Social site Formspring hacked, passwords disabled

July 11, 2012

(AP) — Social networking site Formspring said Tuesday that it was disabling nearly 30 million registered users' passwords after hundreds of thousands of them were leaked to the Web in their encrypted form.

Formspring said in a blog post that the breach happened after someone hacked into one of the San Francisco-based company's servers.

Spokeswoman Dorothee Fisher said Wednesday the company was alerted Monday that some 420,000 encrypted passwords had showed up on a security forum whose identity she refused to disclose because she did not want to draw attention to it.

Encrypted passwords aren't immediately useable, although they can sometimes be decoded by a savvy attacker.

Fisher said there was no evidence that any accounts had been tampered with.

Formspring founder Ade Olonoh said in a blog post that his company had fixed the vulnerability and upgraded its encryption, adding that the company wanted to "play it safe" and had asked all users to reset their passwords.

"We take this matter very seriously and continue to review our internal security policies and practices to help ensure that this never happens again," he said.

Formspring launched in 2009 as a crowd-powered question-and-answer site. Last month, the company announced a major revamp intended to shift the site's focus toward users' interests.

Explore further: Some LinkedIn, eHarmony passwords leaked online (Update 3)


Related Stories

Password breach spreads beyond LinkedIn

June 7, 2012

More websites admitted security breaches Thursday after LinkedIn said some of its members' passwords were stolen, and experts warned of email scams targeting users of the social network.

Company says YouPorn chat service compromised

February 22, 2012

(AP) -- Users of a chat service linked to the heavily-trafficked YouPorn website have had their personal information compromised after a third-party service provider failed to secure its data, YouPorn's owners said Wednesday.

Hacker claims porn site users compromised

February 13, 2012

A hacker claims to have compromised the personal information of more than 350,000 users after breaking into a disused website operated by pornography provider Brazzers.

Recommended for you

Microsoft aims at Apple with high-end PCs, 3D software

October 26, 2016

Microsoft launched a new consumer offensive Wednesday, unveiling a high-end computer that challenges the Apple iMac along with an updated Windows operating system that showcases three-dimensional content and "mixed reality."

Making it easier to collaborate on code

October 26, 2016

Git is an open-source system with a polarizing reputation among programmers. It's a powerful tool to help developers track changes to code, but many view it as prohibitively difficult to use.

Dutch unveil giant vacuum to clean outside air

October 25, 2016

Dutch inventors Tuesday unveiled what they called the world's first giant outside air vacuum cleaner—a large purifying system intended to filter out toxic tiny particles from the atmosphere surrounding the machine.

1 comment

Adjust slider to filter visible comments by rank

Display comments: newest first

not rated yet Jul 11, 2012
I suspect the "encryption" was hashing and the "upgrade" was MD5 to SHA2. And they don't salt their hashes.

Maybe people should start suing web sites that do this.

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.