Online dating site eHarmony has confirmed that a massive list of passwords posted online included those used by its members.
"After investigating reports of compromised passwords, we have found that a small fraction of our user base has been affected," company officials said in a blog post published Wednesday evening. The company didn't say what percentage of 1.5 million of the passwords, some appearing as MD5 cryptographic hashes and others converted into plaintext, belonged to its members.
eHarmony's blog also omitted any discussion of how the passwords were leaked. That's unsettling, because it means there's no way to know if the lapse that exposed member passwords has been fixed. Instead, the post repeated mostly meaningless assurances about the website's use of "robust security measures, including password hashing and data encryption, to protect our members personal information." Oh, and company engineers also protect users with "state-of-the-art firewalls, load balancers, SSL and other sophisticated security approaches."
The company recommended users choose passwords with eight or more characters that include upper- and lower-case letters, and that those passwords be changed regularly and not used across multiple sites.