Facebook Exposes Hundreds of Millions of User Passwords in Plaintext
Facebook admits to storing hundreds of millions of user passwords in readable plaintext format since 2012. The company claims no internal abuse occurred, but the massive security lapse affects Facebook Lite, Facebook, and Instagram users.
Facebook resets its track record on security incidents after confirming it stores hundreds of millions of user passwords in plaintext. A routine review in January reveals this alarming oversight, which dates back to 2012 and affects Facebook Lite, regular Facebook, and Instagram users. Although the company insists the readable passwords remain invisible to outsiders, cybersecurity reporter Brian Krebs reports that up to 2,000 Facebook engineers and developers access these internal logs.
This storage method directly violates standard security practices that require companies to hash and salt passwords so they remain unreadable. Facebook's Pedro Canahuati states that the company finds no evidence of internal abuse, though the social media giant does not explain how it reaches this conclusion. The tech giant plans to notify the hundreds of millions of affected users, but it delays publicly acknowledging the incident for months after its initial discovery.
This massive lapse adds to a growing list of severe security and privacy headaches for Facebook, inviting fresh congressional inquiries and government investigations. Similar plaintext password bugs hit Twitter and GitHub last year, highlighting a concerning trend in the tech industry. It remains unclear why Facebook takes so long to disclose the issue or if the company properly notifies regulators under European and United States data protection laws.