LWN.net Logo

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 9, 2012 0:37 UTC (Sat) by martinfick (subscriber, #4455)
In reply to: 8 million leaked passwords connected to LinkedIn, dating website (ars technica) by AndreE
Parent article: 8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Not if it can be changed by anyone who knows the details he just mentioned. Which is why backup questions are the dumbest things ever. You only have to compromise the weakest link. It doesn't matter how strong your password is if anyone can change it with knowledge of "unchangeable pseudo secrets" about yourself. If I care about security on a site, I would never answer those questions with anything but a random answer (just record it in a safe place).


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds