Facebook lay in hundreds of millions of report passwords in plaintext for years , the companyadmittedon Thursday following areportby cybersecurity newsman Brian Krebs . The parole were accessible to over 20,000 Facebook employee , according to Krebs , raise the obvious risk that they could be improperly accessed .
“ We estimate that we will notify C of millions of Facebook Lite drug user , X of millions of other Facebook users , and tens of thousand of Instagram users , ” said Facebook ’s Pedro Canahuati .
Facebook ’s “ newsroom ” , which is not a newsroom , publish a piece titled “ Keeping Passwords Secure ” about how it failed to keep passwords securehttps://t.co/0rTTCExU7X

— Jon Swaine ( @jonswaine)March 21 , 2019
The plaintext passwords see back to 2012 , according to Krebs .
“ This capture our tending because our login system are plan to mask passwords using technique that make them indecipherable , ” said Canahuati .

There ’s no account of why the fault was made . TwitterandGitHubhave made similar mistakes .
“ We ’ve not find any showcase so far in our investigation where someone was bet intentionally for passwords , nor have we find signs of abuse of this data , ” Facebook engineer Scott Renfro told Krebs . “ In this position what we ’ve found is these password were unwittingly logged but that there was no actual risk that ’s come from this . We need to make indisputable we ’re reserving those steps and only force a password change in cases where there ’s definitely been signs of abuse . ”
As far as Facebook ’s foresighted listing of scandals and incident go , include a 2o18 incidentimpacting 50 million report , the uncollectible depot of these password seems at first to be far from the worst .

There is , of course , danger to stay fresh C of millions decipherable and more pronto steal . But there are still unanswered motion as Facebook say they used industry standard encryption engineering science ( known as hashing and salting ) , but how all these watchword ended up sit around in unpatterned textbook for as tenacious as seven years stay on unnamed .
At this point in Facebook ’s investigation , no abuse seems to have materialise , but it ’s obvious that the interrogation is on-going .
The salutary thing you’re able to do to secure your Facebook account , and most of your important accounts , is to use a unique parole for every on-line account you andenable two - factor authentication . you could alsocheck your Facebook account for suspicious action .

Daily Newsletter
Get the best tech , science , and culture news in your inbox daily .
News from the future , delivered to your present .












![]()