{"id":267,"date":"2012-06-08T02:21:01","date_gmt":"2012-06-08T02:21:01","guid":{"rendered":"http:\/\/www.redesigns.org\/web-builder\/blog\/?p=267"},"modified":"2024-01-21T00:33:06","modified_gmt":"2024-01-21T08:33:06","slug":"linkedin-eharmony-social-networking-sites-hacked-passwords-leaked-poor-security","status":"publish","type":"post","link":"https:\/\/www.ultimatewb.com\/blog\/267\/linkedin-eharmony-social-networking-sites-hacked-passwords-leaked-poor-security\/","title":{"rendered":"LinkedIn, eHarmony social networking sites hacked, passwords leaked, poor security"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/linkedin.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"268\" src=\"https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/linkedin-1024x268.png\" alt=\"\" class=\"wp-image-4502\" style=\"aspect-ratio:3.8208955223880596;width:627px;height:auto\" srcset=\"https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/linkedin-1024x268.png 1024w, https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/linkedin-300x79.png 300w, https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/linkedin-768x201.png 768w, https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/linkedin-1536x403.png 1536w, https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/linkedin-2048x537.png 2048w\" sizes=\"(max-width: 600px) 100vw, (max-width: 1200px) 75vw, 1200px\" \/><\/a><\/figure>\n\n\n<p>LinkedIn, a popular professional social networking website, and eHarmony, a paid subscription social networking dating site, both\u00a0confirmed Wednesday their sites have been hacked.\u00a0 The breach in the database security was found when the hacker(s) posted the list of 8 million encrypted passwords on a hacker forum, asking for help to break the encryption code.\u00a0<\/p>\n<p><\/p>\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/eharmony.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-4504 alignleft\" src=\"https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/eharmony-1024x489.jpg\" alt=\"\" width=\"482\" height=\"230\" srcset=\"https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/eharmony-1024x489.jpg 1024w, https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/eharmony-300x143.jpg 300w, https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/eharmony-768x367.jpg 768w, https:\/\/www.ultimatewb.com\/blog\/wp-content\/uploads\/eharmony.jpg 1400w\" sizes=\"(max-width: 600px) 100vw, (max-width: 1200px) 75vw, 1200px\" \/><\/a><\/figure>\n<p><\/p>\n<p>According to <a title=\"Sophos\" href=\"http:\/\/nakedsecurity.sophos.com\/2012\/06\/06\/linkedin-confirms-hack-over-60-of-stolen-passwords-already-cracked\/\" target=\"_blank\" rel=\"nofollow noopener\">Sophos security reports<\/a>, more than 60% of the passwords have already been cracked.\u00a0 Tech news site Ars Technica said it found about 1.5 million of those leaked passwords to be from eHarmony users.\u00a0 It is possible that all the passwords have been compromised and hacked from the sites&#8217; database, as Rick Redman, a security consultant for Kore Logic Security told <a title=\"Arts Technica\" href=\"http:\/\/arstechnica.com\/security\/2012\/06\/8-million-leaked-passwords-connected-to-linkedin\/\" target=\"_blank\" rel=\"nofollow noopener\">Ars Technica<\/a>, &#8220;It&#8217;s pretty obvious that whoever the bad guy was cracked the easy ones and then posted these, saying, &#8216;These are the ones I can&#8217;t crack.'&#8221;\u00a0 If you&#8217;re a user on either of these two social networking sites, it is best that you change your password asap &#8211; especially if you have been using the same password for different websites, and even worse for data-sensitive websites such as online banking, which is highly recommended against.<\/p>\n<p>How did the hackers gain access to the sites&#8217; database? Most likely there were security holes in their coding that need to be patched. Poorly formed mysql database queries, for example, can be taken advantage of and manipulated to print out database data to the hacker&#8217;s internet browser.\u00a0 Also, the storage of passwords were not secure enough.\u00a0<a title=\"LinkedIn blog\" href=\"http:\/\/blog.linkedin.com\/2012\/06\/06\/linkedin-member-passwords-compromised\/\" target=\"_blank\" rel=\"nofollow noopener\">LinkedIn<\/a> encrypted passwords, but did not &#8220;salt&#8221; them &#8211; a process whereby random characters are introduced in the encryption process to make the password cracking harder.\u00a0 LinkedIn has corrected this security weakness and now encrypts and salts new passwords.\u00a0 EHarmony apparently was also using weak encryption policies.\u00a0 While they are advising members how to choose strong passwords in their <a title=\"EHarmony blog\" href=\"http:\/\/advice.eharmony.com\/blog\/2012\/06\/06\/update-on-compromised-passwords\/\" target=\"_blank\" rel=\"nofollow noopener\">eHarmony blog<\/a>, they make no mention of any security measures taken by the company to increase security.\u00a0 A strong password is not much use if the website is not storing it properly.<\/p>\n<p>According to the <a title=\"Techlicious blog\" href=\"http:\/\/www.techlicious.com\/blog\/linkedin-eharmony-confirm-passwords-were-hacked\/\" target=\"_blank\" rel=\"nofollow noopener\">Techlicious blog<\/a>, &#8220;Because eHarmony has yet to adequately address the security measures they are putting in place to protect this breach from happening again, you should consider any password and personal information you post to eHarmony as insecure.&#8221; Anyways, we recommend the totally free dating site <a title=\"Friends Match Me free dating site, Facebook dating\" href=\"http:\/\/www.friendsmatchme.com\" target=\"_blank\" rel=\"noopener\">Friends Match Me<\/a>. Built on Ultimate Web Builder software, it is also a free Facebook dating app and doesn&#8217;t store any user passwords in the website database&#8230;besides it is a really cool and awesome dating site!<\/p>\n<p>How to handle member account\/password security on your website?\u00a0 Ultimate Web Builder software uses the latest recommended security policies, employing an encryption process with &#8220;salting&#8221; for password database storage.\u00a0 Moreover, you can avoid brute force password guessing by setting limits on users trying to login unsuccessfully repeatedly, both on the members side and admin panel side.<\/p>","protected":false},"excerpt":{"rendered":"<p>LinkedIn, a popular professional social networking website, and eHarmony, a paid subscription social networking dating site, both\u00a0confirmed Wednesday their sites have been hacked.\u00a0 The breach in the database security was found when the hacker(s) posted the list of 8 million &hellip; <a href=\"https:\/\/www.ultimatewb.com\/blog\/267\/linkedin-eharmony-social-networking-sites-hacked-passwords-leaked-poor-security\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[199,621,336],"tags":[208,207,209,206],"class_list":["post-267","post","type-post","status-publish","format-standard","hentry","category-social-networking","category-technology-in-the-news","category-website-security-2","tag-eharmony","tag-linkedin","tag-passwords-hacked","tag-website-security"],"_links":{"self":[{"href":"https:\/\/www.ultimatewb.com\/blog\/wp-json\/wp\/v2\/posts\/267"}],"collection":[{"href":"https:\/\/www.ultimatewb.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ultimatewb.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ultimatewb.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ultimatewb.com\/blog\/wp-json\/wp\/v2\/comments?post=267"}],"version-history":[{"count":6,"href":"https:\/\/www.ultimatewb.com\/blog\/wp-json\/wp\/v2\/posts\/267\/revisions"}],"predecessor-version":[{"id":4505,"href":"https:\/\/www.ultimatewb.com\/blog\/wp-json\/wp\/v2\/posts\/267\/revisions\/4505"}],"wp:attachment":[{"href":"https:\/\/www.ultimatewb.com\/blog\/wp-json\/wp\/v2\/media?parent=267"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ultimatewb.com\/blog\/wp-json\/wp\/v2\/categories?post=267"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ultimatewb.com\/blog\/wp-json\/wp\/v2\/tags?post=267"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}