I suspect most of 13 million users were mislead into installing the app via fake Flash updater.The part of this story that shocks is that 13 million fell for their scam.
Who could have thought of this? Me! God I really hate this product.
Wow they had 13 million suckers... I mean customers?!?!?
me2! i had no idea people actually believe its a legit thing
Well, now ya knowWhat many tech professionals don't get is that most people simply want something that works easily, and are not necessarily experts. Moreover, nor have they the time - and/or knowledge to know the difference between what is good, and what is a parasitic and horrible product.
Anyway, I was one of those who succumbed to the advertising, and found the damned thing impossible to remove - eventually, I had to get it removed professionally.
Two equally likely scenarios in my mind:The part of this story that shocks is that 13 million fell for their scam.
Not so much that as the people with accounts probably already had their credentials stolen by some other means. Anyone dumb enough to sign up for Mac Keeper is probably dumb enough to fall for any random phishing attempt.
IE, just the other day I got a random call on my phone.
"Hi, I'm from tech support. I'm calling to help with your Windows computer. Are you the admin of your Windows computer?"
I stopped them there asking for more details (which they didn't provide) such as whose tech support. I don't doubt the next thing they would have asked for would have been some combination of my username, password, and email address.
I once helped a person who called 1800 number, gave the company access to their computer, paid $400 electronically and then walked away while the company "CLEANED" their computer. Wow!
Anti-virus company MacKeeper is making headlines today for its lax security on a customer database that contained 13 million customer records complete with names, email addresses, usernames, password hashes, phone numbers, IP address, and system information.![]()
As shared in a reddit post, Chris Vickery (via Forbes) was able to download the records simply by entering an IP address, with no username or password required to access the data, a major security oversight on MacKeeper's part.
MacKeeper was also using MD5 hashes for passwords, a weak algorithm that's easily bypassed using an MD5 cracking tool. As Vickery says, MacKeeper (and parent company Kromtech) "appears to have no respect for the privacy of its users' data or the integrity of their information."
Vickery did not share details on the exploit and immediately contacted Kromtech about the oversight. Using Vickery's information, Kromtech secured the database after several hours, and nobody with malicious intent was reportedly able to get ahold of customer details. With the exploit fixed, Vickery explained how he accessed the data.For those unfamiliar with MacKeeper, it is Mac software that purports to optimize a Mac and keep it secure from viruses and malware, tricking people into a purchase with unrealistic claims. Earlier this month, a class action lawsuit led to a $2 million settlement that will see MacKeeper providing refunds to customers who purchased the software and would like their money back.
Though MacKeeper says Vickery was the only person to access the information, MacKeeper customers should still change their passwords and passwords on sites that used the same password as the MacKeeper password.
Article Link: MacKeeper Exposes Data on 13 Million Customers
The people that made accounts probably deserve their info to be hacked anyways.
Im glad, as a Service Manager for an Apple Specialist we tell people everyday not to use this. Some people fight us on this say they love it. We try to educate them that there are free alternatives like Malwarebytes Anti-Malware for Mac and Sophos Home for Mac that do not take over your Mac and are valid companies. Actually Malwarebytes (formally Adware Medic) sees MacKeeper as malware, CAUSE IT IS!
What a horrible thing to say. Many of these people were probably new converts to Apple or elderly and didn't know any better. Not everyone is technologically inclined. Get off your high horse.
The amount of people that come into my store with this issue is STAGGERING. Malwarebytes has been a blessing but it doesn't remove everything. Many times we have to go into the System Library to remove the remnants or it'll just re-appear upon restart.
It's not about being technologically savvy. It's about using common sense. If you get a popup that says you have a Microsoft error Trojan...that's a red flag, especially if you're not running any MS software. If you don't know the difference between the basic software running on your computer(you probably bought a Mac because they rarely if ever get viruses) and the error message you're getting maybe you should go back to a PC.What a horrible thing to say. Many of these people were probably new converts to Apple or elderly and didn't know any better. Not everyone is technologically inclined. Get off your high horse.
The amount of people that come into my store with this issue is STAGGERING. Malwarebytes has been a blessing but it doesn't remove everything. Many times we have to go into the System Library to remove the remnants or it'll just re-appear upon restart.
Victim-blaming is 100% ********. Don't fall into that trap.The people that made accounts probably deserve their info to be hacked anyways.
It must have been hard to say that with a straight face!Anti-virus company MacKeeper...
There are already ways for them to do that. Has Apple already revoked their developer license? If not, they should! People would try to install it and get the "unidentified developer; you should throw this in the trash" message. Apple could/should also add it to the quarantine list, preventing anyone from opening it.Can this company, software and their ads die already?
I think Apple should include a note with every Mac purchase to tell the mac newbies to avoid this crap at all cost!
The victims do deserve all of MacKeeper's funds distributed to themThe only people who deserve anything are the Mackeeper people, and we all know what they deserve.