CNET NEWS – June 26 – An analysis of passwords stolen from eHarmony and leaked to the Web recently reveals several problems with the way eHarmony handled password encryption and policies, according to a security expert. The biggest problem clearly was that the passwords, although encrypted and obscured with a hashing algorithm, were not "salted," which would have increased the amount of work password crackers would need to do, writes Mike Kelly, a security analyst at Trustwave SpiderLabs. 99.5% of the passwords did not contain a special character, but 57% contained letters and numbers. Also, the word "love" was the most commonly occurring password of those that were examined, the analysis found.
by Elinor Mills
See full article at CNet News
