Feeds

LinkedIn faces class action suit over password leak

People can take data from us, but not money

Reducing the cost and complexity of web vulnerability management

LinkedIn is facing a class action suit over the security breach that saw millions of users' passwords posted online.

Illinois resident Katie Szpyrka leads the complaint, which alleges that LinkedIn failed to "properly safeguard its users' personally identifiable information".

The complaint filed in California accuses the business network of using a "weak encryption format" for users' information and not having crucial security measures in place.

A LinkedIn spokesperson told The Register that the class action suit's claims were "without merit".

"No member account has been breached as a result of the incident, and we have no reason to believe that any LinkedIn member has been injured," the company said. "Therefore, it appears that these threats are driven by lawyers looking to take advantage of the situation.

"We believe these claims are without merit, and we will defend the company vigorously against suits trying to leverage third-party criminal behaviour."

The 6.5 million user passwords hacked and posted online were in hashed format, but the biz site evidently had not applied any salts. Salting adds extra arbitrary data to a password when it is hashed, thwarting pre-generated tables and making life more difficult for password crackers. The class action suit claims that hashing without salting is not an "industry standard protocol" as promised by LinkedIn's privacy policy.

"Despite its contractual obligation to use best practices in storing user data, LinkedIn failed to utilise basic industry standard encryption methods. In particular, LinkedIn failed to adequately protect user data because it stored passwords in unsalted SHA1 hashed format," the filing said, branding SHA1 "outdated".

The case also latches on to reports that LinkedIn was hacked through an SQL injection attack, which uses weaknesses in a company's website to get into its back-end systems.

"If true, LinkedIn's failure to adequately protect its website against SQL injection attacks - in conjunction with improperly securing its users' personally identifiable information - would demonstrate that the company employed a troubling lack of security measures," the complaint said.

Naturally, the class action suit is looking for attorney fees and damages for US members of LinkedIn. ®

Security and trust: The backbone of doing business over the internet

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
JINGS! Microsoft Bing called Scots indyref RIGHT!
Redmond sporran metrics get one in the ten ring
Driving with an Apple Watch could land you with a £100 FINE
Bad news for tech-addicted fanbois behind the wheel
Murdoch to Europe: Inflict MORE PAIN on Google, please
'Platform for piracy' must be punished, or it'll kill us in FIVE YEARS
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
Sony says year's losses will be FOUR TIMES DEEPER than thought
Losses of more than $2 BILLION loom over troubled Japanese corp
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.