• Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Facebook stored hundreds of millions of user passwords in plain text

PCHF IT Feeds

PCHF Tech News
PCHF Bot
Jan 10, 2015
50,226
26
pchelpforum.net
A new report from Krebs On Security has revealed that Facebook stored the account passwords of hundreds of millions of users in plain text and they were easily searchable by thousands of its own employees in some cases going back to 2012.

According to a senior employee familiar with the investigation, the social networking giant is currently probing a series of security failures in which employees wrote applications that logged unencrypted password data for Facebook users and stored this information in plain text on internal company servers.

So far, the investigation has discovered that between 200m and 600m Facebook users may have had their account passwords stored on its servers and searchable by over 20,000 employees.


The company is still trying to determine exactly how many passwords were exposed and for how long but archives with plain text user passwords have been discovered that date back to 2012.

Plain text passwords


Access logs at Facebook show that around 2,000 engineers or developers made nine million internal queries for data elements that contained plain text user passwords.

Software engineer at Facebook, Scott Renfro provided further insight into the ongoing investigation to Krebs On Security in an interview, saying:

“We’ve not found any cases so far in our investigations where someone was looking intentionally for passwords, nor have we found signs of misuse of this data. In this situation what we’ve found is these passwords were inadvertently logged but that there was no actual risk that’s come from this. We want to make sure we’re reserving those steps and only force a password change in cases where there’s definitely been signs of abuse.”

Affected users will not have to change their passwords as they were not leaked outside of the company, though Facebook is preparing to notify “hundreds of millions of Facebook Lite users, tens of millions of other Facebook users, and tens of thousands of Instagram users”.

Via Krebs On Security

13zKOqfvID4


Continue reading...