This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by Gareth Morgan
06 Jun 2012
Professional networking website LinkedIn has run into a pair of thorny privacy issues, after reports emerged that millions of account credentials had been leaked, while researchers also accused its iPhone app of surreptitiously snaffling users' data.
According to Norwegian website Dagens, around 6.5 million encrypted LinkedIn passwords were recently posted to a Russian hacker site. Many of those hacked passwords have now been decrypted.
Linked said in a Twitter posting that it was investigating the reports.
Our team is currently looking into reports of stolen passwords. Stay tuned for more.
— LinkedIn News (@LinkedInNews) June 6, 2012
V3 also contacted the firm for any update but had received no information at the time of publication.
Meanwhile, a pair of researchers with Israeli firm Skycure revealed details of a data-sharing issue with LinkedIn's iOS app.
Yair Amit and his colleague Adi Sharabani found the app sent users' calendar information to the company's servers, without warning.
The problem affects users that enable the feature which allows them to view their iOS calendar within the app.
“The app doesn’t only send the participant lists of meetings; it also sends out the subject, location, time of meeting and more importantly personal meeting notes, which tend to contain highly sensitive information such as conference call details and passcodes,” the researchers wrote on a blog.
The researchers said they informed LinkedIn about the potential risk of obtaining user details without permission, but the issue had not yet been fixed.
The mobile app feature had been intended to provide a better calendar service for its users, LinkedIn's mobile product manager Joff Redfern wrote in a company blog.
“We do not store any calendar information on our servers.” he said. “We do not share or use your calendar data for purposes other than matching it with relevant LinkedIn profiles.”
LinkedIn has promised to update its app, removing the capability for calendar note information to be uploaded to its servers.
Latest stories from Security
Related articles
Related jobs
Poll
How concerned are you by the rising tide of cyber threats?
V3 pits top devices against one another ahead of Samsung Galaxy S4 launch
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
C# Developer Successful Software Consultancy are looking...
Our client is an international software development organisation...
Our client is an international software development organisation...
£450M+ IT Solutions Company is recruiting for a suitably...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree