1. Headline
  1. Headline
LinkedIn
LinkedIn is having trouble alerting members affected by the recent password theft.
By
updated 6/14/2012 4:45:56 PM ET 2012-06-14T20:45:56

LinkedIn is far from the only company to suffer a massive data breach, but the company's response to the incident is unique — in all the wrong ways.

First, a short timeline: On June 6, the passwords of more than 6.4 million LinkedIn users hit a Russian Web forum after a reported hack. After repeatedly issuing statements saying nothing was wrong — and prompting widespread criticism from security experts —  LinkedIn finally admitted late in the day that the security breach was real.

To alert its millions of potentially compromised members, LinkedIn issued a list of security steps to help users from having their accounts hijacked. LinkedIn said affected users would receive an email from LinkedIn on how to reset their passwords.

[LinkedIn, eHarmony Don't Take Your Security Seriously]

  1. More from TODAY.com
    1. Groom-less bride poses in sweet solo wedding photos

      One bride decided to pursue her dream wedding photos, even though her husband was stationed abroad in the Air Force.

    2. ‘A hot meal can make people cry’: BBQ volunteers comfort Oklahoma victims
    3. Joe Francis: 'Retarded' jury should be 'shot dead'
    4. Joy amid tornado's destruction as owners find lost pets
    5. PTC angry after Ke$ha drinks pee on TV

Those emails have set off another series of problems. About a quarter of a million of the legitimate LinkedIn email alerts ended up in spam folders, according to Computerworld. Andrew Conway, a researcher at the security firm Cloudmark, told Computerworld that LinkedIn's emails weren't the problem — they were all addressed to the recipient by name and contained no links — it was that those recipients were expecting spam, and ready to delete it when it came.

"Part of the problem is that people are used to getting email that they don't want from LinkedIn, and rather than unsubscribe, some of them just mark it as spam and hope that it will go away," Conway said.

Softpedia reported that some of the notifications from LinkedIn were, in fact, poorly worded, and did not contain any "precise information" — the hallmarks of traditional spam messages.

The fallout from the data breach doesn't end there for LinkedIn. In attempting to rectify the problem for its affected members, LinkedIn mistakenly sent the password reset notification emails to current members' former employers, regardless of whether their email addresses have ever been associated with LinkedIn.

As Bitdefender reported, the LinkedIn notification doesn't include the username or password of the compromised member's account, but "this alleged security feature counts as unnecessary disclosure of activity that may actually work against the user by informing third parties of his or her whereabouts."

© 2012 SecurityNewsDaily. All rights reserved

Discuss:

Discussion comments

,

Most active discussions

  1. votes comments
  2. votes comments
  3. votes comments
  4. votes comments

More on TODAY.com

None
  1. Kael Alford / Kael Alford

    Laughter, tears for family devastated by tornado

    5/23/2013 9:18:16 AM +00:00 2013-05-23T09:18:16
None
  1. Cash-for-phone ATMs may fuel violent crime, top cop says

    Some officials say a machine popping up in malls across the country that offers instant cash for used cellphones is fueling a wave of violent crime.

    5/23/2013 11:53:19 AM +00:00 2013-05-23T11:53:19
  2. What to do if your cellphone is stolen
None
  1. Mom in labor as twister destroys hospital

    5/22/2013 11:13:07 PM +00:00 2013-05-22T23:13:07
None
  1. Ryan Brenizer

    Groom-less bride poses in sweet solo wedding photos

    5/22/2013 8:03:05 PM +00:00 2013-05-22T20:03:05
None
  1. TODAY

    video Okla. victims find pets, photos through social media

    5/22/2013 9:13:42 PM +00:00 2013-05-22T21:13:42
None
  1. Man knifed to death in suspected London terror attack

    A man, reportedly a British soldier, was killed by knife-wielding assailants on a London street Wednesday. A bloodstained man at the scene carrying a meat clever was filmed telling passers-by: "We swear by the almighty Allah."

    5/22/2013 8:13:05 PM +00:00 2013-05-22T20:13:05