TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Updating Your Password on LinkedIn and Other Account Security Best Practices

19 点作者 bwag将近 13 年前

6 条评论

sofal将近 13 年前
<i>Substitute numbers for letters that look similar (for example, substitute “0″ for “o” or “3″ for “E”.</i><p>Am I correct in thinking that the amount of entropy added with cute tricks like this is essentially nil? Is this advice even remotely valid?<p><i>Never give your password to others or write it down.</i><p>I don't think the advice to never write your password down is very useful unless coupled with a better way to manage all of your passwords besides memorizing them (like a password manager).
评论 #4075321 未加载
评论 #4075774 未加载
评论 #4075714 未加载
评论 #4075825 未加载
jgrahamc将近 13 年前
Seems foolish for them to have posted this. It's not very good advice on choosing a password and feels like the wrong response to the story about passwords apparently having been leaked.
评论 #4075870 未加载
Yoms将近 13 年前
This is getting silly now, the hash for my unique strong password was in the list. And there are many others who have stated the same. It should have taken them a whole of 5 minutes to find if these hashes were from their database. It's shameful and shows an utter disrespect for security that they didn't bother salting them (and sha1 really?).<p>Now it's time for them to own up to the mistake and inform their users, before anyone has anything else compromised.
lawnchair_larry将近 13 年前
From the updated blog entry:<p><i>"It is worth noting that the affected members who update their passwords and members whose passwords have not been compromised benefit from the enhanced security we just recently put in place, which includes hashing and salting of our current password databases."</i><p>Still doing it wrong I see.
评论 #4076112 未加载
martian将近 13 年前
The Dropbox post on passwords (and their password strength estimation tool) is much better at describing what strong passwords actually are.<p><a href="http://tech.dropbox.com/?p=165" rel="nofollow">http://tech.dropbox.com/?p=165</a><p>The advice from LinkedIn like "Don't use a word from the dictionary" and "Substitute numbers for letters that look similar (for example, substitute “0″ for “o” or “3″ for “E”." are security theater.
ajays将近 13 年前
" <i>At this time, we’re still unable to confirm that any security breach has occurred</i> ..."<p>Really? How long does it take to verify that this breach is accurate and sound an alarm?
评论 #4075853 未加载