3 ms·
> Members that have accounts associated with the compromised passwords will notice that their LinkedIn account password is no longer valid. I wonder if they kn
by daave 14y ago
> Members that have accounts associated with the compromised passwords will notice that their LinkedIn account password is no longer valid.
I wonder if they know how those particular hashes that were leaked got stolen, if not, they should assume the whole database was stolen and only some of it has been leaked publicly, thus necessitating that this action be taken for all users accounts, not just the ones that match the hashes in the leak.
> It is worth noting that the affected members who update their passwords and members whose passwords have not been compromised benefit from the enhanced security we just recently put in place, which includes hashing and salting of our current password databases.
Huh? For people who change their password, fine, but 'for members whose passwords have not been compromised', how are they re-hashing them with salt unless they have the original (plaintext) passwords on file. Or are they doing H(salt + H(pass)), rather than H(salt + pass)?
If the latter, then hopefully they are at least re-hashing your password next time you log in, but most people don't log in very often - my cookies certainly haven't been expired. A co-worker tells me that even after changing his password through the website, the login credentials on the Android app were not expired!