Another day, another massive privacy scandal at Facebook — this time, around unencrypted passwords.
Digital security best practices call for passwords to be stored in an encrypted format — making them unreadable even by the companies that hold them. But in Facebook's case, they were stored in plain text, meaning that anyone with access to the file could read users' passwords with no additional steps required. According to Krebs, more than 20,000 employees had access to those passwords.
It's not clear exactly how many people were affected, but Facebook says it plans to notify"hundreds of millions" of affected users of Facebook Lite ,"tens of millions" of regular Facebook users, and"tens of thousands" of Instagram users. Krebs, meanwhile, reports that the total number is between 200 and 600 million.
Facebook says it has"found no evidence anyone internally abused or improperly accessed" the password data, and that the issue was discovered during a"routine security review" in January 2019. The incident is the newest in a long line of serious scandals and crises to wrack Facebook over the last two years — many of which have been security- or privacy-related. That includes the Cambridge Analytica scandal, as well as a hack of tens of millions of users' personal data.Contact this reporter via Signal at +1 636-6268 using a non-work phone, email at rprice@businessinsider.
United States Latest News, United States Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
Facebook says left 'hundreds of millions' of user passwords unencryptedNEW: Facebook says that an internal security found the passwords of hundreds of millions of users had been stored on company servers without encryption, but that no passwords leaked and the company has found no indication the data was improperly accessed.
Read more »
Facebook employees had access to millions of user passwordsThe passwords of up to 600 million users dating back to 2012 were stored as plain text on Facebook servers.
Read more »
Facebook says it left ‘hundreds of millions’ of users’ passwords stored in plain textFacebook on Thursday said that it had left 'hundreds of millions' of its users' passwords exposed in plain text, potentially visible to the company employees, marking another major privacy and security headache for a tech giant already under fire for mishandling people's personal information.
Read more »
Facebook staff had access to millions of people's passwordsFacebook revealed on Thursday it didn't properly mask the passwords of hundreds of millions of it users and stored them in an internal database that could be accessed by its staff.
Read more »
Facebook says it stored millions of passwords in plain textBREAKING: Facebook stored millions of user passwords in plain text for years, the social media company confirmed, after a security researcher posted about the issue online. Facebook says there is no evidence that employees abused access to the data.
Read more »
Facebook’s Chris Cox Leaves After Privacy Pivot, He's Made Millions In Facebook StockFacebook Chief Product Officer Chris Cox, the product visionary who worked alongside company founder Mark Zuckerberg for more than a decade building some of the company's most important products, including early versions of News Feed, is leaving the company.
Read more »
At Facebook, Cox welcomed new employees weekly and advocated getting rid of fake newsIn Chris Cox's departure, Facebook is losing 'the heart and soul of the Facebook mission at the company,' a former employee said.
Read more »
Facebook Oops: A special hotline for employees to get urgent support for friends and familyFacebook has a special internal email hotline, commonly referred to as 'Oops,' where employees can get priority support.
Read more »
Facebook just lost 'the heart and soul' of the company, ex-employees sayCox's resignation from Facebook, which the company announced on Thursday, marks the departure of not just its chief product officer but also one of its most popular executives.
Read more »