Facebook stored passwords in plain text for hundreds of millions of users

Some users had their passwords stored in plain text as early as 2012, according to a senior Facebook source who spoke to KrebsOnSecurity. The source, speaking on condition of anonymity, says that somewhere between 200 million and 600 million Facebook users were affected. More than 20,000 Facebook employees would have had access to these plain text passwords.
Shortly after KrebsOnSecurity published its story, Facebook posted its own statement by its vice president of engineering, security and privacy, Pedro Canahuati. He states that the company first discovered the issue during “a routine security review in January.”
The users most affected by the security lapse are those who use the social network’s “lower connectivity” client, Facebook Lite. The company estimates that hundreds of millions of Facebook Lite users and tens of millions of “other” Facebook users had their passwords stored in plain text. Tens of thousands of Instagram users also were also affected.
Facebook claims that no one outside of the company was able to view the passwords and that it has found no evidence that anyone working at the social network “abused or improperly accessed them.” According to KrebsOnSecurity’s source, around 2,000 engineers or developers queried data that contained plain text passwords approximately 9 million times.
“We have fixed these issues and as a precaution we will be notifying everyone whose passwords we have found were stored in this way,” stated Canahuati.
At this point, Facebook is no stranger to security failures. In one recent breach reported in October 2018, personal information of tens of millions of Facebook users were accessed by hackers. Just two months later, the company shared that millions of its users’ photos leaked to third-party developers who never had permission to view them in a completely separate breach.
Facebook is not forcing affected users to change their passwords at this time.
Source: Mashable
Source: David Apinga
Trending News
Mahama to launch ‘Big Push’ infrastructure programme in Ho on Tuesday
02:35Tema Police arraigned four over 315 parcels of suspected Indian Hemp
14:23Three Nigerian nationals jailed for vehicle theft in Kumasi
16:17Minority labels Abronye's arrest, arraignment as political persecution
12:01Ghana’s Justice Alor and Princess Acolatse elected to Commonwealth Students’ Association executive
22:06TDC Managing Director sues Kweku Baako Media over alleged defamation
12:05Businessman donates computer to NADMO office in Suhum
08:44Vice President Opoku-Agyemang meets UN Climate Advisor, calls for fair and just global climate action
09:34Businesswoman Niharika Handa Sues 4 media outlets over defamation
21:46O/R: Jasikan MCE commends progress on university project, calls for unified support
16:13