<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: LinkedIn Password Hacking confirmed</title>
	<atom:link href="http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/</link>
	<description>Feeding Your Gadget and Tech Obsessions</description>
	<lastBuildDate>Mon, 09 Jul 2012 11:45:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Guest</title>
		<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/#comment-215346</link>
		<dc:creator>Guest</dc:creator>
		<pubDate>Thu, 07 Jun 2012 16:02:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.slashgear.com/?p=232653#comment-215346</guid>
		<description><![CDATA[I&#039;m sure glad those hackers are working against big companies... and supporting the general public instead.

Hey, wait a minute.  How did posting my password online... help me exactly????
]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m sure glad those hackers are working against big companies&#8230; and supporting the general public instead.</p>
<p>Hey, wait a minute.  How did posting my password online&#8230; help me exactly????</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patty</title>
		<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/#comment-215344</link>
		<dc:creator>Patty</dc:creator>
		<pubDate>Thu, 07 Jun 2012 15:58:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.slashgear.com/?p=232653#comment-215344</guid>
		<description><![CDATA[I think he was trying to say:

Do you have a list of passwords?
Or do you have a list of user names?
Or do you have both?

... or... do you have a *MATCHING* relationship list????]]></description>
		<content:encoded><![CDATA[<p>I think he was trying to say:</p>
<p>Do you have a list of passwords?<br />
Or do you have a list of user names?<br />
Or do you have both?</p>
<p>&#8230; or&#8230; do you have a *MATCHING* relationship list????</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bonnie T.</title>
		<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/#comment-215342</link>
		<dc:creator>Bonnie T.</dc:creator>
		<pubDate>Thu, 07 Jun 2012 15:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.slashgear.com/?p=232653#comment-215342</guid>
		<description><![CDATA[I&#039;m thinking of a number.  When you take the square-root of it... the 11th digit is a 4.

What&#039;s my original number?

There is no answer.   Because there are millions of solutions.... and absolutely no way to know which 1 the original user picked.

The whole point of &quot;a password file was stolen&quot; is to PREVENT hackers from posting everyone&#039;s password online.

LinkedIn didn&#039;t think.  Now I know your password... and can use it on other sites.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m thinking of a number.  When you take the square-root of it&#8230; the 11th digit is a 4.</p>
<p>What&#8217;s my original number?</p>
<p>There is no answer.   Because there are millions of solutions&#8230;. and absolutely no way to know which 1 the original user picked.</p>
<p>The whole point of &#8220;a password file was stolen&#8221; is to PREVENT hackers from posting everyone&#8217;s password online.</p>
<p>LinkedIn didn&#8217;t think.  Now I know your password&#8230; and can use it on other sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jill</title>
		<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/#comment-215340</link>
		<dc:creator>Jill</dc:creator>
		<pubDate>Thu, 07 Jun 2012 15:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.slashgear.com/?p=232653#comment-215340</guid>
		<description><![CDATA[You can &quot;brute-force&quot; without a need to even steal the password list.  That&#039;s not the point.

But a lossy 1-way encryption would *NEVER* get you back to the original user&#039;s password.   It could (maybe) get you 1000s of guesses at it.   But never the original one.  Only the user would know that one.]]></description>
		<content:encoded><![CDATA[<p>You can &#8220;brute-force&#8221; without a need to even steal the password list.  That&#8217;s not the point.</p>
<p>But a lossy 1-way encryption would *NEVER* get you back to the original user&#8217;s password.   It could (maybe) get you 1000s of guesses at it.   But never the original one.  Only the user would know that one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guest</title>
		<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/#comment-215339</link>
		<dc:creator>Guest</dc:creator>
		<pubDate>Thu, 07 Jun 2012 15:49:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.slashgear.com/?p=232653#comment-215339</guid>
		<description><![CDATA[They have something far, far more powerful than an old Cray.

They can combined the power of 1,000,000 individual computers all over the world.

And that&#039;s exactly what they did yesterday.
]]></description>
		<content:encoded><![CDATA[<p>They have something far, far more powerful than an old Cray.</p>
<p>They can combined the power of 1,000,000 individual computers all over the world.</p>
<p>And that&#8217;s exactly what they did yesterday.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Nonya</title>
		<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/#comment-215283</link>
		<dc:creator>Jeff Nonya</dc:creator>
		<pubDate>Thu, 07 Jun 2012 10:09:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.slashgear.com/?p=232653#comment-215283</guid>
		<description><![CDATA[They don&#039;t have Crays. What you propose would take billions of years, if not longer.]]></description>
		<content:encoded><![CDATA[<p>They don&#8217;t have Crays. What you propose would take billions of years, if not longer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joan Respondi</title>
		<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/#comment-215215</link>
		<dc:creator>Joan Respondi</dc:creator>
		<pubDate>Thu, 07 Jun 2012 00:12:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.slashgear.com/?p=232653#comment-215215</guid>
		<description><![CDATA[Correct.]]></description>
		<content:encoded><![CDATA[<p>Correct.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joan Respondi</title>
		<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/#comment-215214</link>
		<dc:creator>Joan Respondi</dc:creator>
		<pubDate>Thu, 07 Jun 2012 00:11:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.slashgear.com/?p=232653#comment-215214</guid>
		<description><![CDATA[...who noted that the company does indeed correspond directly with LinkedIn accounts...&quot; Author, what on earth does that sentence mean?]]></description>
		<content:encoded><![CDATA[<p>&#8230;who noted that the company does indeed correspond directly with LinkedIn accounts&#8230;&#8221; Author, what on earth does that sentence mean?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jdeberhart</title>
		<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/#comment-215158</link>
		<dc:creator>jdeberhart</dc:creator>
		<pubDate>Wed, 06 Jun 2012 21:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.slashgear.com/?p=232653#comment-215158</guid>
		<description><![CDATA[They brute-force passwords until they match the hash.]]></description>
		<content:encoded><![CDATA[<p>They brute-force passwords until they match the hash.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guest</title>
		<link>http://www.slashgear.com/linkedin-password-hacking-confirmed-06232653/#comment-215152</link>
		<dc:creator>Guest</dc:creator>
		<pubDate>Wed, 06 Jun 2012 21:06:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.slashgear.com/?p=232653#comment-215152</guid>
		<description><![CDATA[They should always be using a lossy 1-way hash algorithm.   Even if you GIVE someone the entire password file... no passwords will ever be found there.  Just a useless load of coded letters/numbers that can *NEVER* be decoded back into their original passwords.

My password is: poodle
The database encodes it and stores: 3j3h228s8s83930922dfdf4686
A talented hacker &quot;successfully&quot; decodes it, but only gets: xxksej3322kx3343kxkxfgf

The original word &quot;poodle&quot; is *NEVER* stored or obtainable by anyone.  Not by me.  Not by a hacker.  Not even by the staff of the company itself.
]]></description>
		<content:encoded><![CDATA[<p>They should always be using a lossy 1-way hash algorithm.   Even if you GIVE someone the entire password file&#8230; no passwords will ever be found there.  Just a useless load of coded letters/numbers that can *NEVER* be decoded back into their original passwords.</p>
<p>My password is: poodle<br />
The database encodes it and stores: 3j3h228s8s83930922dfdf4686<br />
A talented hacker &#8220;successfully&#8221; decodes it, but only gets: xxksej3322kx3343kxkxfgf</p>
<p>The original word &#8220;poodle&#8221; is *NEVER* stored or obtainable by anyone.  Not by me.  Not by a hacker.  Not even by the staff of the company itself.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
