Stories
Slash Boxes
Comments

SoylentNews is people

posted by takyon on Wednesday August 19 2015, @01:30AM   Printer-friendly
from the find-your-own-torrent dept.

Multiple reports suggest that Impact Team has leaked around 9.6 to 10 gigabytes of data from the "cheating/affair website" Ashley Madison onto Tor sites (now available via BitTorrent). According to Ars Technica:

A 10-gigabyte file purportedly containing e-mails, member profiles, credit-card transactions and other sensitive Ashley Madison information became available as a BitTorrent download in the past few hours. Ars downloaded the massive file and it appeared to contain a trove of details taken from a clandestine dating site, but so far there is nothing definitively linking it to Ashley Madison. User data included e-mail addresses, profile descriptions, addresses provided by users, weight, and height. A separate file containing credit card transaction data didn't include full payment card numbers or billing addresses.

Rob Graham, CEO of Errata Security, said the dump also included user passwords that were cryptographically protected using the bcrypt hashing algorithm. That's among the most secure ways to store passwords, because bcrypt is extremely slow, a trait that requires crackers to devote vast amounts of time and computing resources. Still, it's highly likely a large percentage of the hashes will be cracked, given rampant use of weak passwords.

Ashley Madison officials have stopped short of confirming the published information was extracted from the breach.

"We have now learned that the individual or individuals responsible for this attack claim to have released more of the stolen data," they wrote in an e-mail to Ars. "We are actively monitoring and investigating this situation to determine the validity of any information posted online and will continue to devote significant resources to this effort. Furthermore, we will continue to put forth substantial efforts into removing any information unlawfully released to the public, as well as continuing to operate our business."

Previously: Adult 'Extracurricular Activity' Website AshleyMadison.com Hacked


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0) by Anonymous Coward on Wednesday August 19 2015, @05:11AM

    by Anonymous Coward on Wednesday August 19 2015, @05:11AM (#224814)

    You could download the data yourself and check.

  • (Score: 4, Funny) by jasassin on Wednesday August 19 2015, @05:32AM

    by jasassin (3566) <jasassin@gmail.com> on Wednesday August 19 2015, @05:32AM (#224823) Homepage Journal

    You could download the data yourself and check.

    I did. Every girlfriend I've had was on there. Oh well, I'm officially becoming celebate, and have already made my appointment for the clinic.

    --
    jasassin@gmail.com GPG Key ID: 0xE6462C68A9A3DB5A
    • (Score: 0) by Anonymous Coward on Wednesday August 19 2015, @07:29PM

      by Anonymous Coward on Wednesday August 19 2015, @07:29PM (#225137)

      > Oh well, I'm officially becoming celebate, and have already made my appointment for the clinic.

      Celebate good times, come on! (Let's celebate)
      Celebate good times, come on! (Let's celebate)

      There's a party goin' on right here
      A celebation to last throughout the years
      So bring your good times, and your laughter too
      We gonna celebate your party with you

      Come on now

      Celebation
      Let's all celebate and have a good time
      Celebation
      We gonna celebate and have a good time

  • (Score: 0) by Anonymous Coward on Wednesday August 19 2015, @09:14AM

    by Anonymous Coward on Wednesday August 19 2015, @09:14AM (#224893)

    Yes, I could, and maybe I even would.

    Where do I go for the download? This is not a rhethorical question.

    The best information I've seen so far is that it was released "on the darknet". I realize that a) a search engine probably won't help me and b) going to www.darknet.com will not be useful either. But I'm still naive enough to not know where I would obtain those 10GB.

    Since I only have a passing interest (most of their members live on a different continent), I also will not embark on a week-long quest to become knowledgable in black-hatty things like "Where do I download stolen data?".