- How to live stream Guadalajara vs. Atletico Madrid 3 Years Ago
- Forget Area 51—People are planning to storm the Bermuda Triangle 3 Years Ago
- It’s too late to book a room for the Area 51 raid 3 Years Ago
- Adam Sandler’s next Netflix film is a star-studded Halloween comedy 3 Years Ago
- How to live stream Arsenal vs. Real Madrid 3 Years Ago
- Netflix’s ‘7SEEDS’ is an abominable adaptation of the original manga 3 Years Ago
- Alinity Divine hasn’t been punished for throwing her cat—and people are livid Today 10:16 AM
- Gamer Krucial B passes away during Defend the North tournament Today 9:25 AM
- Brexit supporter Boris Johnson becomes prime minister—spawning lots of memes Today 9:16 AM
- Democrats want to ban use of facial recognition in public housing Today 8:29 AM
- In America’s meme war, the left and right are fighting different battles Today 8:10 AM
- Mahershala Ali’s ‘Blade’ movie won’t arrive until Phase 5 of the MCU Today 7:18 AM
- Natalie Portman isn’t playing ‘female Thor’—she’s ‘Mighty Thor’ Today 7:08 AM
- How to watch ‘Breaking Bad’ online Today 7:00 AM
- Controversial Instagram influencer plans event called ‘The Scam’ Today 7:00 AM
Years-old security flaw leads to Dota 2 forum hack that exposed 1.5M passwords
Valve’s Dota2.com used a security feature that has been broken for more than a decade.
The stolen data includes email addresses, IP addresses, usernames, and passwords. The passwords are hashed—effectively a password scrambler meant to keep the data safe—using the MD5 algorithm, a long-antiquated and weak function that reportedly allowed LeakedSource “to convert over 80 percent” of the passwords to their true plain text values, a format anyone can read.
That amounts to over 1.5 million passwords stolen outright.
The weakness of MD5 isn’t new. In 2012, LinkedIn was hacked and 6.46 million passwords were exposed due to the weak MD5 algorithm. The software’s author said then—over four years ago—that the scrambler is “no longer considered safe.“
Worse yet, security expert Bruce Schneir said in 2005 and 2004 that “MD5 is broken” because a large number of passwords can be computed and decrypted by an attacker at rapid speed. That’s over a decade go.
Why was Valve, the publisher of Dota 2 and the company behind the breached forum, relying on it for security in 2016?
The company has yet to respond to questions about its security.
The theft came in the lead up to The International 2016, the game’s global championship, which boasts over $20 million in prize money, a record-breaking amount.
Originally breached on July 10 using an SQL injection vulnerability on vBulletin forum software, ZDNet reports, the hacked database ended up on LeakedSource.com, a site meant to chronicle breaches and give easy access to users searching for their own stolen credentials.
You can search LeakedSource.com to see if your credentials have been stolen. Users should immediately change their passwords if they may be impacted, especially if they share passwords across multiple sites. If you used your Dota2.com password anywhere else, change those, too.
Patrick Howell O'Neill is a notable cybersecurity reporter whose work has focused on the dark net, national security, and law enforcement. A former senior writer at the Daily Dot, O'Neill joined CyberScoop in October 2016. I am a cybersecurity journalist at CyberScoop. I cover the security industry, national security and law enforcement.