Millions of LinkedIn passwords reportedly leaked online

I came across this today and thought I would warn everyone

Millions of LinkedIn passwords reportedly leaked online

by Lance Whiney

LinkedIn users could be facing yet another security problem. A user in a Russian forum says that he has hacked and uploaded almost 6.5 million LinkedIn passwords, according to The Verge. Though his claim has yet to be confirmed, Twitter users are already reporting that they’ve found their hashed LinkedIn passwords on the list, security expert Per Thorsheim said.

LinkedIn revealed through its own tweet that it’s looking into reports of stolen passwords, and it advised users to stay tuned for more information. Many of the hashes include the word “linkedin,” which The Verge believes lends credibility to the reports. LinkedIn passwords are encrypted using an algorithm known as SHA-1, which is considered very secure. Complex passwords will likely take some time to decrypt, but simple ones may be at risk.

Sophos security expert Graham Cluley is advising LinkedIn users to change their passwords as soon as possible, at least as a precaution. If the report is true, then hackers are undoubtedly working hard to decrypt the hashed, or unsalted, passwords.

“Although the data which has been released so far does not include associated email addresses, it is reasonable to assume that such information may be in the hands of the criminals,” Cluley added.

The report of the leaked passwords comes hard on the heels of word from security researchers that LinkedIn’s iOS app is collecting information from calendar entries — including passwords — and transmitting it back to the company’s servers without users’ knowledge.

In response to concerns over this collection of data, LinkedIn yesterday tried to explain how and why it captures this information. The company acknowledged that it picks up information from the Calendar app on your iOS device to try to sync any appointments listed with fellow LinkedIn users. The feature is opt-in, so users of the LinkedIn IOS app can turn off the ability to “Add Calendar” in the Settings screen.

The details sent to LinkedIn’s server include the e-mail addresses of the people you meet with, the meeting subject, the location, and any meeting notes. The calendar data is sent securely using SSL encryption and isn’t shared or stored, LinkedIn added.

But in a concession to concerned users, the company has promised two tweaks to the feature. It will no longer pick up meeting notes from your calendar. And it will add a “learn more” link to explain how your calendar data is being used.

LinkedIn did not address the question of whether passwords are being collected along with the meeting information.

To change your LinkedIn password, log onto your account. Click on your name in the upper right corner and then click on the link for Settings. In the Settings section, click on the Change link next to Password. You’ll be prompted to to enter your old password and then create a new one. Aim to pick a complex password that’s not easy to decipher. Then click on the Change Password button.

CNET contacted LinkedIn for further details and will update the story when we get more information.

Here is the url to the acutal story

http://news.cnet.com/8301-1009_3-57448079-83/millions-of-linkedin-passwords-reportedly-leaked-online/?tag=mncol;editorPicks

Back

What Clients Say About Patrice & Associates

  • Francisco Chevez is one in a million!

    I would like to formally thank Francisco Chevez for helping me get this great District Manager position. Francisco was very professional from the beginning. He was persistent in his search for the perfect opportunity. He presented me with multiple job opportunities, all great. He made me feel as if I was his only client and his top priority. Even after starting the new job, he called back to check on me. Francisco is great at what he does and I’m glad I was paired with him.      

    Sincerely,

    Enzo Mera

    Francisco Chevez is one in a million!
  • Matt Lopez nailed it!

    I am thankful for the service that Matt Lopez provided on behalf of Patrice and Associates in finding me and matching me to an excellent job with an energy company in northern Virginia. Matt Lopez discussed the position and the company and advised me on the hiring process. Matt has the intuition to assess me the job candidate, and the employer regarding my personality and the corporate culture to make the match. Matt found a Company that has all the attributes that I have struggled over the past few years to find. I intend to do an excellent job for the Company that I am joining in October 2022. I plan to achieve my immediate objectives, the company’s goals and show that Patrice and Associated backed the right person for the job.                    

    Sincerely,

    Robert Chew

    Matt Lopez nailed it!
  • I can't thank Karl Busch enough!

    I recently relocated to South Carolina from New York.  At first I tried the usual big company name job search engines, I even reached out to a couple of recruiters but, Karl Busch at Patrice and Associates was the guy who got it done!  His guidance and advice along the way was invaluable.  I was able to secure an Executive Chef position at a high profile restaurant thanks to him.          

    Thank you!

    Steven D.

    I can't thank Karl Busch enough!
  • Shawn Hoye was great to work with.

    Super attentive with plenty insight into the local job market which gave me a leg up in making the perfect career move.              

    Many Thanks,

    Sean Giffing

    Shawn Hoye was great to work with!
  • Whitney Davis was incredible!

    I would just like to say what an asset Whitney Davis was in regards to me finding another job. I appreciate all the help and I would definitely recommend him to others.        

    Thank you!

    Larry A.

    Whitney Davis was incredible!