LinkedIn slashes cookie lifespan after research exposes security flaws

    Date24 May 2011
    CategoryLatest News
    4430
    Posted ByDave Wreski
    LinkedIn said it would reduce the persistence of cookies it uses to identify users of the business-focused social networking site following the discovery of security issues with the site that create a possible means for fraudsters to hijack profiles. Security researcher Rishi Narang discovered that LinkedIn session cookies are transmitted over an unsecured HTTP connection even in cases where users follow the option of signing in over a secure (SSL) connection. These cookies remain active for up to a year. Hackers who captured these cookies, perhaps using a tool such as Firesheep to sniff out cookies transmitted over open Wi-Fi connections, would be able to obtain unauthorised access to other users' accounts.

    The LEO_AUTH_TOKEN cookie grants access to an associated account irrespective of whether or not users are logged in at the time, Narang warns. These cookies work for up to a year or until a user changes their password and logs in using this new password, generating a fresh authentication token. LinkedIn boasts more than 100 million registered users, a factor that inevitably makes it of interest to miscreants.

    You are not authorised to post comments.

    LinuxSecurity Poll

    Do you reuse passwords across multiple accounts?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 2 answer(s).
    /component/communitypolls/?task=poll.vote
    13
    radio
    [{"id":"55","title":"Yes","votes":"5","type":"x","order":"1","pct":45.45,"resources":[]},{"id":"56","title":"No","votes":"6","type":"x","order":"2","pct":54.55,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    Advisories

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.