When the Ashley Madison website was hacked in July, exposing 37 million users to risk, not all was lost. While usernames and emails were exposed to the public, the actual user accounts are still password-protected. The password is not stored in plain text, but instead is protected by one of the strongest protection mechanisms.
Avast looked at the Ashley Madison data leak, which included passwords encrypted with bcrypt. Bcrypt is a secure hashing algorithm for good passwords, meaning those that are not trivial to guess, according to Ross Dickey, senior systems engineer at Avast.
While bcrypt provides a secure hashing algorithm that makes passwords hard to guess, Dickey notes that the problem is that there is no known way to securely store “123456” or “password.” As a result, Ashley Madison users with simple passwords are still at risk, since the passwords could be cracked even with bcrypt hashing. That said, using brcrypt adds a significant amount of complexity and time to trying to decrypt Ashley Madison passwords, he said.

Avast researchers looked at a subset of the Ashley Madison database, examining 10,000,000 encrypted passwords. Ultimately, they concluded that MD5 and SHA are alternatives, older and less secure hashing algorithms that were once in high demand. Bcrypt is considered more secure than both (MD5 and SHA) for a number of reasons, and it is based on the fact that bcrypt hashes are “salted” by default. A salt refers to a random piece of data that is included in a hash to make it more secure.
The top password found by Avast was “123456,” which was used by 6,495 Ashley Madison users. In second place was “password,” which was chosen by 3,268 people.
Despite the fact that the Ashley Madison database was leaked in a criminal attack that is under investigation by authorities in Toronto, Dickey believes there is nothing wrong with examining the password hashes.
The security research group Cynosure Prime also examined Ashley Madison passwords and claims to have found a more efficient method for decrypting the hashes.
Furthermore, it claims that this method allowed it to decrypt millions of bcrypt hashes in days, not years. Specifically, the insecure operations are not present in the entire database and allowed the researchers to take advantage of the weaker MD5 hashing algorithm to decrypt the passwords.
