RIABiz

News, Vision & Voice for the Advisory Community

RIABiz

Why the LinkedIn password theft is a big deal and how advisors can avoid falling victim

The bad news: This was possibly a major breach; The good news: You can fix the problem in a few minutes

6 min read
By Mike Golaszewski Guest Columnist June 8, 2012Updated: July 14, 2020
no description available
Mike Golaszewski: You've worked hard to establish trust and rapport with your clients...Don't undo all that.
  • LinkedIn's password theft highlights the need for strong online credential management.
  • Immediately change your LinkedIn password and any duplicates used elsewhere.
  • Salting passwords defends against hackers using pre-computed 'rainbow tables'.
  • Avoid common words; use random numbers and characters for stronger passwords.
AI generated

Brooke’s Note: We’re all blasted mercilessly by media reports that sound important but we filter them out — and hope that somebody jabs us when something really needs to be paid attention to. I try to do that daily at RIABiz with events that are ground shifters in this industry. But I don’t have a clue about technology threats. Fortunately, Mike Golaszewski has that one covered for us this time around as LinkedIn shifts on its moorings. Thanks, Mike. (Thanks especially for teaching us how to create a memorable password! So easy.)

The recent disclosure that over 6.5 million passwords hashes were stolen from LinkedIn and posted online is the latest reminder that everybody, especially those of us that have access to sensitive financial data, need to be especially careful with managing both our personal and professional online credentials. See: Advisor Tested: How LinkedIn can truly build your business and not just feed your ego.

Before you get any further reading this article, however, you should stop, go over to LinkedIn, and change your password if you haven’t done so already. And if you used that same password with any other service, especially the e-mail providers that you have linked to your LinkedIn account, you should change those passwords as well.

Pipe by hash

What happened? Well, details are still thin, but it appears that a still-unknown hacker was able to get a hold of a large number (possibly all) of LinkedIn password hashes, not the passwords themselves. However, because of a mistake LinkedIn made in calculating and storing these hashes, the hacker was then able to determine the actual passwords for a wide swath of LinkedIn users.

Advisor Tested: How LinkedIn can truly build your business and not just feed your ego
Related· Feb 7, 2011

Advisor Tested: How LinkedIn can truly build your business and not just feed your ego

First, some basics (and this gets technical, so if you are more interested in alpha than crypto, skip to the end). A hash is a cryptographic function that takes a piece of data, like a password, and then slices, dices, and scrambles it using complex mathematics to create a unique, numerical value that represents the original data. The resulting number is called a digest (or a hash), and according to cryptoanalytic theory, each digest is unique (like a fingerprint or a snowflake). The other special characteristic about a digest is that it’s impossible to reverse the mathematics on the digest to determine what the original data is. So, most online web services store the hash of your password rather than the password itself; that way, they never know what your actual password is—just what its “signature” looks like.

Hackers are crafty though, and have figured out a way to defeat this system. They will take a dictionary, like the Oxford English Dictionary, and pre-compute the hashes for every single English word in that dictionary and store the results in what is called a “rainbow table.” That way, all they have to do to determine a password is compare its hash to all of the pre-computed digests in their rainbow table. If they find a match, they can easily determine your password.

In fact, hackers don’t even need to create these rainbow tables. They are easily downloaded from the internet and include entire dictionaries, lists of common names, as well as hashes for every possible letter, number, and symbol combination up to at least 8 characters long). This is one of the reasons why security researchers say that passwords should include things like random numbers and characters. Common words and names are trivially easy to crack!

Worth its salt

However, there is a defense against rainbow tables, and it’s called “salt.” In cryptography, salt is a random piece of data that is added to your password before it is hashed. The theory is that a hacker has probably pre-computed the hash for “apple,” but they likely haven’t pre-computed the hash for “apple+@*#$&123.” The more salt the provider adds, the more secure your password is because after a certain point it becomes physically impossible for hackers to pre-calculate the hashes for all the possible permutations of a certain length. The time needed would exceed the age of the entire universe.

Salting is a fundamental security best practice, and it’s where LinkedIn stumbled. By not salting their hashes, LinkedIn made it incredibly easy for hackers to deduce the many common passwords that people often use, and now a wide swath of professionals are at risk of identity and information theft.

Beware: RIA privacy breaches aren’t always high-tech
Related· Jun 20, 2012

Beware: RIA privacy breaches aren’t always high-tech

So, what does this mean for financial services professionals? First of all, the LinkedIn security breach is a reminder that you should never, ever use the same password for multiple websites (especially e-mail!). Using the same password is no different than having one key that works for your house, your car, and your safe deposit box, and means that once a hacker figures out your password, they effectively have access to every single website that you might use.

Stone free

The second thing you want to do is to make your passwords long. In general, length equates to security because the amount of time it would take to guess your password increases significantly each time you add a character. One easy way to make long passwords is to take your favorite song (mine is Dylan’s “Like a Rolling Stone”) and use the first letter in each word of your favorite lyrics. For example, “how does it feel / to be on your own / with no direction home” might become “hdif/tboyo/wndh.”

Finally, season your own passwords by adding random numbers, letters, and characters to both the beginning and end of them. Again, the goal here is to make it unlikely that a hacker has pre-computed the hashes for a word, a name, or a collection of letters that includes your random numbers, letters, and characters. See: Top 10 tips for the 'social’ financial professional when creating your LinkedIn profile.

A hacker accessing your Facebook profile or LinkedIn account might be embarrassing and even inconvenient, but having that same hacker accessing your e-mail account, corporate systems, or anything else that contains non-public information of your clients is entirely different matter. Not only does it expose you and your firm to reputational and financial risk, but it also triggers expensive and embarrassing regulatory disclosure requirements and possible reviews.

Vaulting trust

You’ve worked hard to establish trust and rapport with your clients. Don’t take the chance that the careless security practices of websites that you use for fun, entertainment, networking, or other purposes will undo all of that. Get smart with your passwords.

Mike writes this column in his capacity of managing partner of Element-12, a technology consulting firm that provides services to the financial services and software industries. He is also senior director and head of product for Black Diamond.

Rely on RIABiz? Tell Google.

Naming us a preferred source puts our reporting first in your Top Stories and AI Overviews. Takes one click, and only you see the difference.

Make us a preferred source on Google

On the record

Be an expert voice.

Become an expert voice

Anonymous

Or tell us without your name.

Send an anonymous tip
Entities in this article
Firms
LinkedIn
Oxford English Dictionary
RIABiz
Topics
Cryptography
Hacker
Hash
Online credentials
Rainbow table
Robo-advisor
Salt


RIABiz Directory

The Industry Sourcebook for RIAs

   |    LISTING


RIABiz Directory
sponsored by

Directory Sponsor Logo