jsteele
Post 06/08/2012 16:00     Subject: Re:LinkedIn Hacked

Anonymous wrote:OP here, this came from my very vigiliant IT department at work. They would NEVER ask me to enter a password in an unsecure site.


Feel free to enter your password wherever you want. I just explained why I wouldn't do it. Your IT department didn't care that you entered your password in LinkedIn and look where that got you.
Anonymous
Post 06/08/2012 15:40     Subject: Re:LinkedIn Hacked


Anonymous wrote:Check your account and reset your password, apparently they were hacked and almost 7 million passwords were stolen. The passwords have been posted on the internet. If your password was one of the ones stolen, you should immediately change the password Here is a web page that will tell you if your password was one of those posted online: https://lastpass.com/linkedin/. It is safe to enter your password there




I would never enter a password there. In fact, that seems like a scam. The LinkedIn passwords are hashed. Hashes are not reversible. So, hackers hash known lists of words and compare the known and unknown hashes for matches. If everyone enters unhashed passwords into that form, they are just building a list to help find matched hashes and, hence, expose passwords.


OP here, this came from my very vigiliant IT department at work. They would NEVER ask me to enter a password in an unsecure site.
Anonymous
Post 06/08/2012 14:32     Subject: LinkedIn Hacked

Then again maybe it's bad to train the users to do this. There is another site that lets you post your own sha-1 hash.

Btw boo! To LinkedIn for not salting their hashes. Bad bad bad.
Anonymous
Post 06/08/2012 14:30     Subject: LinkedIn Hacked

True but
Anonymous
Post 06/08/2012 14:30     Subject: LinkedIn Hacked

jsteele wrote:
Anonymous wrote:If you used the same password anywhere else, you have to change that too.

And they are building rainbow tables with the data, so if it's a password you think someone else may have used (like something common) you have to redo those too.


Building rainbow tables takes a lot of time and computer resources. Here's a better idea: set up a web page and tell people just to enter their passwords.
Trubut view source on the page and you will see they only post the hash.
jsteele
Post 06/08/2012 14:25     Subject: LinkedIn Hacked

Anonymous wrote:If you used the same password anywhere else, you have to change that too.

And they are building rainbow tables with the data, so if it's a password you think someone else may have used (like something common) you have to redo those too.


Building rainbow tables takes a lot of time and computer resources. Here's a better idea: set up a web page and tell people just to enter their passwords.
Anonymous
Post 06/08/2012 14:00     Subject: Re:LinkedIn Hacked

I got an email today but assumed it was spam. What exactly would whoever hacked the passwords do with them? My linked in profile is open anyway. I suppose they could change my work experience but that doesn't seem very productive. I dont have any credit card or other info on linked in.
jsteele
Post 06/08/2012 13:49     Subject: LinkedIn Hacked

Anonymous wrote:Check your account and reset your password, apparently they were hacked and almost 7 million passwords were stolen. The passwords have been posted on the internet. If your password was one of the ones stolen, you should immediately change the password Here is a web page that will tell you if your password was one of those posted online: https://lastpass.com/linkedin/. It is safe to enter your password there



I would never enter a password there. In fact, that seems like a scam. The LinkedIn passwords are hashed. Hashes are not reversible. So, hackers hash known lists of words and compare the known and unknown hashes for matches. If everyone enters unhashed passwords into that form, they are just building a list to help find matched hashes and, hence, expose passwords.
Anonymous
Post 06/08/2012 13:13     Subject: LinkedIn Hacked

If you used the same password anywhere else, you have to change that too.

And they are building rainbow tables with the data, so if it's a password you think someone else may have used (like something common) you have to redo those too.
Anonymous
Post 06/08/2012 12:43     Subject: LinkedIn Hacked

and if you used that same password other places....
Anonymous
Post 06/08/2012 12:38     Subject: LinkedIn Hacked

Thanks! Linked in will also prompt you to change your password if you try to log in.
Anonymous
Post 06/08/2012 11:32     Subject: LinkedIn Hacked

Check your account and reset your password, apparently they were hacked and almost 7 million passwords were stolen. The passwords have been posted on the internet. If your password was one of the ones stolen, you should immediately change the password Here is a web page that will tell you if your password was one of those posted online: https://lastpass.com/linkedin/. It is safe to enter your password there