Facebook Exposes Hundreds of Millions of User Passwords in Plain Text

Facebook admits that internal applications inadvertently store between 200 million and 600 million user passwords in plain text on internal servers. Although thousands of employees have access to this searchable data, the company claims it finds no evidence of abuse.

Facebook investigates a major security failure where internal applications inadvertently store between 200 million and 600 million user passwords in plain text on internal company servers. These unencrypted password archives date back to 2012 and remain fully searchable by more than 20,000 Facebook employees. A senior employee reveals that engineers make approximately nine million internal queries for data elements containing these plain text user passwords.

Despite the massive scope of this exposure, Facebook states that its ongoing investigation finds no indication that employees abuse access to this sensitive data. Software engineer Scott Renfro emphasizes that the company discovers no cases of anyone intentionally looking for passwords or showing signs of misuse. Facebook plans to notify the affected users about the incident but decides against forcing mandatory password resets.

The social media giant currently attempts to narrow down the exact number of exposed users by analyzing only the data currently stored in its active data warehouse. As the legal team grows more comfortable with the lower bounds of the affected figures, the company works to reduce that estimated number even further. Facebook maintains that the passwords are logged inadvertently and that no actual risk comes from this oversight.

Read More at the original source →