10 ms·
LeakedIn
- anon01 14y agoI think its interesting to see what kind of passwords were in there. "password" was of course in there, "password1" was not, "password2" was....
- ryeguy_24 14y agoGenius. LinkedIn needs more of you apparently.
- imcotton 14y agoThere is a tracking service on the results page keep sending out everything you've just submited.
- KenCochrane 14y agoYou could use the service to see if your new password was already hacked..
- jharding 14y agoYou should add a note on the page that lets people know that checking a password takes a minute or two. EDIT: Actually never mind, seems like it's much faster now.
- scoates 14y agoYeah. We got hit pretty hard. It doesn't actually take a minute or two, unless you're doing a few hundred at the same time. Fixing. (-:
- mythz 14y agoCan you confirm you're not logging/recording the hashed passwords?
- shiflett 14y agoWe can tell you we're not, but that doesn't actually confirm anything. (We're really not, though.) To be safe, you should consider the SHA-1 hash of your LinkedIn password to be public, even if it's not one of these 6.5 million.
- joshuahedlund 14y agoMine was not in the list. I had a non-dictionary password with letters and numbers, 8 characters, and it was at least several months old. (If we can collect enough data points of whose passwords are on it or not, how old they are, and how complex the password was, we should be able to narrow down a potential date range for the list and the odds that the compromised list is full or partial.)
- deleted 14y ago[deleted]
- epo 14y agoYou're confusing "not on the list" with "not in the hacker's possession".
- joshuahedlund 14y agoNot necessarily. There are two possibilities we can analyze: 1. "not on the list" means "not in the hacker's possession". In other words, the compromised list is partial. 2. "not on the list" means hacker already has cracked it and didn't post for help. Learning more about the kinds of passwords not on the list could help us determine which scenario is more likely. (If lots of complex passwords are not on the list, that is evidence the compromised list is partial. If only simple passwords or passwords of a certain pattern are not on the list, that is evidence the compromised list is complete and passwords that were already cracked were not posted.)
- aidos 14y agoAs I understand it they zeroed out the start of the hashes they've already cracked (that's the speculation). I'm assuming that's being checked for server side? According to LI they started salting at some point. Simple hashing obviously won't match in that case but I guess the crackers have the salts so they can do the leg work themselves. Annoyingly LI say that they've invalidated passwords on compromised accounts but I can see that's not the case. My password hash is in the list (random 20 char pw) but they didn't deactivate my password (I've obviously changed it now).
- fendrak 14y agoOne suggestion: make the input box have a type of 'password'. I was only a bit put-off by seeing my plaintext password staring me in the face!
- kungfooey 14y agoProbably a good thing since it makes you think twice about submitting your plain-text password to an unknown entity.
- sontek 14y agoI think its safer to test yourself than randomly typing your password in on websites =)
- jeffgreco 14y agoYou can provide your own hash, and a quick source check reveals that plaintext is being converted into a hash client-side, so only hashed data is being sent to the server.
- nailer 14y agoI think it'd be best to provide people with a simple way to generate their hash with a well-known tool they already trust - eg, an openssl command.
- cschmidt 14y agoFor the record, on a Mac, save your password in a text file called password, without a return at the end of the line. Then: openssl dgst -sha1 password will give you the hash you need. Mine has been leaked but not cracked, according to this site :-(.
- Hoff 14y agoOr... echo -n "password" | openssl dgst -sha1
- thrill 14y ago'password' was actually in use - go figure.
- ConstantineXVI 14y agoAs is ********
- 14y ago
- pbreit 14y agoNow there's a great idea! Provide your password to some random site purporting to check if your password's been compromised.
- samstave 14y agohunter2
- deleted 14y ago[deleted]
- madsr 14y agocorrect horse battery staple.
- samstave 14y agoYears ago, 1996, we had a border router that we inherited and didnt have the password to, nor any way to get it. It was in production and we needed to get the password without killing the config. David Sifry (founder of linuxcare) was my consultant on the issue - he was able to recover the password after some effort. I'll never forget what it was: Feet4monkey Your post reminded me of that.
- jperras 14y agoYou can supply just your password hash if you want, and if you supply the raw password, it's hashed client-side via Javascript before being sent to the server. Test it out with firebug and a dummy password if you're not keen on wading through the source.
- paulhodge 14y agoStill, hashes can be cracked, and an evil password-checking website can then associate the password with all of the other personally-identifiable data that browsers are known to leak. I don't think this particular site is being evil, but it would be wrong for a user to trust a site like this.
- yelloblac 14y agoHow about submitting the hashes over https, at the very least somebody could be sniffing the traffic from your site and gathering the hash list for themselves..
- deleted 14y ago[deleted]
- mrlase 14y ago"Your password was leaked and cracked. Sorry, friend." Well that's lovely. Just changed my LinkedIn password so hopefully no one had a chance to take advantage of that. Luckily I very recently switched to a new password scheme so my other accounts should be secure too.
- ajacksified 14y agoBeat me to my more tounge-in-cheek http://ismylinkedinpasswordleaked.com http://ismylinkedinpasswordleaked.com ;)
- jes5199 14y agoyipes - apparently that site sends up an unsalted sha1 of your password. If leaked unsalted sha1s are worth being worried about, then typing your password into this site is just as bad as the original leak
- Splines 14y agoLike others have stated, you should assume your password hash was leaked anyway. Change it first, then put in the old password into this tool for curiosity's sake.
- Splines 14y agoMy autogenerated password was in the list, and not cracked. I've changed it anyway on linkedin.
- Aleran 14y agoSame for me. "Your password was leaked, but it has not (yet) been cracked. Fingers crossed." Damnit, LinkedIn.
- ig1 14y agoThe site should tell people to change their password anyway regardless of whether it's in the list or not.
- Splines 14y agoWe need a "wasmylinkedinpasswordleaked.com" with <h1>yes</h1> as the content.
- bevan 14y agohaha, quite funny. I made it.
- isnotchicago 14y agoI don't think a Like button was in the original charter.
- deleted 14y ago[deleted]
- hung 14y agoI quickly wrote a script to do this locally, not the most efficient, but I'm at work ;) https://github.com/hungtruong/LinkedIn-Password-Checker https://github.com/hungtruong/LinkedIn-Password-Checker
- yalogin 14y agoThat works pretty well. And yes, my password is in there.
- obituary_latte 14y agoThank you. Worked for me as well... I wonder what kind of bonkers executive at LI decided it would not be a good idea to do a sweeping wipe of all passwords on their systems... for user in users: force_pw_reset(user); def force_pw_reset(user): user.pw = rand; user.sendResetEmail(); (note to LI: this isn't real code; don't use)
- deno 14y agoNow just send phising emails with fake reset links to your targets at the same time. Password reset should be enforced at first login.
- obituary_latte 14y agoAh yes, didn't consider that...you are correct--reset should be forced on login. Though I doubt any of the above will happen. Wouldn't want the user to be inconvenienced now would we?
- deno 14y agoWait till it gets more publicity.
- wilfra 14y agoWhat is standard practice for a situation like if the users lost access to the email account they signed up with? A large forum I post on was hacked recently and - after voluntarily shutting their site down for a month - they required password resets. If users did not have access to the email address they signed up with and couldn't otherwise verify their identity, they were not allowed to get their account back. Unsurprisingly, post counts are down site-wide and the owners have reported a > 25% decrease in traffic.
- will_work4tears 14y agoSomebody had the password test123. Lol. I'm going to go see what other crazy simple passwords people have used.
- weakwire 14y ago"binladen" was actualy used for a password at linkedin lol!
- wouterinho 14y agoI'm wondering about the legality of this. If you take an (assumed) stolen dump of sensitive data and turn it into a webservice, could you get in trouble?
- tazzy531 14y agoReminds me of the Seinfeld/MovieFone episode... "Why don't you just tell me your password..."
- eddieplan9 14y agoI made something almost the same (including name!), except all check is done in browser: http://crackedin.s3-website-us-east-1.amazonaws.com/ http://crackedin.s3-website-us-east-1.amazonaws.com/ And it's hosted on S3 so it is faster :)
- raverbashing 14y agoI just wanted the list in an easily downloadable format so I can check offline (easily downloadable == not the rapidshare of russia, something you could wget) But I submitted the hash of my password and it's there so...
- deleted 14y ago[deleted]
- Hethrir 14y agoI have a torrent up of the database so you can check locally, here: http://www.seedpeer.me/download/linkedin_hashes/ad1e93a1aee28165daab22945b29352ec7518c71 http://www.seedpeer.me/download/linkedin_hashes/ad1e93a1aee2...
- joshx 14y agowww.mediafire.com/?n307hutksjstow3 Click download, copy the URL from your browser into wget/axel/download manager. I get a solid 1mb/s from media fire.
- wouterinho 14y agoInteresting implementation, but won't this eat up a lot of bandwidth and cause a high S3 bill?
- eddieplan9 14y agoI cut the hash database into 256 pieces based on the last two digits of hash so chunk is smaller than 1MB. To check one password it only downloads one piece. So hopefully it won't be that bad.
- olemartinorg 14y agoOh.. Didn't know anyone already made this - i also made a tool, but it doesn't send your whole hash over the wire (only the last 4 chars). http://olemartin.org/linkedin-passwords/ http://olemartin.org/linkedin-passwords/
- Terretta 14y agoNice looking page for such fast work. What about letting 'advanced' users check the SHA1 of their password, so they don't enter their password at all but also don't have to track down the giant file?
- olemartinorg 14y agoThat should work already - just use the other field and click the button. :-) There's no giant file though, i've split the giant file into ~65000 smaller ones that are more bandwidth friendly.
- towts 14y agoi observed it seems this tool and the leaked in one don't agree on the resulting hash value from the same word. for example this tool says the word "test" hashes with the last 5 digits of 77136 where as leaked in translates the word "test" to fbbd3. hmmm
- olemartinorg 14y agoThanks! I've changed it now. Seems i didn't catch the key event properly. :-)
- deleted 14y ago[deleted]
- deleted 14y ago[deleted]
- alexlitov 14y agoYour password was leaked, but it has not (yet) been cracked. Fingers crossed.
- STRiDEX 14y agoSomeone used "georgebush"
- its_so_on 14y agoSorry, I don't mean to be harsh, but this concept is pretty much dead on arrival. "Check if your hash is still private and secure by sending us your hash." Well, even if the hash was secure, it isn't now! (Unless you: O get the whole database into the client O ask the user to: o reload the URL in PRIVATE browsing mode o DISCONNECT from the network o test the results with javascript o close the whole browser o reopen the browser o finally, clear flash cookies (how do I even do that?) o Only then reconnect to the network All to prevent you from either reading the results afterward or, as regards instructions to disconnect from the network, somehow changing or making a mistake in the javascript, perhaps after we or others have verified and ok'd it.) If the only answer to the objection against giving you the hash is that you don't ask for the username, you might as well ask for the password plaintext. Sorry, the concept is pretty much dead on arrival. Still, way to ship. (or 'nice shipping.' Should be our secret handshake :). Good luck on the next concept.
- exit 14y agohow can they tell what was leaked but not cracked?
- ckrailo 14y agoThe cracked passes have hashes starting with zeros. See the discussion here: http://news.ycombinator.com/item?id=4073309 http://news.ycombinator.com/item?id=4073309
- namank 14y agoWell the fun I'm having with this is checking all the trivial passwords that people still use despite warnings. No, mine isn't in the list.
- dsl 14y agowww.wasmylinkedinpasswordstolen.com is much better.
- deleted 14y ago[deleted]
- siavosh 14y agoI wish I could down vote or delete this article. Regardless of the creator's intentions, there are a lot of non-techie people on HN (like one of my co-workers) who used this site to check their linkedin password. It reinforces fatal security habits.
- fozzle 14y agoI'm really enjoying testing completely silly passwords against the leaks. 'pooppants' is a confirmed hit. "World's Largest Professional Network". I like to imagine some suit with a cigar logging into look for new hires with that one.
- dfrey 14y agoMy password was leaked and cracked. It is also the same password I use on Hacker News. :((((
- tommyvyo 14y agoIf you're not looking to give your password to this site, I built a rails app with similar intentions: git clone git@bitbucket.org:tommyvyo/linked-in-password-searcher.git rake db:migrate rake db:seed (this will take a while if you use the default of sqlite3) rails s open localhost:3000 Bitbucket: (https://bitbucket.org/tommyvyo/linked-in-password-searcher https://bitbucket.org/tommyvyo/linked-in-password-searcher) Github: (https://github.com/tommyvyo/linkedin-password-searcher https://github.com/tommyvyo/linkedin-password-searcher)
- Hethrir 14y agoI think the much bigger risk here is password re-use, think if some CEO used the same password for their website/email? Also, torrent: http://www.seedpeer.me/download/linkedin_hashes/ad1e93a1aee28165daab22945b29352ec7518c71 http://www.seedpeer.me/download/linkedin_hashes/ad1e93a1aee2...
- tommyvyo 14y agoI wrote a Rails app that does the same thing. If you don't trust this site you can checkout the source to my app (in app/controllers/searcher.rb) and then try it out yourself. You can clone it from bitbucket (including the SHA1.TXT file) from (https://bitbucket.org/tommyvyo/linked-in-password-searcher https://bitbucket.org/tommyvyo/linked-in-password-searcher). setup: rake db:migrate rake db:seed (this will take a while) rails server open http://localhost:3000 http://localhost:3000
- david_shaw 14y agoEven if this is a completely trusted and secure site, why would you not use SSL for something like this? Transport layer security is a serious issue, especially for people prone to password reuse.
- mark-r 14y agoThe link appears to be down now, either it served its nefarious purpose or it's a victim of its own success.
- facorreia 14y agoIf your hash is not on that list, it's bad news. There are indications that the hacker published only the hashes he needed help with. The others were more easily decoded.
- bevan 14y agoA better solution: www.wasmylinkedinpasswordleaked.com
- johnchristopher 14y agoIf you leave the page opened long enough some random(?) characters fill the input field. What for ?
- tarellel 14y agoWelp, looks like they've got your password now ;-)
- deleted 14y ago[deleted]
- elchief 14y agoGood news, the following passwords where not leaked: password asdfasdf (whew!) linkedinpassword The following were: password1 password$ linkedin a1a1a1a1 drowssap 12345678
- rajbot 14y ago`password` was leaked. See this comment about the format of hashes in the dump: http://news.ycombinator.com/item?id=4073928 http://news.ycombinator.com/item?id=4073928
- elchief 14y agoHm, when I first typed those in, it said not leaked, but now it is saying leaked for all of them. Apologies.
- cristianocd 14y agoplease make the wordlist you're getting everyone generate for you available to download! thanks
- x1 14y agohuh, I have a linked in account that I don't check often and my password was on that list. Luckily it was specific to linkedin. I don't believe this is just a small percentage of users. Oh and I never received an email like the blog states (http://blog.linkedin.com/2012/06/06/linkedin-member-passwords-compromised/ http://blog.linkedin.com/2012/06/06/linkedin-member-password...)... odd...
- ronik 14y agoI'm amazed someone took the time to develop this without thinking of the potential trust issues involved.
- lifthrasiir 14y agoHeck, isn't it supposed to use type="password" in its input element?
- JEVLON 14y agoIt is helpful to have a unique password for each meaningful service you use. That way the black-hats can't compromise your other accounts using the same password.
- Jebus 14y agoI lol'd trying all kinds of nasty sexual passwords, and seeing people have actually used them.
- bwei 14y agoThanks. I was a victim.
- therandomguy 14y agoIf any of your had "password" as your password, it has been compromised. I just checked.
- andrewpi 14y agoMy (previous) password was randomly generated, and it was on this list. Fortunately I had already changed it when I read about the breach earlier on Wednesday.
- cpg 14y agoTangencially related to some of the comments in this thread. Amahi (my startup) started experiencing lots of spamming accounts a little while ago. We started using blacklists and some heuristics to detect the spammers. Then we logged the attempts. Some interesting things emerge. * The vast majority of them have "super123" as the password * The vast majority use emails from china (163.com, qq.com, etc.) * They try twice in a row if the first attempt fails * They try regularly The suspicion is that they then sell these accounts in bulk for later action. We have seen them have these accounts sitting idle, with occasional logins to check if they still work. Then later they pounce, posting spam links, etc. The level of sophistication of all this is rather troublesome ...
- kbronson 14y agoMy 1234 password was not leaked! Yahooo!!!
- lucb1e 14y agoBrilliant. Next time I want someone's password I'll create a page similar to this ("check if your password was leaked!") and pretend to spam my entire contact list while my target is really the only person receiving it. No seriously, how in the world can we trust this website with our password? They don't even claim to keep your password a secret. For all we know this is a follow-up scam to extend the 6.5mil hacked hashes. Having a very quick glance at the HTML source, it seems they hash it before it's sent to the site to check, but it easily might have been a scam. Or turn into one with a probability of 1 in 10, that still gets them many passwords while remaining to be trusted.
- twodayslate 14y agoI was compromised :(
- btb 14y agoAhh interesting. My password was on the list(I changed it before checking). old password: ve78d9k6k 4c1433ca9d58d7d7ba00658d209583d8edde144a
- lollancf37 14y agolol
- jheriko 14y agothis smacks of a scam...
- Melug 14y agoIf leaked in saves my password, I'm leaked now.