{"id":133223,"date":"2019-03-26T16:56:20","date_gmt":"2019-03-26T16:56:20","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=133223"},"modified":"2025-07-01T22:11:20","modified_gmt":"2025-07-02T05:11:20","slug":"facebook-plain-text-passwords","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/facebook-plain-text-passwords\/","title":{"rendered":"Facebook stored hundreds of millions of user passwords insecurely"},"content":{"rendered":"<p>Facebook is becoming more famous for not being very good at looking out for its users than it is for being a social network. Although, over the last few years the scandals coming out of Facebook HQ have been much more serious and have had some pretty wide-reaching and devastating consequences, this latest blunder is <strong>the stupidest by far.<\/strong><\/p>\n<h2>Hundreds of million of Facebook and Instagram user passwords were stored unencrypted as text on internal servers<\/h2>\n<figure id=\"attachment_133226\" aria-describedby=\"caption-attachment-133226\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-133226\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/Facebook_password_insecure_list_tg0wqy.jpg\" alt=\"Facebook password header\" width=\"700\" height=\"394\" \/><figcaption id=\"caption-attachment-133226\" class=\"wp-caption-text\">Image via: <a href=\"https:\/\/newsroom.fb.com\/news\/2019\/03\/keeping-passwords-secure\/\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a><\/figcaption><\/figure>\n<p>A <a href=\"https:\/\/newsroom.fb.com\/news\/2019\/03\/keeping-passwords-secure\/\" target=\"_blank\" rel=\"noopener noreferrer\">recent Facebook blog post<\/a> described how a routine security review showed that \u201csome\u201d user passwords were being stored in a readable text format. The post goes on to say that Facebook will be notifying all affected users and it is here that the \u201csome\u201d mentioned earlier magically becomes \u201chundreds of millions\u201d<\/p>\n<p>In the blog post, Pedro Canahuati who is Facebook\u2019s VP for Engineering, Security, and Privacy writes, \u201cWe estimate that we will notify <strong>hundreds of millions of Facebook Lite users, tens of millions of other Facebook users, and tens of thousands of Instagram users.<\/strong>\u201d If you\u2019re a Facebook Lite user you are exponentially more likely to have had your password stored in this insecure manner at Facebook HQ.<\/p>\n<div class=\"sc-related-articles-white\">\r\n<p class=\"sc-related-articles-white__title\">More about Facebook's scandals<\/p>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"Facebook deliberately shared your data with 60 companies \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/facebook-shares-your-data\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/06\/revised-image.png)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Facebook deliberately shared your data with 60 companies \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"Facebook banned \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/facebook-banned-papua-new-guinea\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/05\/Facebook-banned-1024x576.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Facebook banned \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"Facebook suspends over 200 apps in the wake of the Cambridge Analytica scandal \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/facebook-app-suspensions\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/05\/facebook-spy-1024x576.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Facebook suspends over 200 apps in the wake of the Cambridge Analytica scandal \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"Facebook deletes over 200 accounts and pages linked to Russian troll farm \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/facebook-deletes-over-200-accounts-and-pages\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/04\/facebook-257829_1280.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Facebook deletes over 200 accounts and pages linked to Russian troll farm \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n<\/div>\n<p>Canahuati does go on to mention, however, that <strong>none of the passwords were visible to anybody outside of Facebook<\/strong> and that the company has found no evidence that any Facebook employee has abused or improperly accessed the insecure list of user passwords.<\/p>\n<p>Outside of Facebook, security expert <a href=\"https:\/\/krebsonsecurity.com\/2019\/03\/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years\/\" target=\"_blank\" rel=\"noopener noreferrer\">Brian Krebs has also written a blog post on the latest Facebook blunder<\/a>. According to Krebs, who cites an insider at Facebook, the internal investigation \u201cso far indicates between <strong>200 million and 600 million Facebook users<\/strong> may have had their account passwords stored in plain text and searchable by more than 20,000 Facebook employees.\u201d The insider goes on to say, \u201cAccess logs showed some 2,000 engineers or developers made approximately nine million internal queries for data elements that contained plain text user passwords.\u201d<\/p>\n<figure id=\"attachment_133229\" aria-describedby=\"caption-attachment-133229\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-133229\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/password-866979_1920_tjhe6e.jpg\" alt=\"A lot of passwords\" width=\"700\" height=\"495\" \/><figcaption id=\"caption-attachment-133229\" class=\"wp-caption-text\">Hundreds of millions is a LOT of passwords<\/figcaption><\/figure>\n<p>Krebs went on though to point out that the further the investigation progresses the easier Facebook\u2019s legal team feels about the whole situation. It looks increasingly likely that although Facebook is going to have to notify all affected users, no actual password resets will be required.<\/p>\n<p>This doesn\u2019t come close to being one of the most serious scandals to rock Facebook recently. From <a href=\"https:\/\/en.softonic.com\/articles\/two-studies-facebook-depression-loneliness-alcohol\" target=\"_blank\" rel=\"noopener noreferrer\">causing depression<\/a> to <a href=\"https:\/\/en.softonic.com\/articles\/facebook-location-tracking\" target=\"_blank\" rel=\"noopener noreferrer\">tracking location without permission<\/a> the scandals just haven\u2019t stopped coming at Facebook for a period of years now. This is symptomatic, however, of a wider malaise at Facebook. The social network just doesn\u2019t seem to care about its users. Not even enough to store their passwords, which protect some of the most intimate parts of their lives, properly and in a secure manner. The social network needs to have a look at itself and start thinking about <a href=\"https:\/\/en.softonic.com\/articles\/will-facebook-fix-itself\" target=\"_blank\" rel=\"noopener noreferrer\">how it is going to fix itself<\/a>.<\/p>\n<div class=\"sc-related-articles-white\">\r\n<p class=\"sc-related-articles-white__title\">More from Softonic<\/p>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"Facebook vs Facebook Lite: What are the differences between the apps? \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/facebook-vs-facebook-lite-what-are-the-differences-between-the-apps\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/04\/facebook-vs-lite-1024x576.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Facebook vs Facebook Lite: What are the differences between the apps? \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"How to find out what Facebook knows about you \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/how-to-find-out-what-facebook-knows-about-you\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/05\/facebook-spy-1024x576.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to find out what Facebook knows about you \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"How to bulk delete apps and website logins on Facebook \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/how-to-bulk-delete-apps-and-website-logins-on-facebook\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/04\/access-app-application-267399.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to bulk delete apps and website logins on Facebook \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"How to download all your Facebook data in just a few minutes \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/how-to-download-all-of-your-facebook-data\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2016\/05\/17.-Read-your-Wifes-Facebook-Messages-without-her-knowing1.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to download all your Facebook data in just a few minutes \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Hundreds of million of Facebook and Instagram user passwords were stored unencrypted as text on internal servers.<\/p>\n","protected":false},"author":9073,"featured_media":133227,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[2353,1059,1063,1027],"usertag":[839],"vertical":[],"content-category":[],"class_list":["post-133223","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionfacebook","tag-facebook","tag-facebook-messenger","tag-security","usertag-vpn"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/133223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=133223"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/133223\/revisions"}],"predecessor-version":[{"id":326367,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/133223\/revisions\/326367"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/133227"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=133223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=133223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=133223"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=133223"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=133223"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=133223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}