Facebook has revealed that up to 600M users have had their passwords compromised

Facebook has been in the news a lot lately and it has not been positive for them. Just after Mark Zuckerberg recently announced that he plans for Facebook to become focused on encryption, privacy, and security, Facebook has revealed that they might have had an internal security breach that could affect Facebook and Instagram users.

The Social Media tech titan admitted that up to 600 million passwords were stored in plain text on its internal servers after security expert Brian Krebs revealed this on his blog.  The Data Protection Commission has said they have been contacted by Facebook and that they are seeking further information as this might come under GDPR jurisdiction.

If you have a Facebook or Instagram account what should you do? According to Paul Ducklin, senior technologist, Sophos you should change your password. “It’s perfectly possible that no passwords at all fell into the hands of any crooks as a result of this. But if any passwords did get into the wrong hands (and you can bet your boots that the crooks are trawling through any old data they might have right now, to see if there is anything they missed before), then you can expect them to be abused. Hashed passwords still need to be cracked before they can be used; plaintext passwords are the real deal without any further hacking or cracking needed.”

Paul also recommends turning on two-factor authentication. ” We’ve been urging you to use two-factor authentication everywhere you can anyway – it means that a password alone isn’t enough for crooks to raid your account. If you are reluctant to give Facebook your phone number, use app-based authentication, where your mobile phone generates a one-time code each time you log in”.

John Shier, senior security advisor at Sophos comments:

“Despite the recent public struggles Facebook has had with respect to privacy and security, this incident is a little different. Authentication data is something that Facebook treats very seriously and has put in place many mechanisms, both externally and internally, to ensure that user credentials are safeguarded. While the details of the incident are still emerging, this is likely an accidental programming error that led to the logging of plain text credentials. That said, this should never have happened and Facebook needs to ensure that no user credentials or data were compromised as a result of this error. This is also another reminder for people who are still reusing passwords or using weak passwords to change their Facebook password to something strong and unique and to turn on 2-factor authentication.”

 

Ronan Leonard

Recent Posts

AI FORWARD > Supercomputing the Future: Rare Open Day at Ireland’s Most Advanced AI Infrastructure

CloudCIX, in conjunction with AlloComp, will host AI FORWARD > Supercomputing the Future, a one-day…

19 hours ago

MTU to Host National Workshop on Strengthening Rural Life and the Future of Farming

Munster Technological University (MTU) will host a major stakeholder workshop exploring the future of rural…

21 hours ago

Pendulum Summit returns Friday, January 23rd

Pendulum Summit kicks off this Friday for the 12th year, founded by Irish International rugby…

22 hours ago

Accelerating Clean Transport: Tyndall Researchers Driving New Research to Integrate Electric Buses in Ireland

Tyndall National Institute was awarded six projects from SEAI’s National Energy Research, Development & Demonstration…

23 hours ago

ServiceNow and OpenAI collaborate to deepen and accelerate enterprise AI outcomes

ServiceNow the AI control tower for business reinvention, and OpenAI has announced an enhanced strategic…

1 day ago

More about Irish Tech News


Irish Tech News are Ireland’s No. 1 Online Tech Publication and often Ireland’s No.1 Tech Podcast too.


You can find hundreds of fantastic previous episodes and subscribe using whatever platform you like via our Anchor.fm page here: https://anchor.fm/irish-tech-news


If you’d like to be featured in an upcoming Podcast email us at Simon@IrishTechNews.ie now to discuss.


Irish Tech News have a range of services available to help promote your business. Why not drop us a line at Info@IrishTechNews.ie now to find out more about how we can help you reach our audience.


You can also find and follow us on Twitter, LinkedIn, Facebook, Instagram, TikTok and Snapchat.