LinkedIn faces class action suit over password leak

People can take data from us, but not money

21 Reg comments Got Tips?

LinkedIn is facing a class action suit over the security breach that saw millions of users' passwords posted online.

Illinois resident Katie Szpyrka leads the complaint, which alleges that LinkedIn failed to "properly safeguard its users' personally identifiable information".

The complaint filed in California accuses the business network of using a "weak encryption format" for users' information and not having crucial security measures in place.

A LinkedIn spokesperson told The Register that the class action suit's claims were "without merit".

"No member account has been breached as a result of the incident, and we have no reason to believe that any LinkedIn member has been injured," the company said. "Therefore, it appears that these threats are driven by lawyers looking to take advantage of the situation.

"We believe these claims are without merit, and we will defend the company vigorously against suits trying to leverage third-party criminal behaviour."

The 6.5 million user passwords hacked and posted online were in hashed format, but the biz site evidently had not applied any salts. Salting adds extra arbitrary data to a password when it is hashed, thwarting pre-generated tables and making life more difficult for password crackers. The class action suit claims that hashing without salting is not an "industry standard protocol" as promised by LinkedIn's privacy policy.

"Despite its contractual obligation to use best practices in storing user data, LinkedIn failed to utilise basic industry standard encryption methods. In particular, LinkedIn failed to adequately protect user data because it stored passwords in unsalted SHA1 hashed format," the filing said, branding SHA1 "outdated".

The case also latches on to reports that LinkedIn was hacked through an SQL injection attack, which uses weaknesses in a company's website to get into its back-end systems.

"If true, LinkedIn's failure to adequately protect its website against SQL injection attacks - in conjunction with improperly securing its users' personally identifiable information - would demonstrate that the company employed a troubling lack of security measures," the complaint said.

Naturally, the class action suit is looking for attorney fees and damages for US members of LinkedIn. ®

SUBSCRIBE TO OUR WEEKLY TECH NEWSLETTER


Keep Reading

Fake crypto-wallet extensions appear in Chrome Web Store once again, siphoning off victims' passwords

'Seriously sometimes seems Google's moderators are only optimized to respond to social media outrage'

Social media giants move to defy Hong Kong's new national security law

Plus: US govt says it's 'looking at' banning Chinese social media apps, including TikTok

Firefox 74 slams Facebook in solitary confinement: Browser add-on stops social network stalking users across the web

Prompt to install enhanced extension is the first thing you'll see

Your latest security headache? Ed from accounting using his kid as an unpaid helpdesk

Techie teens, not IT support, tasked with helping work-from-home parents sort out vid calls, Word and Excel files, antivirus – survey report

News aggregator app Flipboard hacked: All passwords reset after hackers pinch user data

Over half a billion installs? This one's not over yet, we reckon

After intense scrutiny, Zoom tightens up security with version 5. New features include not, er, spilling video calls to network snoops

No dog-eared National Geographic for those left in the virtual waiting room

UK intel committee on Russia: Social media firms should remove state disinformation. What was that, MI5? ████████?

Also (yikes): A 'complicated wiring diagram of responsibilities amongst ministers' in the event of cyber attack

Uncle Sam challenged in court for slurping social media info on 'millions' of visa applicants

Documentary filmmakers lob sue ball to halt practice

Biting the hand that feeds IT © 1998–2020