Security Management
Published on Security Management (http://www.securitymanagement.com)
LinkedIn Had Strengthened Protection of Leaked Passwords
By John Wagley
Created 06/14/2012 - 21:01



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
Yes
Date: 
06/15/2012
By Line: 
By John Wagley
Teaser: 

By the time it became news that 6.5 million passwords from the Website LinkedIn had been posted on a hacker Web site last week, the Internet Company had “salted” all its passwords, making them significantly more difficult to crack, according to LinkedIn.

By the time it became news that 6.5 million passwords from LinkedIn had been posted on a hacker Web site last week [1], the Internet company had “salted” all its passwords, making them significantly more difficult to crack, according to LinkedIn.

In a blog post [2], the company also described how it was not aware of any improper access to accounts resulting from the breach. It also described some of the steps it took to quickly protect users’ privacy.

Compromised passwords were not published with corresponding e-mail log-ins, according to the post, written by director Vicente Silveira. When published, the “vast majority” of passwords were hashed, or encoded, but a subset of the passwords was not.

The company said that it had disabled “all member passwords that we believe to be at risk.” Such members were sent e-mails, asking them to reset their passwords. The company added that for members who had not had their passwords disabled, “we do not believe your account is at risk.”

The company also said that by the time news broke about the breach, all member passwords had been “salted,” a technique that increases the computer time needed to crack an encrypted password. An initiative had already been underway to transition from just hashing passwords, to hashing and salting them, the post said.

LinkedIn didn’t say how the passwords were hacked [3]. But it said it was working with investigators. “We take this criminal activity very seriously so we are working closely with the FBI as they aggressively pursue the perpetrators of this crime.”

Additional security enhancements to the site are planned, the post said, though it didn’t describe what those enhancements might be.


photo by smi23le/flickr [4]

Related Resources: 
Thumbnail: 

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/linkedin-had-strengthened-protection-leaked-passwords-009985

Links:
[1] http://www.securitymanagement.com/news/millions-passwords-lost-linkedin-breach-009951
[2] http://blog.linkedin.com/2012/06/09/an-update-on-taking-steps-to-protect-our-members/
[3] http://www.securitymanagement.com/news/how-easy-it-get-your-password-stolen-online-009954
[4] http://www.flickr.com/photos/smi23le/4613342990/