Pakistanis angry over detentions in Times Sq. case Monday, May 24, 2010
ISLAMABAD – Relatives of three men detained by Pakistan for alleged links to the suspect in the attempted Times Square bombing say the men are innocent.
They
AFP - Thursday, August 6TAIPEI (AFP) - - Taiwan's Beijing-friendly government on Wednesday denied boycotting an Australian film festival amid a row over the e
BERLIN (Reuters) - Chancellor Angela Merkel suffered a double blow on Thursday as a senior party ally in east German
Minister seeks closure of anti-Berlusconi websites Wednesday, December 16, 2009
ROME (AFP) - – The Italian government moved Tuesday to close down Internet sites encouraging further violence against Prime Minister Silvio Berlusconi, who
By ELAINE KURTENBACH,AP Business Writer AP - Wednesday, March 18SHANGHAI - Asia's stock market rally seemed to be running out of steam Wednesday, despite an
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Home
Business
Business Home
Economy
Technology
Media
Small Business
Legal
Deals
Earnings
Social Pulse
Business Video
The Freeland File
Markets
Markets Home
U.S. Markets
European Markets
Asian Markets
Global Market Data
Indices
M&A
Stocks
Bonds
Currencies
Commodities
Futures
Funds
peHUB
World
World Home
U.S.
Brazil
China
Euro Zone
Japan
Mexico
Russia
India Insight
World Video
Reuters Investigates
Decoder
Politics
Politics Home
Election 2012
Tales from the Trail
Political Punchlines
Supreme Court
Politics Video
Tech
Technology Home
MediaFile
Science
Tech Video
Tech Tonic
Social Pulse
Opinion
Opinion Home
Chrystia Freeland
John Lloyd
Felix Salmon
Jack Shafer
David Rohde
Bernd Debusmann
Nader Mousavizadeh
Lucy P. Marcus
David Cay Johnston
Bethany McLean
Edward Hadas
Hugo Dixon
Ian Bremmer
Lawrence Summers
Susan Glasser
The Great Debate
Steven Brill
Jack & Suzy Welch
Frederick Kempe
Christopher Papagianis
Breakingviews
Equities
Credit
Private Equity
M&A
Macro & Markets
Politics
Breakingviews Video
Money
Money Home
Tax Break
Lipper Awards 2012
Global Investing
MuniLand
Unstructured Finance
Linda Stern
Mark Miller
John Wasik
James Saft
Analyst Research
Alerts
Watchlist
Portfolio
Stock Screener
Fund Screener
Personal Finance Video
Money Clip
Investing 201
Life
Health
Sports
Arts
Faithworld
Business Traveler
Entertainment
Oddly Enough
Lifestyle Video
Pictures
Pictures Home
Reuters Photographers
Full Focus
Video
Reuters TV
Reuters News
Article
Comments (0)
Slideshow
Counterparties: Today's Best Links
Children suffer under Spain's austerity
At a time when its bailing out its banking sector, Spain is cutting crucial medical services for disabled children, Bloomberg reports. Read more at Counterparties
Greece is quickly running out of money
The IPO where "nothing could go wrong"
Sign up for the Counterparties newsletter!
Follow Reuters
Facebook
Twitter
RSS
YouTube
Read
Mexican presidency front-runner's image used to promote adultery
06 Jun 2012
LinkedIn, eHarmony suffer data breaches
12:36am EDT
Untreatable gonorrhoea spreading around world: WHO
06 Jun 2012
Republicans attack Obama over glitzy fundraisers
06 Jun 2012
Exclusive: Drones "inhumane", dead al Qaeda man's family says
06 Jun 2012
Discussed
353
NY mayor blasts sugar ban critics: ”That’s a lot of soda”
280
Louisiana’s bold bid to privatize schools
277
Florida to continue voter purge in defiance of warning
Watched
NASA delivers high-def view of Venus transit
Wed, Jun 6 2012
Supersonic mini-drone aims for jet speed record
Tue, Jun 5 2012
A look at the UK’s most beautiful face
Thu, May 10 2012
Pictures
Reuters Photojournalism
Our day's top images, in-depth photo essays and offbeat slices of life. See the best of Reuters photography. See more | Photo caption
Enterprise in NY
The Enterprise shuttle floats by Manhattan. Slideshow
D-Day: A look back
Images from the Allied landings at Normandy. Slideshow
LinkedIn, eHarmony suffer data breaches
Tweet
Share this
Email
Print
Related News
LinkedIn suffers data breach
Wed, Jun 6 2012
REFILE-Security experts say LinkedIn suffered data breach
Wed, Jun 6 2012
Flame exploits Windows bug to attack PCs
Mon, Jun 4 2012
UN agency plans major warning on Flame virus risk
Tue, May 29 2012
Facebook prices at top of range in landmark IPO
Thu, May 17 2012
Analysis & Opinion
Silicon Valley hubris watch, TJ Rodgers edition
IA brief: State regulator’s deficiency letter offers clues for social-media policies
Related Topics
Tech »
Media »
1 of 2. A banner announcing Linkedin Inc. listing on the New York Stock Exchange hangs on the face of the building in New York, May 19, 2011.
Credit: Reuters/Mike Segar
By Jim Finkle and Jennifer Saba
BOSTON/NEW YORK |
Thu Jun 7, 2012 12:36am EDT
BOSTON/NEW YORK (Reuters) - Social networking site LinkedIn and online dating service eHarmony warned that some user passwords had been breached after security experts discovered scrambled files with passwords for millions of online accounts.
The two companies declined to say how many accounts had been breached when they disclosed the breaches in statements issued on Wednesday.
They only said they were conducting investigations.
The breaches are the latest in a string of high-profile attacks around the world that have put personal information of millions at risk. The release of information stolen from the intelligence analysis firm Stratfor in December included data belonging to former U.S. Vice President Dan Quayle and former Secretary of State Henry Kissinger.
Mary Landesman, senior researcher with messaging security firm Cloudmark, said that a hacker who has access to somebody's LinkedIn credentials along with their eHarmony account might be in a good position to commit extortion.
"When somebody has the keys to your business and personal kingdom, that gives them all sorts of powerful information," she said. "They might be able to use it for years."
The technology news site Ars Technica reported on Wednesday that a total of 8 million encrypted passwords were published on underground forums by a hacker known as 'dwdm', who was seeking help unscrambling them.
It was not clear whether all 8 million of the passwords belonged to users of LinkedIn and eHarmony, or if the hacker had stolen an even larger number of credentials and just posted some of them on the site.
LinkedIn, which made its stock debut last year, is a social media company that caters to companies seeking employees and people scouting for jobs. It has more than 161 million members worldwide. One of the Mountain View, California-based company's main initiatives is to grow internationally - 61 percent of its membership is located outside the United States.
Santa Monica-based eHarmony, which has more than 20 million registered online users, said in a blog post that it has reset affected members passwords. The company said those members will receive an email with instructions on how to reset their passwords.
Marcus Carey, security researcher at Boston-based Rapid7, said he believed the attackers had been inside LinkedIn's network for at least several days, based on an analysis of the type of information stolen and quantity of data posted on forums.
"While LinkedIn is investigating the breach, the attackers may still have access to the system," Carey warned. "If the attackers are still entrenched in the network, then users who have already changed their passwords may have to do so a second time."
The files included only passwords and not corresponding email addresses, which means that people who download the files and decrypt, or unscramble, the passwords will not easily be able to access any accounts with compromised passwords.
Yet analysts said it is likely that the hackers who stole the passwords also have the corresponding email addresses and would be able to access the accounts.
NEEDS MORE SALT?
At least two security experts who examined the files containing the LinkedIn passwords said the company had failed to use best practices for protecting the data.
The experts said that LinkedIn used a vanilla or basic technique for encrypting, or scrambling, the passwords which allowed hackers to quickly unscramble all passwords after they figured out the formula by which any single password had been encrypted.
The social network could have made it extremely tedious for the passwords to be unscrambled by using a technique known as "salting", which means adding a secret code to each password before it is encrypted.
"What they did is considered to be poor practice," Landesman said.
LinkedIn officials declined to comment on the criticism, saying it was discussing the breach only on its official blog.
LinkedIn engineer Vicente Silveira said in a blog that the company had instituted new security measures to protect customer passwords, including the use of salting techniques.
The breach at LinkedIn comes after a security researcher last year warned that the company had flaws in the way it managed communications with browsers to authorize logins, making accounts more vulnerable to attack. The company responded by tightening its procedures for logins.
LinkedIn was co-founded by former PayPal executive Reid Hoffman in 2002 and makes money selling marketing services and subscriptions to companies and job seekers.
LinkedIn shares closed 8 cents higher at $93.08 on Wednesday.
(Additional reporting by Sakthi Prasad; Editing by Leslie Gevirtz, Carol Bishopric and Richard Pullin)
Tech
Media
Related Quotes and News
Company
Price
Related News
Tweet this
Link this
Share this
Digg this
Email
Reprints
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (0)
Be the first to comment on reuters.com.
Add yours using the box above.
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Back to top
Reuters.com
Business
Markets
World
Politics
Technology
Opinion
Money
Pictures
Videos
Site Index
Legal
Bankruptcy Law
California Legal
New York Legal
Securities Law
Support & Contact
Support
Corrections
Connect with Reuters
Twitter
Facebook
LinkedIn
RSS
Podcast
Newsletters
Mobile
About
Privacy Policy
Terms of Use
AdChoices
Copyright
Our Flagship financial information platform incorporating Reuters Insider
An ultra-low latency infrastructure for electronic trading and data distribution
A connected approach to governance, risk and compliance
Our next generation legal research platform
Our global tax workstation
Thomsonreuters.com
About Thomson Reuters
Investor Relations
Careers
Contact Us
Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Thomson Reuters journalists are subject to an Editorial Handbook which requires fair presentation and disclosure of relevant interests.
NYSE and AMEX quotes delayed by at least 20 minutes. Nasdaq delayed by at least 15 minutes. For a complete list of exchanges and delays, please click here.