Music site joins LinkedIn, eHarmony as victim of password th

In the span of about 24 hours, three major websites have requested that their users change their passwords following apparent heists of millions of credentials.

  Music website Last.fm is the latest to fall prey. On Thursday, the U.K.-based company released a statement announcing it was looking into the matter.

  “We are currently investigating the leak of some Last.fm user passwords,” the statement read. “As a precautionary measure, we're asking all our users to change their passwords immediately.”

  The news comes on the heels of the leak of some 6.5 million passwords belonging to users of LinkedIn, in addition to possibly another 1.5 million passwords connected to members of dating website eHarmony. The passwords, which were protected by an easily crackable encryption format, were posted to a Russian forum by a hacker who was seeking assistance in decoding them.

  Although there is no evidence that directly ties the three attacks, Chester Wisniewski, senior security adviser at SophosLabs, said the timing may imply that they are.

  “There's no evidence so far, but it certainly feels like it,” Wisniewski said. “That's just a gut feeling.”

  While the LinkedIn data was cloaked using a cryptographic hash function, SHA-1, it can still be decoded because additional encryption methods such as salting, which adds a sequence of symbols to passwords before they're hashed, were not implemented. Meanwhile, eHarmony's passwords were disguised using MD-5, a cryptographic hash function that has been known for years to be vulnerable.

  “They shouldn't even have bothered using it,” Wisniewski told SCMagazine.com Thursday. “It's almost as bad as storing them in plain text.”

  Users with profiles or accounts on these websites should replace their passwords with more “complex” characters even if they weren't compromised, Lance James, director of intelligence at Vigilant, a company that offers security monitoring solutions, said in an email to SCMagazine.com.

  “As an example, use a sentence that can be memorized and add symbols and numbers that substitute certain letters,” he said.

  In all three cases, it is unclear how the attackers stole the data. Security experts have offered up a number of possibilities of how the thieves may have gotten to the passwords, including through a defective web application or as a trusted insider.

  A spokesperson for Last.fm did not respond to a request for comment.

(责任编辑:)

分享到:

更多
发表评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
  • 微笑/wx
  • 撇嘴/pz
  • 抓狂/zk
  • 流汗/lh
  • 大兵/db
  • 奋斗/fd
  • 疑问/yw
  • 晕/y
  • 偷笑/wx
  • 可爱/ka
  • 傲慢/am
  • 惊恐/jk
用户名: 验证码:点击我更换图片
资料下载专区
图文资讯

英国官员:让华为参与英国5G建设风险可控

英国官员:让华为参与英国5G建设风险可控

2月21日,英国金融时报报道称,在布鲁塞尔发表的一次演讲中,英国信号情报机构政府通...[详细]

西媒:以色列打造网络安全“硅谷”

西媒:以色列打造网络安全“硅谷”

2月13日报道 西媒称,凭借每年超过10亿美元的企业投资,以色列已经成为全球网络安全领...[详细]

俄罗斯力推脱离互联网计划 确保应急状态下

俄罗斯力推脱离互联网计划 确保应急状态下网络安全

俄罗斯新闻机构 RosBiznesKonsalting(RBK)上周报道称:作为计划实验的一部分,当局正...[详细]

GSMA呼吁欧洲守住网络安全和网络基建供应竞

GSMA呼吁欧洲守住网络安全和网络基建供应竞争力

5G将改变欧洲公民的生活和工作方式。5G作为现有4G网络的补充,与之协同工作将比以往更...[详细]

涉嫌窃取近千政界人士信息 德国20岁黑客遭

涉嫌窃取近千政界人士信息 德国20岁黑客遭逮捕

涉嫌窃取德国近千政界人士信息的黑客落网 政府拟修法加强网络安全 德国当局8日宣布,...[详细]

返回首页 返回顶部