Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Facebook says it stored millions of passwords in plain text
kvue ^ | Mar. 21, 2019 | Barbara Ortutay

Posted on 03/21/2019 12:17:25 PM PDT by bgill

Facebook said Thursday that it stored millions of its users' passwords in plain text for years. The acknowledgement from the social media giant came after a security researcher posted about the issue online. "Security rule 101 dictates that under no circumstances passwords should be stored in plain text, and at all times must be encrypted," said cybersecurity expert Andrei Barysevich of Recorded Future. "There is no valid reason why anyone in an organization, especially the size of Facebook, needs to have access to users' passwords in plain text." Facebook said there is no evidence its employees abused access to this data. But thousands of employees could have searched them. The company said the passwords were stored on internal company servers, where no outsiders could access them. But the incident reveals a huge oversight for the company amid a slew of bruises and stumbles in the last couple of years. The security blog KrebsOnSecurity said some 600 million Facebook users may have had their passwords stored in plain text.

(Excerpt) Read more at kvue.com ...


TOPICS: Business/Economy; Crime/Corruption
KEYWORDS: facebook; security
Navigation: use the links below to view more comments.
first previous 1-2021-28 last
To: bgill

Facebook is run by liberals - they don’t give a damn about anyone’s security... Not ours - not even fellow liberals.


21 posted on 03/21/2019 2:14:14 PM PDT by GOPJ
[ Post Reply | Private Reply | To 1 | View Replies]

To: bgill

Wow, Facebook appears to have the award for sleazy untrustworthy employees.

Get to it, Google. You know you’re number 1.


22 posted on 03/21/2019 2:18:59 PM PDT by Da Coyote
[ Post Reply | Private Reply | To 1 | View Replies]

To: bgill

But only conservatives!


23 posted on 03/21/2019 2:50:19 PM PDT by SgtHooper (If you remember the 60's, YOU WEREN'T THERE!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: discostu

In UNIX, /etc/passwd, was it? Maybe /etc/pwd? encrypts automatically.

(Sorry, I haven’t used UNIX in over 10 years...but I did use it quite a bit during the 1990’s and into the 2000’s).


24 posted on 03/21/2019 4:00:43 PM PDT by scrabblehack
[ Post Reply | Private Reply | To 17 | View Replies]

To: discostu

My project is being delayed in order to absolutely encrypt and un-encrypt one field. Nothing moves forward til we get resources to assist us. That is insane to store it in simple text.


25 posted on 03/21/2019 4:14:09 PM PDT by Donnafrflorida (Thru Him all things are possible.)
[ Post Reply | Private Reply | To 17 | View Replies]

To: bgill

Bump and Amen!


26 posted on 03/21/2019 4:22:10 PM PDT by upchuck (Home schooled kids are educated, not indoctrinated.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: discostu
Everybody has stored user data in plain text at some point. Encryption is a pain.

Especially when you mistype a password when encrypting something. Been there, done that. Lost access, arghh!

27 posted on 03/21/2019 4:23:15 PM PDT by roadcat
[ Post Reply | Private Reply | To 17 | View Replies]

To: scrabblehack
> In UNIX, /etc/passwd, was it? Maybe /etc/pwd? encrypts automatically.

It was /etc/passwd, and still is. And yes, the password has always been stored in a "hashed" format, with the old-style hash using a 56-bit DES encryption algorithm. But that was judged too easy to crack with modern techniques, and was replaced years ago by a variety of other more robust algorithms. Unix and Linux now store even the hashes in files that are unreadable by regular users (/etc/master.passwd, /etc/shadow).

I am unaware of any Unix (or Linux) system that stores passwords in plaintext, unless you go out of your way to specify that (I think openLDAP permits it but discourages it).

The jokers at Fakebook were either being monumentally stupid, or outright malicious. Your choice.

28 posted on 03/21/2019 7:05:18 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 24 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-28 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson