We're a community of 1076K IT Pros here for help, advice, solutions, professional growth and fun. Join us!
1,075,939 Members — Technology Publication meets Social Media
Username:
Password:
Lost login information?

Dating disaster: eHarmony confirms passwords exposed by LinkedIn hacker

By Davey Winder on Jun 8th, 2012 6:57 am

One of the Internet's biggest online dating sites, eHarmony, has confirmed that security has been breached and member passwords compromised. eHarmony spokesperson Becky Teraoka says that "a small fraction of our user base has been affected" although I am led to understand that the 'small fraction' in question is actually around 1.5 million. The password hashes were published on a Russian hacking forum, with members asking for help in cracking them and converting the hashes into usable passwords.

dweb-eharmony Sound familiar? Well that's because this has the hand of the LinkedIn password hacker all over it. As DaniWeb reported yesterday, LinkedIn has also confirmed that security was breached and a file containing some 6.5 million password hashes has been published on a Russian hacking forum. That number has now been scaled down slightly to 5.8 million to allow for duplicates that were found, but it's still one heck of big breach with serious consequences for those users whose accounts may be compromised as a result.

Like LinkedIn, eHarmony has acted to mitigate the fallout and Teraoka confirms that "we have reset affected members passwords" and emails are going out to those members with instructions on how to reset them to something different again. Teraoka also insists that "eHarmony uses robust security measures, including password hashing and data encryption, to protect our members’ personal information. We also protect our networks with state-of-the-art firewalls, load balancers, SSL and other sophisticated security approaches." Which all sounds good, but the fact is that those password hashes have still been breached by hackers and if, as it would seem, they are unsalted then it's now open season on cracking them.

Gary Clark from SafeNet says that the eHarmony security breach "highlights once again the weaknesses in the hashed approach to password data protection revealed by the LinkedIn hack" and continues "a good outcome of this new rash of data breaches may be that consumers will demand real not ersatz encryption from their service providers. Hashed passwords simply don’t cut it and offer little real resistance to a determined hacker. Consumers really need to be reassured that their online service providers are taking data protection seriously and are applying end-to-end encryption to ensure users’ details and passwords are adequately protected against the latest security threats."

Ross Brewer, managing director at LogRhythm, points out that "this is the second significant data breach that eHarmony has suffered in less than two years. When taken alongside the latest LinkedIn hack and the spate of other high-profile incidents of late, it’s becoming painfully clear that falling victim to a security breach is now a case of when and not if."

@Davey Winder

I actually remove my info when I heard that, in the end I had to closed my account because there was a security risk that I'm bit surprise that no one at DaniWeb said anything. Meaning members.

LastMitch
Industrious Poster
4,146 posts since Mar 2012
Reputation Points: 132
Solved Threads: 334
Skill Endorsements: 45

So eHarmony's security has been broken again. I have absolutely no jokes about that. None.
But hang on. Doesn't hacking mean those members might get to be contacted by people? That's why they are there in the first place? And if LinkedIn was hacked then once again, the aim of the site is fulfilled. LinkedIn is all about creating new contacts.

gerbil
Industrious Poster
4,452 posts since May 2005
Reputation Points: 253
Solved Threads: 322
Skill Endorsements: 5

Did I read that right?? They didn't salt the hash? Chortles into his spam... :)

diafol
Keep Smiling
Moderator
10,644 posts since Oct 2006
Reputation Points: 1,628
Solved Threads: 1,508
Skill Endorsements: 57

You read it right. They are doing so now though, after the hash horse has bolted through the unslated stable doors...

happygeek
veganarchist
Administrator
28,352 posts since Mar 2006
Reputation Points: 1,603
Solved Threads: 90
Skill Endorsements: 71

Nice article. It gives the detailed overview.

Maximlis
Light Poster
42 posts since Feb 2012
Reputation Points: 0
Solved Threads: 0
Skill Endorsements: 0

hmmm .... so it become so very risky for public, one must remove his or her data from the back up. or in case if still not feel secure then account should have be deactivated.

rubeccamatthews
Newbie Poster
2 posts since Jun 2012
Reputation Points: 0
Solved Threads: 0
Skill Endorsements: 0

Post: Markdown Syntax: Formatting Help
 
You
View similar articles that have also been tagged:
 
© 2013 DaniWeb® LLC
Page rendered in 0.1374 seconds using 2.78MB