This comes after Twitter and Github made similar mistakes, leaving passwords that were supposed to be hashed elsewhere in plain text. Now Facebook confirms it did much the samehttps://motherboard.vice.com/en_us/article/qvy9k7/facebook-hundreds-of-millions-user-passwords-plaintext-data-leak …
-
- Show this thread
-
Updated with comment from a former technical Facebook employee https://motherboard.vice.com/en_us/article/qvy9k7/facebook-hundreds-of-millions-user-passwords-plaintext-data-leak …pic.twitter.com/WAOxuTY5fH
Show this thread -
Updated with comment from a current technical Facebook employeehttps://twitter.com/josephfcox/status/1108791817359818755 …
Show this thread -
Updated with comment from another former Facebook employee "Would have been scandalous even internally"https://motherboard.vice.com/en_us/article/qvy9k7/facebook-hundreds-of-millions-user-passwords-plaintext-data-leak …
Show this thread End of conversation
New conversation -
-
-
"Breaking"? Where people thinking that Mark Zuckerberg knew how to properly salt and hash passwords back when he was not going to class at Harvard?
-
They were stored fine with salted scrypt hashes Unfortunately they were logged in plain text too
- 1 more reply
New conversation -
-
-
This is why you don't drop out of Harvard
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
@iamdevloper@nixcraft this looks pretty much fucked up to me - End of conversation
New conversation -
-
-
i’d say “fucking unbelievable” but nah, i totally believe them to be this cavalier and inept at the absolute basic, 101 rules of how to store passwords that any 14 year old with a passing interest in dev could tell you
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
If you still use Facebook you deserve all of it.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
This is why we use this DB to check user's password changes: https://haveibeenpwned.com/
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Surely this Cannot be an issue if the primary key is encrypted for the passwords. Correct me if im wrong but the volume of passwords would eliminate any risk of brute force?
-
They are talking about the password getting put into a log file as plaintext and that file is not encrypted. Why they were logging passwords is beyond me though.. the password should have been hashed then discarded before any DB tried to log it
End of conversation
New conversation -
-
- Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
- Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Big oopsie
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
By coincidence they were only the passwords of conservative users
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Complete amateurs at FB
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.