Feeds

LinkedIn dials 911 on password mega-leak hackers

Biz network still silent on spate of spam

Build a business case: developing custom apps

LinkedIn has turned to the FBI for help after 6.5 million of its users' passwords were dumped online by hackers.

The business network said "a small subset" of the hashed data had been deduced and revealed, but the rest is "hard to decode". Security biz Sophos estimated that as much as 60 per cent of the leaked list had been cracked.

It is relatively trivial to work out the original passwords from the unsalted SHA-1 hashes, and LinkedIn has tacitly reiterated that it is upping its database security by sprinkling in some cryptographic salt.

The social network for suits is still silent on what other information the hackers may have lifted. It gave a somewhat slippery statement to the effect that punters' email addresses have not been revealed - as far as it knows - which doesn't answer the question of whether or not that information was stolen.

"To the best of our knowledge, no email logins associated with the passwords have been published, nor have we received any verified reports of unauthorised access to any member’s account as a result of this event," the company stated in a blog post.

Yesterday, members reported that they were being inundated with spam and phishing emails pretending to originate from LinkedIn, which would suggest that their email addresses had been stolen or that the hackers still had access to the network's databases.

LinkedIn has yet to return today's or yesterday's requests from The Register for comment on the spam. The company said on its blog that users whose passwords were leaked had had their accounts locked down for now, but also said it was going to cancel other passwords as well.

"As a precautionary measure, we are disabling the passwords of any other members that we believe could potentially be affected," it said, without giving the criteria for how LinkedIn will figure out which accounts might be in trouble.

Any members who need to come up with yet another new password will be told to do so by email, but there will be no links in the email to click - just the instructions of what to do next.

LinkedIn said it was still looking into things and was also helping law enforcement with its investigation of the breach.

Meanwhile, dating site eHarmony and music site Last.fm have also reported hack attacks in which user passwords were nicked. eHarmony users say they are being spammed as well, although again only passwords have been confirmed stolen by the site. ®

Endpoint data privacy in the cloud is easier than you think

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes, flummox firewalls
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
They're not emails, they're business records, says court
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?