessing his account. He said his gmail was the only other account he had with the same password as LinkedIn.

    3) I am hearing of a lot more spam coming from friends email addresses in the last couple days.

    Coincidence?
    Reply
  • freggo
    A Bad DayI never understood what the IT departments or the higher ups that had full control over what the ITs did were thinking. Did they really think they would get away with weak encryption, or even without encryption?Then again, maybe they were completely blind to the news for the past year or were lazy, like an unnamed company that still uses Windows NT 4.0 because the OS still works (so why replace it?).

    There is only so much security you can implement.
    The problem is not 'weak' security.
    The problem is that there are not serious enough consequences for hacking.

    Put a 20 year minimum sentence on major attacks; put serious law enforsment resources behind finding theose guilty; and make the -short- trials VERY public. Than the rest if these idiots will get the message. You get caught... your life as you know it is over.
    Think about this from the perspective of the 6+Million accounts (not just people) affected. The amount of time lost, money lost, their worries. You are not just screwing with a 'big company'; you are screwing with the lives of Millions of people.

    This is not kiddy stuff, this is a Major Financial crime all told.
    Lock 'em up with Bubba and the gang, and loose the key.


    Reply
  • "such as finding 050 starting from 000 and 999"
    O really? Wasn't it 500 maybe?
    Reply
  • Chipi
    Holy cow! I just found my password has in the list, unbroken.

    Good thing it's 12 characters long, with "random" letters and numbers, and I don;t use it for any email accounts.
    Reply
  • unksol
    9373872 said:
    There is only so much security you can implement.
    The problem is not 'weak' security.
    The problem is that there are not serious enough consequences for hacking.

    Put a 20 year minimum sentence on major attacks; put serious law enforsment resources behind finding theose guilty; and make the -short- trials VERY public. Than the rest if these idiots will get the message. You get caught... your life as you know it is over.
    Think about this from the perspective of the 6+Million accounts (not just people) affected. The amount of time lost, money lost, their worries. You are not just screwing with a 'big company'; you are screwing with the lives of Millions of people.

    This is not kiddy stuff, this is a Major Financial crime all told.
    Lock 'em up with Bubba and the gang, and loose the key.

    You do realize the internet is global, you can hop on open wifi, and this person was (probably) in Russia right?

    you can't even figure out who a hacker is unless they are an idiot let alone chase them down. nevermind that consequences don't do anything to prevent normal crime. the problem IS weak security because crime will never. ever. stop.
    Reply
  • randomizer
    You don't need to use mnemonics and you don't need to use a password made up of entirely random characters. You just need a long password that uses a large character space (ie. at least one lowercase and uppercase letter, one number and preferably one special character). "pAssw0rd1112!" is a much stronger password than ")1!#Bjt1{.#" by orders of magnitude.
    Reply
  • A Bad Day
    freggoThere is only so much security you can implement.The problem is not 'weak' security.
    Wonder why I use long complex passwords for Gmail and Yahoo Mail? Because I prefer forcing the hackers to break through those companies' security measures rather than giving them a weak password to play with.
    Reply
  • Chipi
    randoMIZERYou don't need to use mnemonics and you don't need to use a password made up of entirely random characters. You just need a long password that uses a large character space (ie. at least one lowercase and uppercase letter, one number and preferably one special character). "pAssw0rd1112!" is a much stronger password than ")1!#Bjt1{.#" by orders of magnitude.
    Notice how the word random is in in quotation marks in my sentence. That means I'm not using it literally ;)
    What I meant was that my password looks like a bunch of random letters and numbers, but it's actually a sentance in my head.

    And I never said random symbols, I said letters and numbers. Maybe you should drink your coffee first, huh...

    I'm not even gonna comment on your statement regarding the strength of those 2 passwords, it's just ridiculous :))
    Reply
  • Jerky_san
    it would seem hotmail does the same thing if you look at their login screen as its logging in... I tried to post it but it wouldn't let me.. but it appears they only use SHA1 on their stuff as well..
    Reply