Yes, because security by obscurity has such an awesome track record. In fact, if whoever is responsible for this fiasco had asked on Stack Exchange how he best store passwords, this whole hoopla could've been avoided.
Yes, because security by obscurity has such an awesome track record. In fact, if whoever is responsible for this fiasco had asked on Stack Exchange how he best store passwords, this whole hoopla could've been avoided.
Security by obscurity doesn't refer to the secrets used as keys but instead to the way those keys are stored used to perform authentication.
Please elaborate on how you feel that security for linkedin would be better if they talked about the new specific security measures they've implemented.
And if it turns out that you are using a flawed solution, talking about it early will, at the very least, get people to yell at you as to what you should do instead.
In this age, the best security algorithms are usually the one most talked about. The more you test it and the more people you get to look at it and write theorems and papers about size of the search space, results from various attacks and so forth, the better.
For all we know, they've "fixed" the issue by switching to unsalted MD5 password hashes.