Millions of LinkedIn passwords reportedly leaked online

I came across this today and thought I would warn everyone

Millions of LinkedIn passwords reportedly leaked online

by Lance Whiney

LinkedIn users could be facing yet another security problem. A user in a Russian forum says that he has hacked and uploaded almost 6.5 million LinkedIn passwords, according to The Verge. Though his claim has yet to be confirmed, Twitter users are already reporting that they’ve found their hashed LinkedIn passwords on the list, security expert Per Thorsheim said.

LinkedIn revealed through its own tweet that it’s looking into reports of stolen passwords, and it advised users to stay tuned for more information. Many of the hashes include the word “linkedin,” which The Verge believes lends credibility to the reports. LinkedIn passwords are encrypted using an algorithm known as SHA-1, which is considered very secure. Complex passwords will likely take some time to decrypt, but simple ones may be at risk.

Sophos security expert Graham Cluley is advising LinkedIn users to change their passwords as soon as possible, at least as a precaution. If the report is true, then hackers are undoubtedly working hard to decrypt the hashed, or unsalted, passwords.

“Although the data which has been released so far does not include associated email addresses, it is reasonable to assume that such information may be in the hands of the criminals,” Cluley added.

The report of the leaked passwords comes hard on the heels of word from security researchers that LinkedIn’s iOS app is collecting information from calendar entries — including passwords — and transmitting it back to the company’s servers without users’ knowledge.

In response to concerns over this collection of data, LinkedIn yesterday tried to explain how and why it captures this information. The company acknowledged that it picks up information from the Calendar app on your iOS device to try to sync any appointments listed with fellow LinkedIn users. The feature is opt-in, so users of the LinkedIn IOS app can turn off the ability to “Add Calendar” in the Settings screen.

The details sent to LinkedIn’s server include the e-mail addresses of the people you meet with, the meeting subject, the location, and any meeting notes. The calendar data is sent securely using SSL encryption and isn’t shared or stored, LinkedIn added.

But in a concession to concerned users, the company has promised two tweaks to the feature. It will no longer pick up meeting notes from your calendar. And it will add a “learn more” link to explain how your calendar data is being used.

LinkedIn did not address the question of whether passwords are being collected along with the meeting information.

To change your LinkedIn password, log onto your account. Click on your name in the upper right corner and then click on the link for Settings. In the Settings section, click on the Change link next to Password. You’ll be prompted to to enter your old password and then create a new one. Aim to pick a complex password that’s not easy to decipher. Then click on the Change Password button.

CNET contacted LinkedIn for further details and will update the story when we get more information.

Here is the url to the acutal story

http://news.cnet.com/8301-1009_3-57448079-83/millions-of-linkedin-passwords-reportedly-leaked-online/?tag=mncol;editorPicks

Back

What Clients Say About Patrice & Associates

  • Thanks Again!

    Bartol starts on Wednesday! Thanks for again turning over all the rocks for us. - FH Client  Thanks Again!
  • Amy is genuine, honest and has a passion for what she does.

    Amy contacted me in a time where I was unhappy where I was but wasn’t doing anything to change it. She was very informative and if she didn’t have the information at hand, she got it. She revamped an old resume making it more about achievements than responsibilities. She coached me on interview tactics before multiple interviews and was there to talk about them afterwards. Every conversation we had felt more like a friendship than business. She is genuine, honest and has a passion for what she does. She also helped boost my confidence through the entire interview progress. Whatever she is doing, she must be doing it right because I got the job! Thanks Amy for a life changing experience.
    Sincerely,
    Shawn Ware
    Amy is genuine, honest and has a passion for what she does.
  • I really appreciate Tim for all his handwork and consistency.

    He saw a lot of potential in me which allowed me to apply for a higher position than I had first intended. Although the process wasn't easy he was still very honest and trustworthy. I am very grateful to have received his guidance. I really appreciate Tim for all his handwork and consistency.
  • I want to thank Tim...

    ...for all the time he spent helping me acquire my new career. He has helped by assisting me with redesigning my resume and keeping in contact with me throughout the entire process.  His actions showed that he really cared and wanted the best for me. Thanks again, Dominic Almanza I want to thank Tim
  • I would 100% recommend Ross

    I cannot begin to thank Ross and Karen enough! without the two of them I wouldn't have even known about the position! The interview process was quick, easy and simple. After only a short week I was in a position I knew I was going to love forever and it was all thanks to them! Ross has been so good about following up with me even after being hired, asking how my experience has been, what hours I'm working etc. and to top it all off Ross even sent me a gift card thanking me for working with him. I would 100% recommend Ross to anyone looking for a career in the industry!
    Cheers,
    Bayley Ferreira
    I would 100% recommend Ross