Millions of LinkedIn passwords reportedly leaked online

I came across this today and thought I would warn everyone

Millions of LinkedIn passwords reportedly leaked online

by Lance Whiney

LinkedIn users could be facing yet another security problem. A user in a Russian forum says that he has hacked and uploaded almost 6.5 million LinkedIn passwords, according to The Verge. Though his claim has yet to be confirmed, Twitter users are already reporting that they’ve found their hashed LinkedIn passwords on the list, security expert Per Thorsheim said.

LinkedIn revealed through its own tweet that it’s looking into reports of stolen passwords, and it advised users to stay tuned for more information. Many of the hashes include the word “linkedin,” which The Verge believes lends credibility to the reports. LinkedIn passwords are encrypted using an algorithm known as SHA-1, which is considered very secure. Complex passwords will likely take some time to decrypt, but simple ones may be at risk.

Sophos security expert Graham Cluley is advising LinkedIn users to change their passwords as soon as possible, at least as a precaution. If the report is true, then hackers are undoubtedly working hard to decrypt the hashed, or unsalted, passwords.

“Although the data which has been released so far does not include associated email addresses, it is reasonable to assume that such information may be in the hands of the criminals,” Cluley added.

The report of the leaked passwords comes hard on the heels of word from security researchers that LinkedIn’s iOS app is collecting information from calendar entries — including passwords — and transmitting it back to the company’s servers without users’ knowledge.

In response to concerns over this collection of data, LinkedIn yesterday tried to explain how and why it captures this information. The company acknowledged that it picks up information from the Calendar app on your iOS device to try to sync any appointments listed with fellow LinkedIn users. The feature is opt-in, so users of the LinkedIn IOS app can turn off the ability to “Add Calendar” in the Settings screen.

The details sent to LinkedIn’s server include the e-mail addresses of the people you meet with, the meeting subject, the location, and any meeting notes. The calendar data is sent securely using SSL encryption and isn’t shared or stored, LinkedIn added.

But in a concession to concerned users, the company has promised two tweaks to the feature. It will no longer pick up meeting notes from your calendar. And it will add a “learn more” link to explain how your calendar data is being used.

LinkedIn did not address the question of whether passwords are being collected along with the meeting information.

To change your LinkedIn password, log onto your account. Click on your name in the upper right corner and then click on the link for Settings. In the Settings section, click on the Change link next to Password. You’ll be prompted to to enter your old password and then create a new one. Aim to pick a complex password that’s not easy to decipher. Then click on the Change Password button.

CNET contacted LinkedIn for further details and will update the story when we get more information.

Here is the url to the acutal story

http://news.cnet.com/8301-1009_3-57448079-83/millions-of-linkedin-passwords-reportedly-leaked-online/?tag=mncol;editorPicks

Back

What Clients Say About Patrice & Associates

  • Ed Liedke is amazing to work with! 

    He asked questions about my career preferences to find me the best opportunity out there.  Ed Leidke provided the best practices to guide me through the hiring process and nail the interviews.  I would definitely encourage others to utilize his expertise to find the career of their dreams.              

    Thank you Ed!

    Dusty

    Ed Liedke is amazing to work with! 
  • Ed Carroll was an absolute JOY to work with! 

    Our initial call was extremely casual which made me so much more comfortable talking with him.  He stayed in touch and updated me for every step of the hiring process.  He placed me with a company that is a great fit for both parties.  I could not have asked for a better experience!      

    Thank you, Ed and Patrice and Associates!

    Beyond Thankful,

    Rebecca M.

    Ed Carroll was an absolute JOY to work with!
  • Jobs & Recruitment News - Patrice & AssociatesPradnya Kulkarni was a pleasure to work with 

    She was very patient with me and always very informative.  She always seemed to be in great spirits when I talked to her on the phone witch encouraged me to keep going.  She did such an awesome job!  Highly recommend.

     

    Many thanks,

    Henry T.

    Pradnya Kulkarni was a pleasure to work with
  • Working along with Carlie Knauer was a pleasure! 

    Carlie was always very helpful in assisting with finding my new current job! She is a hard working professional that maintained contact with me throughout the entire process and provided me great guidance all together.  Thank you, Carlie!    

    Kind regards, Isabella

  • Bruce Leininger is TOP NOTCH! 

    He is nothing short of a true asset to Patrice & Associates!  Your company should clone him!!    

    Thank you

    Dave Morrison

    Bruce Leininger is TOP NOTCH!