Facebook stored passwords in plain text for hundreds of millions of users
Hundreds of millions of Facebook users’ passwords were stored in plain text, completely searchable by Facebook employees for years.
Some users had their passwords stored in plain text as early as 2012, according to a senior Facebook source who spoke to KrebsOnSecurity. The source, speaking on condition of anonymity, says that somewhere between 200 million and 600 million Facebook users were affected. More than 20,000 Facebook employees would have had access to these plain text passwords.
SEE ALSO:Facebook's News Feed changes were supposed to make us feel good. It's not working.Shortly after KrebsOnSecurity published its story, Facebook posted its own statement by its vice president of engineering, security and privacy, Pedro Canahuati. He states that the company first discovered the issue during “a routine security review in January.”
The users most affected by the security lapse are those who use the social network’s “lower connectivity” client, Facebook Lite. The company estimates that hundreds of millions of Facebook Lite users and tens of millions of “other” Facebook users had their passwords stored in plain text. Tens of thousands of Instagram users also were also affected.
Tens of thousands of Instagram users also were also affected
Facebook claims that no one outside of the company was able to view the passwords and that it has found no evidence that anyone working at the social network “abused or improperly accessed them.” According to KrebsOnSecurity’s source, around 2,000 engineers or developers queried data that contained plain text passwords approximately 9 million times.
“We have fixed these issues and as a precaution we will be notifying everyone whose passwords we have found were stored in this way,” stated Canahuati.
At this point, Facebook is no stranger to security failures. In one recent breach reported in October 2018, personal information of tens of millions of Facebook users were accessedby hackers. Just two months later, the company shared that millions of its users’ photos leakedto third-party developers who never had permission to view them in a completely separate breach.
Facebook is not forcing affected users to change their passwords at this time.
Featured Video For You
Facebook lost 15 million users in the U.S. since 2017
(责任编辑:关于我们)
- Apple Watch bands: 5 favorites to consider as Apple Watch 10 looms
- N. Korea's multiple provocations seen as retaliation against int'l condemnation: experts
- N. Korea’s denial of arms transfers to Russia suggests fears of tougher sanctions: experts
- Osaka feels the 'itch' to play again
- Spaceship tech slashes energy usage of existing AC systems
- Bill Clinton understands your feelings about the debate
- Apple will soon block autoplay videos and data tracking in Safari
- 创建安全文明校园环境 不断增强师生法律意识
- 20 Places to Eat Dumplings and Noodles for Lunar New Year
- Apple will soon block autoplay videos and data tracking in Safari
- Exhibition shows Danish green tech
- Facebook researchers taught bots to negotiate (and lie) like humans
- Best Labor Day mattress deals in 2024
- 'Everything turned out badly' says Ancelotti
- The OLED Burn
- Apple is basically a parody of itself
- A 'safe' Note7 exploded and destroyed this guy's MacBook Pro with it
- S. Korea, U.S, military chiefs vow strong response to N. Korea provocation
- I used the Pixel 9 Pro XL in the shower — does the screen work when wet as claimed?
- Park visits key military base over N. Korea's threats