Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • The Future of Branding: AI in Logo Creation
    • How a furniture retailer automated order confirmation processing
    • Lit Motors C-1 self balancing electric motorcycle production plan announced
    • Brussels-based HRTech scale-up Shyfter raises €1.5 million to “step on the accelerator” and expand into key markets
    • 5 Best Folding Phones (2025), Tested and Reviewed
    • AI use damages professional reputation, study suggests
    • Blade Runner: 18-Rotor “Volocopter” Moving from Concept to Prototype
    • Inside a council under cyber-attack
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Monday, May 19
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Meta pays the price for storing hundreds of millions of passwords in plaintext
    News

    Meta pays the price for storing hundreds of millions of passwords in plaintext

    Editor Times FeaturedBy Editor Times FeaturedSeptember 30, 2024No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link


    Getty Photos

    Officers in Eire have fined Meta $101 million for storing a whole bunch of tens of millions of person passwords in plaintext and making them broadly accessible to firm workers.

    Meta disclosed the lapse in early 2019. The corporate mentioned that apps for connecting to numerous Meta-owned social networks had logged person passwords in plaintext and saved them in a database that had been searched by roughly 2,000 firm engineers, who collectively queried the stash greater than 9 million occasions.

    Meta investigated for 5 years

    Meta officers mentioned on the time that the error was discovered throughout a routine safety overview of the corporate’s inside community information storage practices. They went on to say that they uncovered no proof that anybody internally improperly accessed the passcodes or that the passcodes had been ever accessible to folks outdoors the corporate.

    Regardless of these assurances, the disclosure uncovered a serious safety failure on the a part of Meta. For greater than three many years, greatest practices throughout nearly each trade have been to cryptographically hash passwords. Hashing is a time period that applies to the observe of passing passwords by a one-way cryptographic algorithm that assigns an extended string of characters that’s distinctive for every distinctive enter of plaintext.

    As a result of the conversion works in just one path—from plaintext to hash—there is no such thing as a cryptographic means for changing the hashes again into plaintext. Extra just lately, these greatest practices have been mandated by legal guidelines and rules in nations worldwide.

    As a result of hashing algorithms works in a single path, the one option to acquire the corresponding plaintext is to guess, a course of that may require massive quantities of time and computational sources. The concept behind hashing passwords is just like the thought of fireplace insurance coverage for a house. Within the occasion of an emergency—the hacking of a password database in a single case, or a home fireplace within the different—the safety insulates the stakeholder from hurt that in any other case would have been extra dire.

    For hashing schemes to work as meant, they have to comply with a number of necessities. One is that hashing algorithms have to be designed in a manner that they require massive quantities of computing sources. That makes algorithms comparable to SHA1 and MD5 unsuitable, as a result of they’re designed to shortly hash messages with minimal computing required. In contrast, algorithms particularly designed for hashing passwords—comparable to Bcrypt, PBKDF2, or SHA512crypt—are gradual and devour massive quantities of reminiscence and processing.

    One other requirement is that the algorithms should embrace cryptographic “salting,” by which a small quantity of additional characters are added to the plaintext password earlier than it’s hashed. Salting additional will increase the workload required to crack the hash. Cracking is the method of passing massive numbers of guesses, typically measured within the a whole bunch of tens of millions, by the algorithm and evaluating every hash in opposition to the hash discovered within the breached database.

    The final word goal of hashing is to retailer passwords solely in hashed format and by no means as plaintext. That stops hackers and malicious insiders alike from having the ability to use the info with out first having to expend massive quantities of sources.

    When Meta disclosed the lapse in 2019, it was clear the corporate had did not adequately shield a whole bunch of tens of millions of passwords.

    “It’s extensively accepted that person passwords shouldn’t be saved in plaintext, contemplating the dangers of abuse that come up from individuals accessing such information,” Graham Doyle, deputy commissioner at Eire’s Knowledge Safety Fee, said. “It have to be borne in thoughts, that the passwords, the topic of consideration on this case, are notably delicate, as they’d allow entry to customers’ social media accounts.”

    The fee has been investigating the incident since Meta disclosed it greater than 5 years in the past. The federal government physique, the lead European Union regulator for many US Web providers, imposed a nice of $101 million (91 million euros) this week. So far, the EU has fined Meta greater than $2.23 billion (2 billion euros) for violations of the Normal Knowledge Safety Regulation (GDPR), which went into impact in 2018. That quantity consists of final yr’s record $1.34 billion (1.2 billion euro) fine, which Meta is interesting.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    AI use damages professional reputation, study suggests

    May 19, 2025

    New pope chose his name based on AI’s threats to “human dignity”

    May 18, 2025

    New attack can steal cryptocurrency by planting false memories in AI chatbots

    May 18, 2025

    GOP sneaks decade-long AI regulation ban into spending bill

    May 18, 2025

    Google introduces Advanced Protection mode for its most at-risk Android users

    May 18, 2025

    OpenAI adds GPT-4.1 to ChatGPT amid complaints over confusing model lineup

    May 18, 2025

    Comments are closed.

    Editors Picks

    The Future of Branding: AI in Logo Creation

    May 19, 2025

    How a furniture retailer automated order confirmation processing

    May 19, 2025

    Lit Motors C-1 self balancing electric motorcycle production plan announced

    May 19, 2025

    Brussels-based HRTech scale-up Shyfter raises €1.5 million to “step on the accelerator” and expand into key markets

    May 19, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    auction records smashed … the first million dollar motorcycle

    February 2, 2025

    The Impact of AI on High-Frequency Trading

    April 7, 2025

    Pakistan Launches It’s First Women-Only Pink Bus Service

    August 18, 2024
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.