"In the worst case your LinkedIn account may be compromised. You will have to weigh this against the convenience of not having to log in to LinkedIn."
This doesn't convince me.
The use of the word rederive sounds like it may be encrypted to me.
So yes, they can and most likely do encrypt it in some way, but in order for their server to be able to decrypt it when using it, they must naturally have to have the decryption code/passkey/etc stored on the server.