LinkedIn, eHarmony, and Last.fm all had their password databases leaked in June. Many commentators opined—some more lucidly than others—on what was wrong and right with their password-handling practices. As testers, how do we assess whether or not our software is handling passwords securely?