Volunteer-run pirate Manga website attacked, loses hashed passwords, has ‘nobody’ to fix the mess
- Reference: 1619404087
- News link: https://www.theregister.co.uk/2021/04/26/mangadex_data_breach/
- Source link:
MangaDex.org, rated as the world’s 1,024th-most-trafficed website in [1]March 2021 by Amazon’s web marketing outfit Alexa, has been offline since that month when the site admitted it had been compromised.
[2]
The site was already in trouble over copyright because its core service is hosting scanned Manga that volunteers translate into different languages, which rather diminished publishers’ chances of securing distribution in nations outside Japan.
ManagDex has therefore endured Pirate-Bay-style whack-a-host hijinks and copyright takedown requests.
REvil ransomware gang claims it stole top-secret tech designs – including Apple lappies – from Quanta Computer [3]READ MORE
Then on March 21, the site went offline, save for a single [4]index.html page offering occasional updates on the security incident.
An email to members seen by The Register says that as of April 22, the dot-org's operators “have identified that a partial database leak” of members' information has been detected.
[5]
“Investigation on the database has pinned the time of the breach to be around December 2020," we're told, "though given the nature of the leaked database, we are unable to confirm if anything else more recent has been leaked.”
The database reportedly contains “your MangaDex username, email, bcrypt-hashed password and first & last accessed IP addresses.” Members have also been offered the following less-than-reassuring news:
As of now, the leak is not public and is instead being shared privately among certain groups of people who have ill intentions against MangaDex and have chosen to be complicit in the breach by keeping quiet about it, likely for unethical reasons. We do not know how many people have their hands on the data, or how long they have had it, but we expect the responsible parties to escalate the situation soon after by releasing the data publicly in some form.
The March security breach notice warned that restoring the website will be slow, because “maintaining MangaDex is nobody's actual job.” An April 6 update detailed work on a new version of the site based on a revised architecture and new code. That update admitted “did not go as smoothly as we dared to hope.”
The dot-org has worked on a new version for over a year, according to cached forum posts. The most recent update and email offer no time frame for restoration of the site.
[6]
Members have been advised that if their MangaDex password is reused anywhere else, it’s time to change that password in case the hashes are cracked. ®
Get our [7]Tech Resources
[1] https://www.alexa.com/siteinfo/mangadex.org
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YIY62KmOFaNT6drHtTwYPQAAABQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/04/21/ransomware_gang_extorts_apple/
[4] https://mangadex.org/index.html
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YIY62KmOFaNT6drHtTwYPQAAABQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YIY62KmOFaNT6drHtTwYPQAAABQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://whitepapers.theregister.com/