Ashley Madison, the online-dating site, was hacked in July and users’ personal information was released by the hackers last month. The users were, however, a little relaxed as their passwords were encrypted and would take years to crack.
But in a major twist to the case, a group going by the name “Cynosure Prime” has revealed in a blog post how they have already cracked over 11 million passwords within days.
The passwords were cryptographically protected using bcrypt, a cryptographic hashing algorithm so strong that it would take years for even a highly specialised computer to crack all the passwords.
After reviewing thousands of lines of code leaked along with the hashed passwords, executive e-mails, and other Ashley Madison data, the Cynosure Prime team made an interesting discovery: some of the login tokens used by the website were protected using MD5, a hashing algorithm that was designed for speed and efficiency rather than slowing down crackers.
All the team had to do then was just brute-force the MD5 tokens of the user accounts, which allowed them to acquire 11.2 Million passwords successfully.
As the weak MD5 hashing algorithm was introduced only June 2012, the team could’nt crack all of the 37 million Ashley Madison passwords. However, researchers estimated that approximately 15 million Ashley Madison accounts could be affected, out of which 11.2 Million have been already deciphered by the team.


Apple Leads Singles’ Day Smartphone Sales as iPhone 17 Demand Surges
Intel Boosts Malaysia Operations with Additional RM860 Million Investment
Senate Sets December 8 Vote on Trump’s NASA Nominee Jared Isaacman
Vietnam’s Growing Use of Chinese 5G Technology Raises Western Concerns
Amazon and Google Launch New Multicloud Networking Service to Boost High-Speed Cloud Connectivity
Quantum Systems Projects Revenue Surge as It Eyes IPO or Private Sale
Morgan Stanley Boosts Nvidia and Broadcom Targets as AI Demand Surges
Norway’s Wealth Fund Backs Shareholder Push for Microsoft Human-Rights Risk Report
Microchip Technology Boosts Q3 Outlook on Strong Bookings Momentum
AI-Guided Drones Transform Ukraine’s Battlefield Strategy
OpenAI Moves to Acquire Neptune as It Expands AI Training Capabilities
Wikipedia Pushes for AI Licensing Deals as Jimmy Wales Calls for Fair Compensation
Hikvision Challenges FCC Rule Tightening Restrictions on Chinese Telecom Equipment
Trump Administration to Secure Equity Stake in Pat Gelsinger’s XLight Startup
ByteDance Unveils New AI Voice Assistant for ZTE Smartphones
EU Prepares Antitrust Probe Into Meta’s AI Integration on WhatsApp
YouTube Agrees to Follow Australia’s New Under-16 Social Media Ban 



