Advertisement

Facebook employees had access to 600 mn passwords stored in plain text, issue fixed

Facebook said that the issue has now been fixed but as a precaution, it will be notifying those affected.

Advertisement
Tech2 News Staff|Mar 22, 2019, 14:09:36 IST
Facebook just can't catch a break at the moment. Just as recently as yesterday the social media giant has suffered yet another setback. A glitch, or so Facebook wants us to believe, made hundreds of millions of users' password appear in plain text to Facebook employees.[caption id="attachment_5814591" align="alignnone" width="1024"]Image: Reuters

Image: Reuters[/caption]The passwords were accessible to as many as 20,000 Facebook employees and dated back as early as 2012, cybersecurity blog KrebsOnSecurity said in its report.Facebook has immediately put up a blog on its Newsroom for damage control and claimed that “these passwords were never visible to anyone outside of Facebook and we have found no evidence to date that anyone internally abused or improperly accessed them,”. It also said that the issue has now been fixed but as a precaution, the company will be notifying everyone whose passwords were exposed.The number of users whose password had been compromised range from nearly 200 million to 600 million, said the report. The breach came into light after a senior Facebook employee familiar with the matter came forward on the condition of anonymity.The cybersecurity blog states that the anonymous Facebook insider revealed that access logs of some 2,000 Facebook employees showed that nearly nine million internal queries were made for data elements that contained plain text user passwords.Facebook said that it will be notifying about hundreds of millions of Facebook Lite users, tens of millions of other Facebook users, and tens of thousands of Instagram users.Facebook Lite, which is a lighter version of the main Facebook app, is designed for areas with poor connectivity and for phones which have low-end specs. It would appear that users of Facebook Lite are the ones that have been affected the most.Facebook software engineer Scott Renfro, said in an interview with KrebsOnSecurity that Facebook first came to know about this situation back in January when security engineers reviewing some new code saw passwords being logged in as plain text.“We have a bunch of controls in place to try to mitigate these problems, and we’re in the process of investigating long-term infrastructure changes to prevent this going forward," said Renfro to KrebsOnSecurity. He has said that no Facebook passwords resets would be required.

How to change your Facebook password

On its blog, Facebook has explained in detail about what it is doing to protect your passwords which includes a variety of signals to detect suspicious activity, introducing a physical security key to your account, two-factor authentication and more. Here's a small guide on how to change your password.For desktopGo to settings -> Security and Login -> Change passwordFor iOS and AndroidSettings & Privacy -> Settings -> Security and Login -> Change PasswordFor InstagramSettings -> Privacy and Security -> PasswordThis caps off a particularly tough month for Facebook after last week federal prosecutors started an investigation into the data deals struck by the company with other tech giants around the world.

Advertisement
Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Mar 22, 2019, 08:28:20 IST
Advertisement
Advertisement
Trending Stories

China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost

Chinese artificial intelligence startup Moonshot AI has unveiled its latest open-weight AI model, Kimi K3, with early results suggesting it could compete with some of the world's most advanced AI systems developed by leading US companies
2 min read
Advertisement
Advertisement
Up Next