LinkedIn cookies compromise user accounts

Research claims the corporate social network could put users at risk.

LinkedIn

A security researcher has claimed LinkedIn's use of cookies leaves user accounts open to attacks.

The independent researcher, Rishi Narangreported, wrote on his blog that cookies of the social networking site for business people may be active for up to a year, meaning if a hacker can access the relevant file, they can continually access a user's account.

After the login process, LinkedIn creates a file on the user's computer which the site then uses for quicker access later on, just like cookies on many other sites. However, the extended expiry time means a bigger window of opportunity for cyber criminals.

LinkedIn uses SSL encrypting to protect data, including login details, but this does not extend to the cookies which hackers can access by monitoring traffic with sniffing' tools.

Narang also explained the cookies were active even after a user had logged out of their session.

"There are examples where cookies are accessible to hijack authenticated sessions and these cookies are months old," he said.

"In just 15 minutes, I was successfully able to access multiple active accounts that belong to individuals from different global locations. They would have logged in/logged out many times in these months but their cookie was still valid."

"Even though you change the password and all settings, still the old cookie is valid and will grant the attacker access to your account," he added.

A spokesperson from LinkedIn told IT PRO the company was looking into stronger SSL protection, but didn't go as far to say the research was right or wrong.

"LinkedIn takes the privacy and security of our members seriously so, among other security measures, we currently support SSL for logins and other sensitive web pages," they said.

"In addition, we seek to improve our site's security and are, for instance, evaluating opt-in SSL support for other parts of the site and expect those to be available in the coming months. Using SSL effectively scrambles cookies sent between servers and users' computers."

The news will come as a blow to LinkedIn after a successful week. The company went public on Friday and blew estimates of a $3 billion (1.86 billion) valuation out of the window when shares trebled. At the close of its first day trading, the social network was said to be worth $9 billion.

Featured Resources

BCDR buyer's guide for MSPs

How to choose a business continuity and disaster recovery solution

Download now

The definitive guide to IT security

Protecting your MSP and your customers

Download now

Cost of a data breach report 2020

Find out what factors help mitigate breach costs

Download now

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Recommended

Data breach exposes widespread fake reviews on Amazon
data breaches

Data breach exposes widespread fake reviews on Amazon

7 May 2021
TsuNAME vulnerability could enable DDoS attacks on major DNS servers
distributed denial of service (DDOS)

TsuNAME vulnerability could enable DDoS attacks on major DNS servers

7 May 2021
What are SSH keys?
cyber security

What are SSH keys?

7 May 2021
Google’s about to push everyone into two-factor authentication
Security

Google’s about to push everyone into two-factor authentication

6 May 2021

Most Popular

KPMG offers staff 'four-day fortnight' in hybrid work plans
flexible working

KPMG offers staff 'four-day fortnight' in hybrid work plans

6 May 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

29 Apr 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

30 Apr 2021