Re: [newtech-1] LinkedIn exploit

From: Gavin Y.
Sent on: Wednesday, June 6, 2012 1:44 PM
Even salted, salt could be leaked as well...


On Wed, Jun 6, 2012 at 1:43 PM, Paul <[address removed]> wrote:
Seriously, isn't "salting" passwords Programming Security 101?

Even I do it for my small business and all of my clients and employees!

Paul C.

On Wed, Jun 6, 2012 at 10:54 AM, Ed Muller <[address removed]> wrote:
Over 6.5m LinkedIn password hashes have been posted online, exploit is probably http://blog.skycure.com/2012/06/linkedout-linkedin-privacy-issue.html due to calendar app in iOS and using unsalted SHA1 encryption http://www.theverge.com/2012/6/6/3067523/linkedin-password-leak-online.

If you are using the integrated calendar services and consider your LinkedIn account to be highly valuable, better change your PW asap.

Ed Muller

(212)[masked]
 
 
This email communication and any attachments are privileged, confidential or otherwise protected by disclosure and are intended only for the individuals or entities named above and any others who have been specifically authorized to receive it. Any unauthorized dissemination, copying or use of the contents of this email is strictly prohibited and may be in violation of law. If you are not the intended recipient, please do not read, copy, use or disclose to others the contents of this communication. Please notify the sender that you have received this e-mail in error by replying to this e-mail. Please then delete the e-mail from your system and any copies of it. (NYTE-2012)




--
Please Note: If you hit "REPLY", your message will be sent to everyone on this mailing list ([address removed])
This message was sent by Ed Muller ([address removed]) from NY Tech Meetup.
To learn more about Ed Muller, visit his/her member profile
Set my mailing list to email me As they are sent | In one daily email | Don't send me mailing list messages

Meetup, PO Box 4668 #37895 New York, New York[masked] | [address removed]





--
Please Note: If you hit "REPLY", your message will be sent to everyone on this mailing list ([address removed])
This message was sent by Paul ([address removed]) from NY Tech Meetup.
To learn more about Paul, visit his/her member profile
Set my mailing list to email me As they are sent | In one daily email | Don't send me mailing list messages

Meetup, PO Box 4668 #37895 New York, New York[masked] | [address removed]

This email message originally included an attachment.

Our Sponsors

People in this
Meetup are also in:

Sign up

Meetup members, Log in

By clicking "Sign up" or "Sign up using Facebook", you confirm that you accept our Terms of Service & Privacy Policy