eHarmony had several password security fails

JMH

Emeritus, Contributor
Joined
Apr 2, 2012
Posts
7,197
An analysis of passwords stolen from eHarmony and leaked to the Web recently reveals several problems with the way the dating site handled password encryption and policies, according to a security expert.

The biggest problem clearly was that the passwords, although encrypted and obscured with a hashing algorithm, were not "salted," which would have increased the amount of work password crackers would need to do, writes Mike Kelly, a security analyst at Trustwave SpiderLabs, in a blog post today.

http://news.cnet.com/8301-1009_3-57...?part=rss&tag=feed&subj=News-Security&Privacy
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top