Christopher Mims

A View from Christopher Mims

Why LinkedIn's Password Leak Endangers Security Across The Web

Hackers can now access the many sites on which we used the same password as LinkedIn.

  • June 6, 2012

Using the same password over and over again, across many sites, is extremely common. We’re not sure how common — estimates range between 10 percent and 50 percent of all passwords are re-used — but I would be shocked if more than a small portion of LinkedIn users hadn’t re-used their LinkedIn password at least once.

Photo: Nan Palmero

Which means, in the wake of the release of 6.46 million hashed (encrypted) LinkedIn passwords, Google probably has thousands of new breaches of Gmail to look forward to. Password re-use is by far the easiest way to breach accounts on otherwise secure sites. (Email addresses aren’t hard to track down, and trying a password harvested from elsewhere can be automated.)

This means it’s time for me to trot out my well-worn PSA about how, if you must re-use passwords rather than using a secure password management program like 1password, at least you can do it in a way that won’t lead to a catastrophic loss of your online security.

How to Prevent a Gawker-Style Hack From Endangering You
You don’t have to memorize hundreds of passwords to ensure hackers won’t compromise your online identity.

Basically, the idea is that you make sure that the passwords you use for your most important accounts — bank, email, etc. — are totally unique. Every other site for which a breach is merely an annoyance, re-use passwords as you please. The full post.

Become an MIT Technology Review Insider for in-depth analysis and unparalleled perspective.

Subscribe today

Uh oh–you've read all of your free articles for this month.

Insider Premium
$179.95/yr US PRICE

Want more award-winning journalism? Subscribe and become an Insider.
  • Insider Premium {! insider.prices.premium !}*

    {! insider.display.menuOptionsLabel !}

    Our award winning magazine, unlimited access to our story archive, special discounts to MIT Technology Review Events, and exclusive content.

    See details+

    What's Included

    Bimonthly home delivery and unlimited 24/7 access to MIT Technology Review’s website.

    The Download. Our daily newsletter of what's important in technology and innovation.

    Access to the Magazine archive. Over 24,000 articles going back to 1899 at your fingertips.

    Special Discounts to select partner offerings

    Discount to MIT Technology Review events

    Ad-free web experience

    First Look. Exclusive early access to stories.

    Insider Conversations. Listen in as our editors talk to innovators from around the world.

  • Insider Plus {! insider.prices.plus !}* Best Value

    {! insider.display.menuOptionsLabel !}

    Everything included in Insider Basic, plus ad-free web experience, select discounts to partner offerings and MIT Technology Review events

    See details+

    What's Included

    Bimonthly home delivery and unlimited 24/7 access to MIT Technology Review’s website.

    The Download. Our daily newsletter of what's important in technology and innovation.

    Access to the Magazine archive. Over 24,000 articles going back to 1899 at your fingertips.

    Special Discounts to select partner offerings

    Discount to MIT Technology Review events

    Ad-free web experience

  • Insider Basic {! insider.prices.basic !}*

    {! insider.display.menuOptionsLabel !}

    Six issues of our award winning magazine and daily delivery of The Download, our newsletter of what’s important in technology and innovation.

    See details+

    What's Included

    Bimonthly home delivery and unlimited 24/7 access to MIT Technology Review’s website.

    The Download. Our daily newsletter of what's important in technology and innovation.

/
You've read all of your free articles this month. This is your last free article this month. You've read of free articles this month. or  for unlimited online access.