Feeds

LinkedIn dials 911 on password mega-leak hackers

Biz network still silent on spate of spam

Beginner's guide to SSL certificates

LinkedIn has turned to the FBI for help after 6.5 million of its users' passwords were dumped online by hackers.

The business network said "a small subset" of the hashed data had been deduced and revealed, but the rest is "hard to decode". Security biz Sophos estimated that as much as 60 per cent of the leaked list had been cracked.

It is relatively trivial to work out the original passwords from the unsalted SHA-1 hashes, and LinkedIn has tacitly reiterated that it is upping its database security by sprinkling in some cryptographic salt.

The social network for suits is still silent on what other information the hackers may have lifted. It gave a somewhat slippery statement to the effect that punters' email addresses have not been revealed - as far as it knows - which doesn't answer the question of whether or not that information was stolen.

"To the best of our knowledge, no email logins associated with the passwords have been published, nor have we received any verified reports of unauthorised access to any member’s account as a result of this event," the company stated in a blog post.

Yesterday, members reported that they were being inundated with spam and phishing emails pretending to originate from LinkedIn, which would suggest that their email addresses had been stolen or that the hackers still had access to the network's databases.

LinkedIn has yet to return today's or yesterday's requests from The Register for comment on the spam. The company said on its blog that users whose passwords were leaked had had their accounts locked down for now, but also said it was going to cancel other passwords as well.

"As a precautionary measure, we are disabling the passwords of any other members that we believe could potentially be affected," it said, without giving the criteria for how LinkedIn will figure out which accounts might be in trouble.

Any members who need to come up with yet another new password will be told to do so by email, but there will be no links in the email to click - just the instructions of what to do next.

LinkedIn said it was still looking into things and was also helping law enforcement with its investigation of the breach.

Meanwhile, dating site eHarmony and music site Last.fm have also reported hack attacks in which user passwords were nicked. eHarmony users say they are being spammed as well, although again only passwords have been confirmed stolen by the site. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.