NEWS / SOCIAL NETWORKING

LinkedIn's Cookies Are Crumbling

25 May, 2011, 1:30 pm IST | by Padmini Harchandrai | Social Networking

LinkedIn user accounts are vulnerable to hacking because of the way the social networking site handles its cookies. The warning was made by Rishi Narang, a consultant at Hackers Locked, a security firm. LinkedIn, not unlike many other sites uses cookies that are stored on users' browers which facilitate log-ins without re-inputing login information, however Narang points out that the way LinkedIn handles these cookies isn't the best.

 

Narang says in particular there are two cookie-related vulnerabilities. The first is from LinkedIn's SSL cookies which don't use a secure SSL flag, which means that session credentials are seen in plaintext. A man-in-the-middle attack is highly possible in this scenario which could be launched by a third party website by remotely redirecting a user to the HTTPS log-in page for LinkedIn, and watching the relevant credentials being passed back and forth. All LinkedIn needs to do to fix this is use the secure flag on any cookies that are used with an HTTPS page, such as the log-in page.

 

The other vulnerability is that LinkedIn has set its cookies to not expire for a whole year and doesn't cancel cookies once a user logs out. With cookies in hand, a violater can then authenticate as another user. LinkedIn's said it's working on related improvements but for now, users should try to access LinkedIn over secured networks.

Tags: Social Networking , LinkedIn , Security , Privacy , Cookies , SSL , Internet , Web Services

RELATED STORIES

Cavemen had their own social networks

Cavemen had their own social networks

In yet another study comparing cavemen to modern day living, it was found that even cavemen had their own ...

Under-13 joining limit on Facebook to go

Microsoft redesigns Bing, plays up Facebook link

Alternatives to Youtube catch on with mobile crowd

Have a break from social media have a KitKat... app

Kuwait to regulate social networking sites

Facebook launches patent counterattack against Yahoo

Social Networking?

23 Apr, 2012, 06:58 am IST

Social Networking?

Social Networking Sites - Beneficial or Dangerous? - ControversialZack

19 Oct, 2011, 02:52 am IST

Social Networking Sites - Beneficial or ...

What is Social Networking?

21 Feb, 2012, 12:24 am IST

What is Social Networking?

Social networking via SMS in Pakistan

02 Apr, 2012, 11:29 am IST

Social networking via SMS in Pakistan

 

OPINIONS

Padmini Harchandrai

The latest "should they-shouldn't they" event with Facebook is the lift of the minimu...

MORE OPINIONS

Leaked Images, Availability, Pricing,
Specs, Pre-order

features

YouTube with a Twist

YouTube with a Twist

YouTube is the most preferred and undoubtedly the most popular video...

By Priyanka Tilve

Social Gifting: The next hot trend?

Social Gifting: The next hot trend?

Social networks have knitted the world too close, and everything one does

By Naina Khedekar

10 must-have Google Chrome extensions

10 must-have Google Chrome extensions

Despite Microsoft’s IE gaining its market share and numerous Mozilla...

By Naina Khedekar

MORE FEATURES

Asus Eee Pad Transformer Prime TF201 Review

Larry Browne

Mon May 28, 01:36:07

Samsung blocks S-Voice feature on non-Galaxy S III devices

Moud Hanad Anaas

Mon May 28, 00:52:13

Nokia 808 PureView to launch in India this month

Bhagat Dheeraj

Mon May 28, 00:03:09

MORE DISCUSSIONS