• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechAshley Madison

Data breach aside, your Ashley Madison affair was never a secret

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
July 20, 2015, 2:51 PM ET

Worried you might be outed as a cheater in the data breach at Ashley Madison?

Turns out the extramarital affairs site, which bills itself as the “world’s leading married dating service for discreet encounters,” had leaky lips anyway. Information about who had an account wasn’t exactly hidden. Or rather, not hidden well.

Troy Hunt, a developer who specializes in security and who runs the site “Have I Been Pwned?”, revealed a flaw affecting the site in a blog post on Monday. The weakness, easily exploited, gave away whether an email address was contained in the site’s database or not; from there, one could infer who may have registered an account on the site.

The flaw affected Ashley Madison’s “password reset” form, a common Achilles heel in web security. Here’s how it worked: If you had submitted the email address of a registered account through that form, the request would trigger a certain message. Submit an email address not associated with an account, and that message would change.

So, invalid email address returned a certain screen. Valid email addresses returned a different screen. The difference? The invalid email address message contains a text box and a “send” button:

Ashley Madison - invalid password reset

 

The valid email address message excludes those details:

Ashley Madison - valid password reset

 

What this means is that anyone who knows your email address could easily check whether you had registered an account on the site.

There is, of course, an easy way to avoid detection: Create a bogus email address and use that to register an account on the site.

“[H]ere’s the the lesson for anyone creating accounts on websites: always assume the presence of your account is discoverable,” said Hunt. Putting aside the morality of the site in question for a moment, Hunt writes: “If you want a presence on sites that you don’t want anyone else knowing about, use an email alias not traceable back to yourself or an entirely different account altogether.”

I would take that truism one step further: always assume anything you do on the Web is discoverable—unless you’re taking some serious operational security measures to remain hidden, such as anonymizing Internet routing services, encryption, aliases, etc.

By the time Fortune tested out the flaw to verify its authenticity, the issue appeared to have been resolved.

A spokesperson for Avid Life Media, the company that owns Ashley Madison, declined to comment.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Most Popular

placeholder alt text
Economy
Elon Musk warns the U.S. is '1,000% going to go bankrupt' unless AI and robotics save the economy from crushing debt
By Jason MaFebruary 7, 2026
1 day ago
placeholder alt text
Success
Even with $850 billion to his name, Elon Musk admits ‘money can’t buy happiness.’ But billionaire Mark Cuban says it’s not so simple
By Preston ForeFebruary 6, 2026
2 days ago
placeholder alt text
Success
Gen Z Patriots quarterback Drake Maye still drives a 2015 pickup truck even after it broke down on the highway—despite his $37 million contract
By Sasha RogelbergFebruary 7, 2026
1 day ago
placeholder alt text
Future of Work
Anthropic cofounder says studying the humanities will be 'more important than ever' and reveals what the AI company looks for when hiring
By Jason MaFebruary 7, 2026
1 day ago
placeholder alt text
AI
AI can make anyone rich: Mark Cuban says it could turn 'just one dude in a basement' into a trillionaire
By Sydney LakeFebruary 7, 2026
1 day ago
placeholder alt text
Energy
Next-gen nuclear's tipping point: Meta and hyperscalers start deals with Bill Gates’ TerraPower, Sam Altman-backed Oklo, and more
By Jordan BlumFebruary 7, 2026
23 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Latest in Tech

InvestingVenture Capital
NFL legend Joe Montana lived around top VC execs as a 49er, then leveraged those ties to launch his second career as an investor
By Jason MaFebruary 8, 2026
2 hours ago
CybersecurityJeffrey Epstein
FBI found little evidence Epstein ran a sex trafficking ring for powerful men and concluded a ‘client list’ doesn’t exist
By Michael R. Sisak, David B. Caruso, Larry Neumeister and The Associated PressFebruary 8, 2026
4 hours ago
RetailEurope
Trump’s Greenland crisis triggered a surge in apps designed to help shoppers boycott U.S. goods, though few American imports are on store shelves
By James Brooks and The Associated PressFebruary 8, 2026
4 hours ago
nfl
CommentaryTV
The Super Bowl was made for TV and instant replay was made for visual AI. Here’s how it could be better and what it would look like
By Jason CorsoFebruary 8, 2026
6 hours ago
monkey
CybersecurityAnimals
One way AI won’t ruin the world: tools to crack down on the $23 billion animal trafficking trade
By Eve Bohnett and The ConversationFebruary 8, 2026
6 hours ago
heacock
CommentaryLeadership
I’m a CEO who grew a ‘boring’ air filter business into a $260 million company, and AI is going to help blue-collar, everyday people just like me
By David HeacockFebruary 8, 2026
7 hours ago