[2896] in Privacy_Forum
[ PRIVACY Forum ] LinkedIn and eHarmony reportedly did not "salt"
daemon@ATHENA.MIT.EDU (PRIVACY Forum mailing list)
Thu Jun 7 16:06:51 2012
Date: Thu, 7 Jun 2012 12:51:17 -0700
To: privacy-list@vortex.com
Message-ID: <20120607195117.GB9701@vortex.com>
MIME-Version: 1.0
Content-Disposition: inline
From: PRIVACY Forum mailing list <privacy@vortex.com>
Reply-To: PRIVACY Forum mailing list <privacy@vortex.com>
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: privacy-bounces+privacy-forum=mit.edu@vortex.com
Content-Transfer-Encoding: 8bit
LinkedIn and eHarmony reportedly did not "salt" their password hashes
http://j.mp/LfSauj (Security News Daily)
"LinkedIn and eHarmony encrypted, or "hashed," the passwords of
registered users, but neither salted the hashes with random data that
would have made them much more difficult to decrypt. Without salting,
it's very easy to crack"
- - -
For LinkedIn and eHarmony to have reportedly not been "salting" their
password cryptographic systems amounts to gross negligence.
UNIX/Linux systems have been routinely using salted functions for
decades. This isn't rocket science. There is *no* excuse.
--Lauren--
Lauren Weinstein (lauren@vortex.com): http://www.vortex.com/lauren
Co-Founder: People For Internet Responsibility: http://www.pfir.org
Founder:
- Data Wisdom Explorers League: http://www.dwel.org
- Network Neutrality Squad: http://www.nnsquad.org
- Global Coalition for Transparent Internet Performance: http://www.gctip.org
- PRIVACY Forum: http://www.vortex.com
Member: ACM Committee on Computers and Public Policy
Lauren's Blog: http://lauren.vortex.com
Google+: http://vortex.com/g+lauren / Twitter: http://vortex.com/t-lauren
Tel: +1 (818) 225-2800 / Skype: vortex.com
_______________________________________________
privacy mailing list
http://lists.vortex.com/mailman/listinfo/privacy