The Star Malaysia - Star2

AdGuard resets over five million passwords after attack

- By SHARMILA NAIR bytz@thestar.com.my

ADGUARD, a popular ad blocking service, has reset the passwords of all its users which number over five million worldwide after it detected its servers being attacked.

It said it detected continuous attempts to login to AdGuard accounts from suspicious IP addresses belonging to various

computers across the globe. The ompany said the attacks were topped by a rate limiter – a ecurity measure that detects multiple login attempts using ifferent passwords. “However, rate limiting is not enough when an attacker already nows what password to use. Unfortunat­ely, this seems to be the case. The pairs of email/password sed by intruders belong to known databases of leaked accounts,” it posted on its site.

“Attackers used one of the databases of leaked accounts that is available online and checked whether the email/password data could access AdGuard accounts. We believe that attackers were able to access some of the accounts.”

It said the leaked databases could have come from numerous data breaches over the years, and it is unable to tell which accounts were accessed.

“All passwords stored in AdGuard database are encrypted so we cannot check whether any of them is present in the known leaked database. That’s why we decided to reset passwords of all users,” it posted.

AdGuard is now connected to HaveIBeenP­wned, a website which collects data of all known compromise­d online services. “If the password that you are entering is found in the database of leaked ones, you will see a warning,” it posted.

Users will now have to reset their password in order to access their accounts, and AdGuard adds that it will introduce two-factor authentica­tion for stronger protection. “We physically can’t implement it in one day, but this will be our next step and we will let you know about it as soon as it’s done,” it said.

 ?? —dpa ?? AdGuard says that attackers accessed some of its users’ accounts.
—dpa AdGuard says that attackers accessed some of its users’ accounts.

Newspapers in English

Newspapers from Malaysia