/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

How the full dump of LinkedIn passwords from 2012 hack will speed cracking of hashed passwords from any future breaches

Second data dump lets hackers be 6 times better cracking future dumps. … Me: “The full dump from the 2012 LinkedIn breach just dropped, so you're probably not going to see much of me over the next week.” Tweets: @tinolle , @alexcryptan , @dannynemer , @tadegbesan and @joshconstine Tweets: Milos Constantin / @tinolle : 180 million passwords, 98% cracked in one week. #LinkedIn ** http://arstechnica.com/... http://twitter.com/..." Alex Biryukov / @alexcryptan : LinkedIn used unsalted SHA-1 for password storage in 2012. 180 million passwords, 98% cracked in one week. http://goo.gl/HtAuLW Danny Nemer / @dannynemer : Password breaches of a few services endangers all via statistical data improving brute force http://arstechnica.com/... pic.twitter.com/CjCBuMRpD1 Tunji Adegbesan / @tadegbesan : “Using a single Sagitta HPC Brutalis wit 8 Nvidia GTX Titan X cards I managed2 recover 85% of passwords the 1st day” http://arstechnica.com/... Josh Constine / @joshconstine : Thx, LinkedIn. Such lazy security let its passwords be cracked, giving hackers a cheat sheet for future breaches http://arstechnica.com/...

Ars Technica Jeremi M. Gosney

Context & Ripple Effects

The full dump lands weeks after 117M LinkedIn email-and-password pairs from the same 2012 breach were offered for sale on a dark web marketplace, prompting LinkedIn to contact affected users. What changed now is scale and completeness: the new release exposes roughly 180 million passwords, and because LinkedIn stored them as unsalted SHA-1, cryptographer Alex Biryukov reports 98% were cracked within a week.

The timing matters for the rest of the breach economy. The same seller behind the LinkedIn sale claims to hold 360M Myspace user emails with passwords, so every additional cracked plaintext from LinkedIn feeds directly into attacks on users who reused credentials across those services.

First-order effects

  • LinkedIn users whose 2012 passwords are now effectively public face immediate account-takeover risk wherever they reused those credentials, and defenders lose the obscurity that partial leaks previously provided.
  • Attackers gain a verified training set of ~180 million real password choices, reported to make cracking of hashed passwords in future breaches up to ~6x more effective.

Second-order effects

  • Any service whose users overlapped with LinkedIn — starting with the Myspace trove already claimed for sale — becomes cheaper to attack, since cracked LinkedIn plaintexts double as candidate passwords elsewhere.
  • Password-cracking economics shift toward GPU rigs like the GTX Titan X setups named in the coverage, making hardware investment in cracking more attractive as each new dump raises its yield.

Third-order effects

  • Old breaches stop expiring: hashed corpora accumulate into permanent cracking dictionaries, a pattern the 2019 distribution of Collections #2-5 — 25 billion records — shows compounding at scale.
  • If legacy hashing schemes keep failing this way, the structural pressure moves toward salted, slow hashing and multi-factor authentication as baseline requirements rather than options, since password secrecy alone can no longer be assumed durable.

The trend: Breach data is becoming a compounding asset — each dumped password corpus makes the next breach faster to crack, steadily eroding the password as a standalone defense.