LinkedIn: 'No customer accounts affected'
video.ft.com
video.ft.com
Shit happens, and we all know this. The fact that this guy is downplaying it is where I start losing respect for the company.
Yes, because security by obscurity has such an awesome track record. In fact, if whoever is responsible for this fiasco had asked on Stack Exchange how he best store passwords, this whole hoopla could've been avoided.
Security by obscurity doesn't refer to the secrets used as keys but instead to the way those keys are stored used to perform authentication.
Please elaborate on how you feel that security for linkedin would be better if they talked about the new specific security measures they've implemented.
And if it turns out that you are using a flawed solution, talking about it early will, at the very least, get people to yell at you as to what you should do instead.
In this age, the best security algorithms are usually the one most talked about. The more you test it and the more people you get to look at it and write theorems and papers about size of the search space, results from various attacks and so forth, the better.
For all we know, they've "fixed" the issue by switching to unsalted MD5 password hashes.
Even assuming that no email address has been taken, the fact that this list of passwords is now seeding rainbow tables across the world is a quite harmful, I think (and this is true irrespective of any advice to users to use unique passwords). Also, for a site as large and supposedly sophisticatd as linkedin, not using salts is inexcusable.
I have been a long time user of linkedin, and have no plans to stop using it. I certainly dont want to hang them, but an acknowledgement of mistakes are expected, otherwise declarations that it wont happen again have no weight. Disappointed.
Also they act like the file that was posted on that forum is the only information that is out there. Everything indicates those were the passwords the hacker couldn't promptly get and needed assistance for.
And as for the security measures that he "won't put on camera because that would be insecure"... wow.
Physical security works in a similar manner. You have multiple obscure parts (keys, passcodes, etc), and non-obscure parts (locks, cameras). If I have keys and passcodes, and I know where the locks are and where the cameras are, I can get through. And, it's not incredibly difficult to get a key (I have personal experience with this, hence the specific setup). What saves you is the passcode and camera that aren't known. That, and the fact that the guy was half-drunk as it was.
In the end, you don't rely on obscurity, but you don't go out of your way to tell everyone what you are doing. That's why you pay experts to do it for you.
Security by obscurity is the opposite of using private keys. The algorithms for security by public/private keypairs are published and open to anyone to see; the strength does not depend on keeping the algorithm secret.
(Worth mentioning, some public/private keypair algorithms may actually have security by obscurity built in, such as the DES algo that some people speculate has hidden backdoors in how hashes are created.)
> the strength does not depend on keeping the algorithm secret.
No, it depends on keeping something else secret.
Sounds like at least one affected customer to me...
"Please elaborate on how you feel that security for linkedin would be better if they talked about the new specific security measures they've implemented."
My feeling is that they would have a better outcome by hiring the appropriate experts rather than being public about anything regarding how they operate.
Keeping in mind of course that linkedin in particular is a mainstream site and it doesn't really matter whether hackers in particular of any type like whether they are open or not. Your thoughts? When you consult do you advise companies to publicly disclose anything (other than misinformation possibly).
Generally, I feel sad for LinkedIn, not outraged.
I would strongly dispute the words "open" and "transparent" in Hoffman's statement, though.
I think you could do a pretty good case study on how not to do security crisis PR from what happened last week. But the only parties really harmed by bad crisis PR are LinkedIn investors.
Agree but wonder why companies don't have the crash cart ready and always seem to mess this one up.
"harmed by bad crisis PR are LinkedIn investors"
My feeling is different. If people are talking about your company (and plenty has been said about this) and it's something that they've heard before many times I think the publicity is not bad and if anything could get some retail investors interested. Linkedin is not a food product and, in general, I don't think people think of linkedin like they think if they find out a product contains pink slime.
It's like WD-40. You spray it on and the carrier evaporates leaving the stuff that does the work. So the memory of linkedin remains and the knowledge of the problem is lost.
People have short memories. The brand will have a publicity gain and the negative will be forgotten.
This happens with celebrities who do bad things. They just become more famous and valuable (in that case even if people remember the bad like with Sheen). (With the exception of, say, OJ Simpson and maybe a few others such as Tiger Woods because of his squeaky clean image.)
edit: Lawyers trying to represent users were inevitable. Now they'll have shareholder lawyers too.
What a joke LinkedIn is! I wouldn't be able to stand embarrassment of a hacker-joker to send to all my connections some ads for Viagra (knowing some non-tech people would really believe I start selling Viagra), so I deleted my account.
But ain't that breath-taking that a 10 years old revenue-positive company with NASDAQ presence would not even salt password. [speechless!]
If there is a point you are making, can you elaborate?