Social Site Formspring's 420,000 Passwords Compromised



Bangalore: Social networking site Formspring has confirmed on Wednesday that they are the latest victims of a colossal password leak that includes more than 420,000 passwords from their member’s accounts.

With just weeks after the much talked security breach in LinkedIn, eHarmony and Last.fm, Formspring confirmed reports on a probable violation via their site that a cyber criminal has posted over 420,000 password hashes from its San-Francisco based servers along with the log-in information in a security forum.

Formspring exclaimed on its site “We learned this morning that we had a security breach where some user passwords may have been accessed. In response to this, we have disabled all users passwords. We apologize for the inconvenience but prefer to play it safe and have asked all members to reset their passwords.”

On Wednesday, Spokeswoman Dorothee Fisher confirmed reports about the security hack as the company was already attentive about a post in a security forum that includes around 420,000 encrypted passwords. But Fisher assured that even though a confident pro hacker can tamper the password, but till now these passwords aren’t immediately useable.

“Once we were able to verify that the hashes were obtained from Formspring, we locked down our systems and began an investigation to determine the nature of the breach,” Formspring said. “We found that someone had broken into one of our development servers and was able to use that access to extract account information from a production database.”

This is a big blow to Formspring’s future advancement as last month saw the company assembling a groundbreaking announcement about a new major revamp, intended to shift the site's focus toward users' interests.