LinkedIn forcing password resets due to Gawker hack(centernetworks.com)
centernetworks.com
LinkedIn forcing password resets due to Gawker hack
http://www.centernetworks.com/linkedin-forcing-all-passwords-to-change
38 comments
I was not impressed by this. It would have been nice of LinkedIn to include a more specific reason for requiring a password reset other than "We have recently disabled your account for security reasons.". I was in panic mode this morning thinking that someone had gotten into my LinkedIn account (and email) and triggered my account to be locked.
They were under absolutely no obligation to do this. Anyone could predict that some subset of their users would get pissy about it. They did it anyways because it was the right thing to do. My esteem for LinkedIn just grew by leaps.
I wasn't pissy about them resetting my password, I was scared that my LinkedIn account and who knows what else had been compromised in relation to the Gawker incident.
It was a good move by LinkedIn to force a password reset. It would have been a GREAT move if they had told me it was precautionary instead of me having to guess why my account was locked.
It was a good move by LinkedIn to force a password reset. It would have been a GREAT move if they had told me it was precautionary instead of me having to guess why my account was locked.
Understand that all parties involved here were under time pressure. They incurred a small amount of angst amongst their users, but may have averted a very large amount of pain. They made the right call; they acted fast rather than getting the messaging exactly right.
I agree -- I applaud the password reset, but would urge them to be specific about the reason, and the fact that this was a bulk action. At first I thought it was just me, and that someone was targeting my account(s). Needless worry could be avoided just by LinkedIn explaining its reasoning.
In contrast, here's the email I just got from Blizzard about my World of Warcraft (battle.net) account:
Greetings!
We’ve recently been informed that several Gawker Media websites have been compromised. These websites include Gawker, Gizmodo, Kotaku, Lifehacker, Jezebel, io9, Jalopnik, Deadspin, and Fleshbot. To help minimize the effects of this compromise and help keep your Battle.net account safe and secure, we’ve reset your account password. To complete the password reset, please log into Battle.net Account Management (https://us.battle.net/account/management) and follow the provided instructions.
In contrast, here's the email I just got from Blizzard about my World of Warcraft (battle.net) account:
Greetings!
We’ve recently been informed that several Gawker Media websites have been compromised. These websites include Gawker, Gizmodo, Kotaku, Lifehacker, Jezebel, io9, Jalopnik, Deadspin, and Fleshbot. To help minimize the effects of this compromise and help keep your Battle.net account safe and secure, we’ve reset your account password. To complete the password reset, please log into Battle.net Account Management (https://us.battle.net/account/management) and follow the provided instructions.
I had a very similar reaction - "is this because my email address was in the gawker database or because someone used my password from the gawker database and did weird things with my account?"
The alternative is calling out Gawker. They probably shouldn't do that.
Or just "Please update your password. This is just a precautionary measure; we do not believe your account to have been compromised."
Exactly.
I had the opposite reaction - I'd already changed my password, and had thought that someone had tried to get in.
The most interesting thing about this to me is that they're obviously only emailing people who's emails were in the gawker data. Eg: I didn't receive one of these because I don't have a gawker account. Very cool.
I apparently have a gawker account, because I received an email from gawker telling me about the breach. This surprised me because I did not remember ever making a gawker account, and I have no entries for any gawker site in 1Password as far as I can see.
Checking the supposedly full database that the hackers released, the email address gawker mailed to is not there (nor are any other email addresses of mine).
I have not received an email from LinkedIn (yet), but when I attempted to log in to it a few minutes ago, it failed and told me there was a problem with my account. I just tried again and this time it takes me to a page that says they have been notified there is a problem with my account and they are fixing it and I'll be taken to my home page in a few minutes.
Net result: I am now very confused.
Checking the supposedly full database that the hackers released, the email address gawker mailed to is not there (nor are any other email addresses of mine).
I have not received an email from LinkedIn (yet), but when I attempted to log in to it a few minutes ago, it failed and told me there was a problem with my account. I just tried again and this time it takes me to a page that says they have been notified there is a problem with my account and they are fixing it and I'll be taken to my home page in a few minutes.
Net result: I am now very confused.
This would also mean they downloaded the copy of gawker's hacked database, which is probably why they didn't provide more details.
Definitely a possibility. There are some alternatives now though, like the list[1] of MD5'd emails that has been circulating that you can use to check against. That's how I confirmed that I wasn't in there, personally.
[1]: http://www.google.com/fusiontables/DataSource?dsrcid=350662
[1]: http://www.google.com/fusiontables/DataSource?dsrcid=350662
I was really impressed about this. I changed most of my other password but forgot about LinkedIn. I think it's really responsible of them to proactively take the initiative on this.
Yesterday I had to change my GMail & Twitter password, today I got mail from LinkedIn to change my password. What is going on!?
Update: If your md5(email) is on this list http://www.google.com/fusiontables/DataSource?dsrcid=350662 Google, Twitter, LinkedIn and probably other sites will ask you to change(reset) your password.
That happened to me.
Update: If your md5(email) is on this list http://www.google.com/fusiontables/DataSource?dsrcid=350662 Google, Twitter, LinkedIn and probably other sites will ask you to change(reset) your password.
That happened to me.
Interestingly enough, my former LinkedIn email was on the Gawker list but my current email with them (to which they sent the alert) was not. Guess that means they are holding on to all previous email accounts?
Yes they are, and they are even keeping track and which of those email account are bouncing back.
See: https://www.linkedin.com/secure/settings?emadd=&goback=....
See: https://www.linkedin.com/secure/settings?emadd=&goback=....
But I went even further, deleting my old email address from that list several months ago. That page only shows my (current) email, which was not on the Gawker list. LinkedIn seems to be keeping around the old email addresses, even after you delete them.
They also seem to be sending out emails to all the email addresses they have on file. I ended up with four copies of the same message.
Is LinkedIn completely down for anyone else? The site's been devolving all afternoon for me. First it said there was a problem and they'd redirect to the homepage in a few minutes. Then there was a LinkedIn-branded Sun ONE Web Server landing page that just had features of ONE for the last hour or so. I just checked back and now it's a totally stock landing page without the linkedin logo. Something seems to be seriously FUBAR today.
And now it seems like they are down, just after I reset my password: http://img.skitch.com/20101214-jk1wagxdf1kn4af4eq9tw2s4na.jp...
Something about this makes me feel nervous..
Something about this makes me feel nervous..
I'm not getting any outage messages, but when I submit the new password form, I get "An unexpected error has occured." And my new password doesn't work, so I'm still locked out.
Looks the same to me. Is it only for the premium accounts?
As people have mentioned above, it seems to have only been for people whose emails were in the gawker dump.
No, I got the email and I don't have a premium account.
I think it's a little silly to force this site-wide. In my experience, most people don't make accounts to comment on tech blogs, and those that do are probably already privvy to the need to change a password when a big database of passwords containing or potentially containing your password is released.
I think it is weird for big companies to act like this has such far-reaching effects; 1.5 million users is not that many in the overall scheme of things, and how many of your users intersect? Apparently LinkedIn thinks that most business people who read that a LinkedIn account would make employers think you were smart and cool also had an account with the same credentials at Gawker.
I think it is weird for big companies to act like this has such far-reaching effects; 1.5 million users is not that many in the overall scheme of things, and how many of your users intersect? Apparently LinkedIn thinks that most business people who read that a LinkedIn account would make employers think you were smart and cool also had an account with the same credentials at Gawker.
Huh? They have a list of email addresses for which passwords were disclosed. If your email address was on the list and you held a LinkedIn account, they zeroed out your password and made you reset it. They didn't reset everyone's account, did they?
My understanding was that they had reset everyone's account. I don't think it was defined or not in the article. If they haven't reset everyone's account, disregard my comment, sorry for the misunderstanding. :)
Mine was definitely not reset, and I don't have a gawker account. My wife's account was also not affected (and likewise, she has no gawker account).
Considering the availability of the list of email addresses it would be pretty silly to force a reset for everyone.
Considering the availability of the list of email addresses it would be pretty silly to force a reset for everyone.