4 ms·
What makes this even worse is the fact that they're trying to cover up just how bad this really is. LinkedIn use(d) the sha1 hashing algorithm (see: http://arst
by jaitsu 10y ago
What makes this even worse is the fact that they're trying to cover up just how bad this really is. LinkedIn use(d) the sha1 hashing algorithm (see: http://arstechnica.com/security/2012/06/8-million-leaked-passwords-connected-to-linkedin/ http://arstechnica.com/security/2012/06/8-million-leaked-pas...) which is easily breakable through rainbow tables when not used with a salt (which LinkedIn failed to use).
The sha1 hash has been known to be cryptographically insecure since as early as 2007 (https://www.schneier.com/blog/archives/2005/02/cryptanalysis_o.html https://www.schneier.com/blog/archives/2005/02/cryptanalysis...).
The very fact that LinkedIn reset everyone's passwords backs this up.
After this data leak I deleted my account, not only is LinkedIn destroyed the art of recruitment it has been completely irresponsible with user's data.
- ProAm 10y ago> art of recruitment What is this?
- justinlardinois 10y agoSounds like he's not happy with the impact LinkedIn has had on talent acquisition. As if it was ever an art, or not shitty, at any point in history.
- douche 10y agoAlso deleted my account. Although according to them, it might take several months before my profile actually goes away "for real" and I stop getting spam emails from recruiters. Apparently there is no nuke it from orbit option.