Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - LinkedIn Accounts Open To Hijackin
Articles

LinkedIn Accounts Open To Hijackin

ISBuzz TeamBy ISBuzz TeamJune 24, 20144 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
man-in-the-middle
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

LinkedIn was recently exposed to be subject to man in the middle attacks.  Michael Sutton of Zscaler and Richard Cassidy from Alert Logic share their views on this issue.

Michael Sutton, VP Security Research at Zscaler:

“I wouldn’t consider this a vulnerability, but rather a transition to enhanced security that is not yet complete. Zimperium is pointing out the fact that LinkedIn does not yet default to and enforce SSL only for all users worldwide. Many web applications are implementing SSL only connectivity due to increasing privacy concerns. LinkedIn is moving in this direction and started transitioning all users to SSL only pages in December 2013 but the transition is ongoing. While we might wish that the transition would move faster, LinkedIn should be applauded for moving in this direction. All web properties should take note and follow the example set by the likes of LinkedIn, Google, Facebook, etc. all of which have moved to SSL only by default.”

Richard Cassidy, Senior Solutions Architect for Alert Logic:

“The concept of MITM attacks has been around a long while now and with the inception of SSL over HTTP (HTTPS) we heralded a new era in online communications that would now allow us to share sensitive data over the public networks without fear of personal details being caught by those men who live in the middle and who love to steal data from any unsuspecting user. That said, things came crashing down when SSL Sniffing was announced to the world and then again, when SSL stripping was released at a Blackhat conference some years ago, should we even mention the more recent “HeartBleed”- perhaps not!

Organisations have since long been working on new and clever(er) ways to thwart the latest spout of MITM attacks against their HTTP and HTTPS sites; The release of HSTS standard, saw a promising response to MITM type threats. Organisations have been considering (and implementing) more advanced countermeasures through NAC solutions or more pro-active network infrastructure equipment to detect ARP-Poisoning at a port (rather than gateway only) level and so on and so forth, all to help reduce the risk of their networks being the source of MITM threats.

The specific threat mentioned against LinkedIn quite simply utilised a well-known MITM attack tool, to re-direct the user to a non-secure version of the site. An unsuspecting (typical) user may simply ignore the warnings that the browser provides when being re-directed to an unsecure version of the site they are accessing, or when a certificate may not be verified. We know that LinkedIn were contacted by a “security group” back in 2013 advising them of the exploit against their services and we can read that they acknowledge this by stating they were transitioning their sites to HTTPS (SSL) only. What we didn’t see was any announcement back then to their customers about the threat of a MITM attack and how users could better protect themselves who might still be accessing old clear-text services or connecting to LinkedIn on open AP’s at coffee shops, hotels, restaurants, etc. We have to appreciate that as users we have to assume a level of responsibility for our own security when accessing publicly available e-services, but there is a level of responsibility on part of the service-provider to ensure we are as educated as possible on “best practices” when accessing their services, in addition to regular updates on what they are doing for the users to further enhance the security of their services.

Unfortunately, there is only so much organisations – such as LinkedIn – can do proactively, to prevent MITM attacks from being successful; In my opinion we still live in a very reactive world from a security perspective, where – for many organisations – security processes are the necessity of exploit attempts (whether successful or not) and (in the context of MITM attacks) the battle is almost always with end-users and how they interact with the websites they’re accessing.  That said however, organisations would clearly benefit from enhancing their web services security to end users by implementing HSTS, or providing SSL access as standard. Users would benefit greatly from regular notifications via their portals on “best-practices” in maintaining their security status when accessing the services from public locations. The better you communicate with your users on the subject of security, the greater the degree of education and the lower the risk on all fronts to both parties. Transparency therefore has to be the first point of order when events such as these are brought to the attention of our providers, followed very closely by users doing their part to ensure a safer browsing experience by paying closer attention to how and what they are accessing on the internet when connecting to trusted providers.”

Click here to subscribe to our weekly round-up!

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}