LinkedIn settles with users over massive password leak

By

Class-action against networking site succeeds.

A United States federal court has approved a settlement that will see users of the professional networking site LinkedIn offered compensation over a passwork leak two years ago.

LinkedIn settles with users over massive password leak

The breach in June 2012 saw around 6.5 million credentials leaked to a Russian web forum in an archive encrypted with the outmoded and weak SHA-1 algorithm.

In November 2013, premium subscriber Khalilah Wright took LinkedIn to court over the leak.

While Wright and other plaintiffs in the class-action suit failed to show that the leak caused them financial loss or future harm, the judge in the case upheld the claim that LinkedIn had misrepresented its security practices.

Wright said if she'd known the details of LinkedIn security practices - that passwords were stored without added salt - her subscription would've been less valuable.

The settlement will now go ahead for a total of US$1.25 million (A$1.6 million). However, the amount that each LinkedIn subscriber can claim is small, just US$50 (A$64) per head.

Some 800,000 paid users who subscribed to LinkedIn's premium service between March 15 2006 and June 6 2012 are eligible for compensation, the US court ruled.

Further details of the settlement and the process to apply for compensation have been published by claims administrators Kurtzman Carson Consultants.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

NSW Police to embark on $126m IT overhaul

NSW Police to embark on $126m IT overhaul

CBA looks to GenAI to assist 1200 'security champions'

CBA looks to GenAI to assist 1200 'security champions'

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

Woolworths' CSO is Optus-bound

Woolworths' CSO is Optus-bound

Log In

  |  Forgot your password?