Facebook Stored Millions of Passwords in Plaintext—Change Yours Now

By now, its difficult to summarize all of Facebooks privacy, misuse, and security missteps in one neat description.

It just got even harder: On Thursday, following a report by Krebs on Security, Facebook acknowledged a bug in its password management systems that caused hundreds of millions of user passwords for Facebook, Facebook Lite, and Instagram to be stored as plaintext in an internal platform.

Organizations can store account passwords securely by scrambling them with a cryptographic process known as hashing before saving them to their servers. This way, even if someone compromises those passwords, they won't be able to read them, and a computer would find it difficulteven functionally impossibleto unscramble them.As a prominent company with billions of users, Facebook knows that it would be a jackpot for hackers, and invests heavily to avoid the liability and embarrassment of security mishaps.

On April 18, four weeks after the initial disclosure, the company sharply revised the number of affected Instagram accounts upward.

Facebook now estimates that the incident caused "millions" of Instagram passwords to be stored in plaintext, rather than tens of thousands.

For such a prominent target, Facebook has had relatively few technical security failures, and in this case appears not to have been compromised. But the companys track record was severely marred by a breach in September, in which attackers stole extensive data from 30 million users by compromising their account access tokensauthentication markers generated when a user logs in.

Facebook says that the plaintext password issue is now fixed, and that it doesnt think there will be long-term impacts from the incident, because the passwords were never actually stolen.

Original article
Author: Wired

Wired has recently written 11 articles on similar topics including :
  1. "For the past four years, Facebook has quietly used a homegrown tool called Zoncolan to find bugs in its massive codebase". (August 17, 2019)
  2. "Alex Stamos' Stanford-based project will try to persuade tech firms to offer academics access to massive troves of user data". (July 25, 2019)
  3. "The Central Asian country’s government has repeatedly threatened to monitor its citizens’ internet activities. Google and Mozilla aren’t having it". (August 21, 2019)
  4. "The idea that FaceApp is somehow exceptionally dangerous threatens to obscure the real point: All apps deserve this level of scrutiny". (July 17, 2019)
  5. "Tim Wu, who coined the phrase "net neutrality," spoke with WIRED Editor-in-Chief Nicholas Thompson at the Aspen Ideas Festival". (July 5, 2019)
  6. "The social network wants to enable easy, inexpensive global commerce, sure. But its ultimate goals are a little more … geopolitical". (June 26, 2019)
  7. "Computer science professor David Gelernter envisaged social networks long before Facebook. Now, he wants to reclaim the concept, using blockchain technology". (July 4, 2019)
  8. "Facebook reportedly bans Huawei from installing its apps, including Instagram and WhatsApp, on new phones". (June 7, 2019)
  9. "The executive, in announcing his departure, was the last of the Oculus founders still at the company". (August 13, 2019)
  10. "But lawmakers appear too divided still to do anything meaningful about it". (July 19, 2019)
  11. "Alex Jones, Infowars, Laura Loomer and Milo Yiannopoulos are expelled from Facebook and Instagram, but the ban's rollout went awry". (May 3, 2019)
Posted on  , ,