
LinkedIn security breach: What’s your password?
0Posted on 7th Jun 2012 by Jennifer Dean
Another major breach was announced in our social media world today. This time LinkedIn was the target and more than six million users are the potential victims. A Russian hacker claims the theft of 6,458,020 encrypted LinkedIn passwords and to prove it, posted the passwords on his website (thankfully without usernames). In addition, he asked for fellow hackers to come forward and help decode the hash protected passwords.
Hackers can quickly work their way through a list and with the help of look up tables and rainbow tables, can crack approximately 40 percent of the hashes in the first day of the breach. The passwords did not contain “salt”, which is supposed to render these types of tables useless and, as I’m writing this, more than 60 percent of the stolen passwords have already been cracked.
“Why should I care if my social media account is hacked?” you may ask. Well, a whole host of bad things can come from a stolen account, even if it is for a site hosting your dusty resumé. Depending on what the hacker is able to obtain, your email address can be sold, your account spoofed, or hackers can even use news of the attack to send you a phishing email with a link to reset your password—a link to no good—downloading malware onto your system.

We’re all guilty of laziness and unfortunately it can come back to bite us financially in a situation like this. We’ve blogged many times about the risks of weak passwords and how the majority of people don’t put much thought into choosing a password. In fact, the most common password is “password!”
Today’s breach is a chance for us to take a step back and think about our online presence and stand up to the untold number of hackers across the world who are trying to steal our identities. Here are five simple questions to ask yourself. Each question to which you answer YES should be a red flag about your online safety.
- Do you use personal information in your password?
- Do you use words that can be found in the dictionary?
- Do you use the same password for most or all of your accounts?
- Are your passwords less than eight characters in length?
- Are most of your passwords all letters or all numbers? No mix of special characters, upper case and lowercase?
Granted, it’s hard to keep up with so many different passwords, but there are techniques for remembering your secure passwords, or secure passphrases. Here’s a great video from Sophos security guru Graham Cluley that may help you pick a stronger password structure.
Safe surfing everyone!
Contact: Jennifer Dean
-
Tags
Apple authentication biometric BYOD CES 2012 CIO cloud convenience cybercrime data data breach digital digital security eBanking EMV enterprise Facebook FFIEC fraud Gaming Gemalto Google hack hacker hackers hacking identity internet IT security LinkedIn malware Microsoft mobile multi-factor authentication NFC one-time password online banking OTP password passwords PIN policy research risk security smartphone strong authentication token Twitter two-factor authentication
-
Around the site
Recent Posts- CTIA E-Tech Awards 2013: With M2M, Smaller and Smarter is Better - 17/05/13 @ 05:03
- Mobile Marketing and the ubiquitous Text Message - 16/05/13 @ 10:26
- Moving Forward on the Path to NFC Adoption - 15/05/13 @ 02:48
- NFC – Not For Commerce? - 14/05/13 @ 10:49
- Sir Alex Ferguson’s legacy for CIOs - 14/05/13 @ 07:01
Recent Comments- I agree with digital ID certification. As a police... - 08/05/13 @ 07:43
- Can't wait for the driverless car. Wouldn't want to... - 29/04/13 @ 06:25
- Yes Reena, I fully understand your worries. Regardi... - 16/03/13 @ 12:11
- Thank you Monika for bringing to light a very impor... - 15/03/13 @ 09:52
- Hi, I wonder which "machines" are networked at McDo... - 28/01/13 @ 11:19
-
Twitter
-
Blogroll
- Amrit Williams Blog
- HIT Consultant
- Independent Identity
- Joey Muniz – The Security Blogger
- Kantara Initiative
- Kim Cameron's Identity Blog
- Krebs on Security
- Life as a Healthcare CIO
- Michael N. Dundas
- Naked Security
- Network Security Blog
- SC Magazine Security Cats
- Schneier on Security
- Security Nirvana
- Social Tech Editor™
- TechMarket Editor™
- Virginia Benedict, Managing Curator, Network Monitoring & Incident Response™ SIG
