Skip to main content

Database of 13 million MacKeeper users easily accessed online

firmware update for apple multiport adaptor macbook gold 2015 hero
Image used with permission by copyright holder
Mac anti-virus software firm MacKeeper may not be so secure itself. Data on 13 million of its users, including email addresses, phone numbers, and hashed passwords, was found to be easily accessible online, according to one security researcher.

Chris Vickery discovered the database online by searching for open databases on the computer search engine Shodan. First, he discovered four IP addresses that led him to a MongoDB database, and he ultimately found the MacKeeper data featuring users’ IP addresses, software licenses, and activation codes along with the hashed passwords, names, numbers, and email addresses.

It is actually quite common to find open MongoDB databases online. However it remains unclear how long the MacKeeper database was left open. According to Brian Krebs, MacKeeper said its database was left open for about a week due to a server misconfiguration, but Vickery points out that the database he found was last dated around the middle of November.

Most strikingly, the passwords in the database were protected only with the hashing algorithm MD5, which has been decried in the past by its own creator as subpar and no longer secure. There are even MD5 cracking tools available online, which are not hard to find. MacKeeper told Forbes that it is currently updating to the SHA512 hashing algorithm.

Vickery claims that he was unable to reach Kromtech, the company behind MacKeeper, to alert it of the flaws, so he took to Reddit to make his discovery public in the hope of catching the company’s attention.

Kromtech has since responded to Vickery and thanked him for his disclosure. The firm said the vulnerability has now been patched and it will be carrying out an internal review.

“We fixed this error within hours of the discovery. Analysis of our data storage system shows only one individual gained access … the security researcher himself,” said Kromtech. “We have been in communication with Chris and he has not shared or used the data inappropriately.”

So it appears that Vickery is the only person that was aware of this potential leak of customer data, and no malicious actor gained access to the database.

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
I finally found a gaming laptop utility that’s actually worth using
The Asus ROG Zephyrus G16 sitting on a coffee table.

Nearly all gaming laptops come with bundled first-party software, and most of it isn't all that good. They tend to be poorly designed and riddled with bloatware and features that you'll never need. Armoury Crate is Asus' version of that, and while it isn't terrible, it suffers from many of those same problems.

A large number of users on Reddit have voiced their criticism of Armoury Crate, accusing it of being buggy, broken, and overly complex. Some of the most common issues include the software's cluttered user interface, promotional pop-ups, unnecessary bloatware, and the high usage of system resources. In my experience, I do find Armoury Crate's UI to be confusing, and I've also noticed that the software runs way too many background processes and services, some of which seem unnecessary.

Read more
How to delete Slack messages on desktop and mobile
how to delete slack messages message confirm mac desktop

If your company uses Slack as its preferred communication tool, then you'll need to know the basics of navigating it. And one action you might want to know how to take in Slack is deleting a message. You can remove a direct message or one you post in a channel using any of the Slack desktop, web, and mobile applications.

For those times when you type a message in the wrong channel or conversation or simply say something you wish you hadn’t, here’s how to delete Slack messages.

Read more
How to download a video from Facebook
An elderly person holding a phone.

Facebook is a great place for sharing photos, videos, and other media with friends and family. But what if you’d like to download a video to store offline? This means you’d be able to watch the clip on your PC or mobile device, without needing to be connected to the internet. Fortunately, there’s a way to download Facebook videos to your everyday gadgets, although it’s not as straightforward a process as it could be.

Read more