Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Facebook says it stored millions of passwords in plain text
kvue ^ | Mar. 21, 2019 | Barbara Ortutay

Posted on 03/21/2019 12:17:25 PM PDT by bgill

Facebook said Thursday that it stored millions of its users' passwords in plain text for years. The acknowledgement from the social media giant came after a security researcher posted about the issue online. "Security rule 101 dictates that under no circumstances passwords should be stored in plain text, and at all times must be encrypted," said cybersecurity expert Andrei Barysevich of Recorded Future. "There is no valid reason why anyone in an organization, especially the size of Facebook, needs to have access to users' passwords in plain text." Facebook said there is no evidence its employees abused access to this data. But thousands of employees could have searched them. The company said the passwords were stored on internal company servers, where no outsiders could access them. But the incident reveals a huge oversight for the company amid a slew of bruises and stumbles in the last couple of years. The security blog KrebsOnSecurity said some 600 million Facebook users may have had their passwords stored in plain text.

(Excerpt) Read more at kvue.com ...


TOPICS: Business/Economy; Crime/Corruption
KEYWORDS: facebook; security
Navigation: use the links below to view more comments.
first 1-2021-28 next last
Reason #958,201 not to use FB.
1 posted on 03/21/2019 12:17:25 PM PDT by bgill
[ Post Reply | Private Reply | View Replies]

To: bgill

Dammit. Oh, wait. I don’t do that. Yawn............


2 posted on 03/21/2019 12:18:59 PM PDT by rktman ( #My2ndAmend! ----- Enlisted in the Navy in '67 to protect folks rights to strip my rights. WTH?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bgill

This is quite surprising. Nearly any commercial LDAP or other security access system stores only the hash of the password. Did Facebook use home-made security? For their size, you would certainly think they’d just buy a suitable commercial product.

When I worked, I was involved with the single sign-on system in a large bank, where we had 250,000 employees with logins. We used the Novell eDirectory LDAP to store the credentials.


3 posted on 03/21/2019 12:22:01 PM PDT by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies]

To: bgill

.....another example of Zuckerberg screwing over the American people.


4 posted on 03/21/2019 12:22:05 PM PDT by Doogle (( USAF.68-73....8th TFW Ubon Thailand....never store a threat you should have eliminated)))
[ Post Reply | Private Reply | To 1 | View Replies]

To: bgill

CEO is a lamebrain


5 posted on 03/21/2019 12:22:10 PM PDT by a fool in paradise (Denounce DUAC - The Democrats Un-American Activists Committee)
[ Post Reply | Private Reply | To 1 | View Replies]

To: a fool in paradise

CEO is a lamebrain

CEO is pawn of 3 letter fed dept


6 posted on 03/21/2019 12:28:58 PM PDT by Nailbiter
[ Post Reply | Private Reply | To 5 | View Replies]

To: bgill

I hope my fake identity hasn’t been compromised


7 posted on 03/21/2019 12:36:23 PM PDT by shelterguy
[ Post Reply | Private Reply | To 1 | View Replies]

To: shelterguy

Look out your window.


8 posted on 03/21/2019 12:38:18 PM PDT by ImJustAnotherOkie (All I know is what I read in the papers.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: bgill
So do I.

And: Bosco.

9 posted on 03/21/2019 12:40:48 PM PDT by Larry Lucido
[ Post Reply | Private Reply | To 1 | View Replies]

To: ImJustAnotherOkie

I hear the black helicopters now. I’m heading to the bunker.


10 posted on 03/21/2019 12:42:42 PM PDT by shelterguy
[ Post Reply | Private Reply | To 8 | View Replies]

To: bgill

Vicious inmates are running that assylum, waiting for a chance to screw over anyone who disagrees with their politics.


11 posted on 03/21/2019 1:23:23 PM PDT by jimmygrace
[ Post Reply | Private Reply | To 1 | View Replies]

To: proxy_user

You’re comparing apples and oranges. Yes, Facebook had/has custom in-house security, not some commercially available LDAP product. FR is the same way and so is any other website you interact with on a daily basis.


12 posted on 03/21/2019 1:23:52 PM PDT by perfect_rovian_storm
[ Post Reply | Private Reply | To 3 | View Replies]

To: bgill
"The company said the passwords were stored on internal company servers, where no outsiders could access them."

"The company" knows as well as everybody else that more info is stolen by those sitting inside the firewalls than those sitting outside.


13 posted on 03/21/2019 1:26:28 PM PDT by Garth Tater (What's mine is mine.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bgill; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
Facebook compromises 600,000,000 users' passwords ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

14 posted on 03/21/2019 1:28:23 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Nailbiter

I think you just cracked the CEO’s password—don’t tell anyone—C..I...A....or it could be N...S...A if the first one does not work. ;-)


15 posted on 03/21/2019 1:50:36 PM PDT by cgbg (Democracy dies in darkness when Bezos bans books.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Garth Tater

I was watching a CSPAN hearing while Marriott and Equifax CEO’s tap-danced around the cyber-security issue. They ignored the potential insider threat—and the Congress-critters questioning them were clueless as well.

You are correct—most data breaches are not hacks at all.

They are inside jobs.

The first suspects should always be employees with access to the hardware and software.


16 posted on 03/21/2019 1:53:28 PM PDT by cgbg (Democracy dies in darkness when Bezos bans books.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: bgill

Everybody has stored user data in plain text at some point. Encryption is a pain. Especially when the encryption level you’re using goes out of vogue, so you have to go bigger but in the case of upgrades you still have to read the old stuff and slowly replace it. Ugh. We all know it’s wrong, but it’s fast and easy.


17 posted on 03/21/2019 1:59:09 PM PDT by discostu (I know that's a bummer baby, but it's got precious little to do with me)
[ Post Reply | Private Reply | To 1 | View Replies]

To: proxy_user

They aren’t on LDAP. It’s just a SQL database.


18 posted on 03/21/2019 1:59:52 PM PDT by discostu (I know that's a bummer baby, but it's got precious little to do with me)
[ Post Reply | Private Reply | To 3 | View Replies]

To: bgill

There is no valid reason why anyone in an organization, especially the size of Facebook, needs to have access to users' passwords in plain text."

Worth repeating. This is sheer lunacy. You always store encrypted and validate against a hash.

19 posted on 03/21/2019 2:02:41 PM PDT by zeugma (Power without accountability is fertilizer for tyranny.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bgill; dayglored

20 posted on 03/21/2019 2:04:05 PM PDT by Tolerance Sucks Rocks (Modern feminism: ALL MEN BAD!!!)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-28 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson