Skip to main content
  1. Home
  2. Computing
  3. Business
  4. Web
  5. News

Political site Infowars was hacked 2 years ago, and we just found out about it

Add as a preferred source on Google

A recent report reveals that political news outlet Infowars was breached, spilling the details of thousands of users that’s now in circulation in the digital underground. The breach stems from the site’s Prison Planet TV portion that provides videos like founder Alex Jones’ latest broadcast, the Infowars Nightly News, and more. The leaked database seems to have been around since 2014.

The report derives from Motherboard, which recently received a copy of the Infowars database from Databases.Land. In a report provided on Monday, the site states that this database contains the email addresses, usernames, and “poorly hashed” passwords of 100,223 registered Infowars users. However, Vigilante.PW has the database stored as well, and only lists 49,933 records, indicating that the former copy is full of duplicates. Yet despite the 2014 dump date, the listing was last updated on Monday.

Recommended Videos

To validate the database dump, Motherboard went to the sign-up page on Prison Planet TV and tested 20 random email addresses and their linked usernames. Motherboard discovered that 19 of those records were already linked to Prison Planet TV accounts, and the last remaining record showed that the username was registered, but not the email address. Motherboard then contacted the owners of two verified accounts to confirm that they were indeed signed up for Prison Planet TV on the Infowars site.

What’s alarming about this report, other than the fact that the database was leaked two years ago, is that the passwords were secured with the MD5 algorithm. This isn’t the ideal method for scrambling a password, as it’s been around since 1991 and is known to have a tremendous amount of vulnerabilities. The United States government won’t it, and even the CMU Software Engineering Institute said back in 2010 that MD5 was “cryptographically broken.”

That said, Motherboard says that it was able to utilize a free online tool to successfully obtain the passwords for a number of the Prison Planet TV accounts. As for the entire database, the site believes that an SQL-injection web attack was used to grab the data given that it’s all stored in a SQL format file. An SQL-injection attack means that the hacker can insert an SQL-based command in an entry filed to tell the SQL database to cough up all of its contents into a downloadable file.

If you’re not familiar with Infowars or Prison Planet TV, they focus on current political topics, global government issues, and so on. Topics of today include Trump recruiting an army of “observers” to prevent a “rigged” election, and the Huffington Post banning a journalist for writing about Hillary Clinton’s health. Infowars founder Alex Jones is also known for his controversial viewpoints about the 9/11 attacks, the Oklahoma City bombing, and the U.S.-based landings on the Moon (or rather a lack thereof).

What’s ultimately surprising is that a website focused on reporting the “truth” to the American people is securing user passwords with a very old and buggy algorithm. As always, web surfers should use a unique password for every service they use online, as you never know what site still relies on ineffective security technologies. It’s good practice anyway, and there are plenty of free tools web surfers can use to keep track of them all.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Apple will finally stop making iPhone-to-Windows copy-paste such a chore
Your iPhone may finally copy and paste with a Windows PC like it should
Apple Universal Clipboard feature

Copying something on an iPhone and pasting it onto a Windows PC should be one of the least remarkable features imaginable. While this simple process seems effortless between an iPhone and Mac, Windows users are still left waiting.

Now, Microsoft is formally asking Apple to provide interoperable clipboard access through the company’s European Union interoperability process. The request, submitted on March 25, argues that iOS restrictions prevent third-party platforms from creating an experience comparable to Apple’s Universal Clipboard. Apple has now reached Phase III and committed to developing a solution.

Read more
Chrome wants more extension reviews, but good ratings won’t keep malware out
Google is testing built-in extension review prompts, but good ratings can still hide malware
malicious-google-chrome-extensions-on-web-store

Google is preparing to add extension review links directly inside Chrome, putting feedback closer to the menus people already use to manage their add-ons.

A Chromium change, first spotted by Windows Report, points to review options in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would qualify, and the feature is still under development.

Read more
Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Google’s “uncopyable” passkeys may be easier to steal than promised
google-lawsuite-AI-Scams

Passkeys have been pushed as the safer successor to passwords. It promised protection from phishing, credential reuse, and password leaks. Google even claims that it cannot be copied or accidentally handed to someone else. But it might not be as secure as the company wants it to be.

Security researchers (Via BleepingComputer) have now found three ways malware can undermine those promises for passkeys synced through Google Password Manager. The techniques, collectively named Pass-ta-key, target Google Password Manager inside Chrome on Windows computers equipped with a Trusted Platform Module. Every attack requires malware to already be running on the victim’s computer.

Read more