- A mysterious website is doxing Hong Kong protesters and journalists Today 1:44 PM
- The best ‘Skyrim’ followers and how to get them Today 1:26 PM
- Why Joel Osteen gets cyberbullied every time Houston floods Today 12:40 PM
- How to stream Jets vs. Patriots in Week 3 Today 12:39 PM
- 10 indie dating simulator games you should be playing Today 12:31 PM
- How to stream Packers vs. Broncos in Week 3 Today 12:14 PM
- Saudi crown prince’s former adviser suspended from Twitter Today 11:57 AM
- How to stream Cowboys vs. Dolphins in Week 3 Today 11:57 AM
- YouTuber to pay restitution after a teen fan died copying her video Today 10:36 AM
- Antonio Brown sent ‘intimidating’ texts to an accuser, including a pic of her children Today 9:38 AM
- Facebook suspended tens of thousands of apps after Cambridge Analytica scandal Today 8:24 AM
- How to stream Browns vs. Rams on Sunday Night Football Today 6:00 AM
- How to watch ‘NFL Primetime’ on ESPN+ Today 5:00 AM
- How to stream Liverpool vs. Chelsea Friday 6:45 PM
- How to stream Real Madrid vs. Sevilla Friday 6:35 PM
The stolen data includes email addresses, IP addresses, usernames, and passwords. The passwords are hashed—effectively a password scrambler meant to keep the data safe—using the MD5 algorithm, a long-antiquated and weak function that reportedly allowed LeakedSource “to convert over 80 percent” of the passwords to their true plain text values, a format anyone can read.
That amounts to over 1.5 million passwords stolen outright.
The weakness of MD5 isn’t new. In 2012, LinkedIn was hacked and 6.46 million passwords were exposed due to the weak MD5 algorithm. The software’s author said then—over four years ago—that the scrambler is “no longer considered safe.“
Worse yet, security expert Bruce Schneir said in 2005 and 2004 that “MD5 is broken” because a large number of passwords can be computed and decrypted by an attacker at rapid speed. That’s over a decade go.
Why was Valve, the publisher of Dota 2 and the company behind the breached forum, relying on it for security in 2016?
The company has yet to respond to questions about its security.
The theft came in the lead up to The International 2016, the game’s global championship, which boasts over $20 million in prize money, a record-breaking amount.
Originally breached on July 10 using an SQL injection vulnerability on vBulletin forum software, ZDNet reports, the hacked database ended up on LeakedSource.com, a site meant to chronicle breaches and give easy access to users searching for their own stolen credentials.
You can search LeakedSource.com to see if your credentials have been stolen. Users should immediately change their passwords if they may be impacted, especially if they share passwords across multiple sites. If you used your Dota2.com password anywhere else, change those, too.
Patrick Howell O'Neill is a notable cybersecurity reporter whose work has focused on the dark net, national security, and law enforcement. A former senior writer at the Daily Dot, O'Neill joined CyberScoop in October 2016. I am a cybersecurity journalist at CyberScoop. I cover the security industry, national security and law enforcement.