meta_pixel
Tapesearch Logo
Log in
Malicious Life

What The LinkedIn Hack Taught Us About Storing Passwords

Malicious Life

Malicious Life

Technology

4.81K Ratings

🗓️ 24 May 2022

⏱️ 30 minutes

🧾️ Download transcript

Summary

What The LinkedIn Hack Taught Us About Storing Passwords



Advertising Inquiries: https://redcircle.com/brands

Transcript

Click on a timestamp to play from that location

0:00.0

Hi and welcome to Sabir reasons malicious life. I'm Ren Levy. On June 2012, 2012, an anonymous hacker posted a list of 6.5 million encrypted passwords on a Russian hacker forum.

0:27.2

They were posted there apparently to crowdsource the cracking process.

0:31.8

Members of this forum, who obviously had a lot of experience dealing with hacking and

0:37.2

passwords, played around with the published passwords and cracked some of them. They discovered that many of the cracked passwords contained

0:46.0

the word linked him. Since many people used the name of the website they're registering

0:51.5

to as part of their chosen password, not a good idea obviously,

0:56.7

many hackers suspected that the posted passwords were related to LinkedIn.

1:07.0

A few days after the reveal of the alleged passwords leak, LinkedIn tweeted, quote,

1:09.0

Our team continues to investigate,

1:12.0

but at this time we're still unable to confirm that any security

1:17.0

breach has occurred.

1:19.2

Stay tuned here.

1:20.2

End quote.

1:21.2

However, in a post on their blog on the very same day and concerning the same alleged

1:27.6

incident, LinkedIn representatives already changed the language.

1:33.0

It is worth noting that the affected members who update their passwords and members whose

1:39.5

passwords have not been compromised benefit from the enhanced security we just recently put in place,

1:47.0

which includes hashing and salting of our current password databases." End quote.

1:53.0

That was at least some kind of recognition on the part of LinkedIn

1:58.0

that password protection measures needed to be improved.

2:05.0

Following the attack, two lawsuits were filed against LinkedIn,

2:10.0

one in June 2012 and the other in November of the same year.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from Malicious Life, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Malicious Life and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.