Live data from Hacker News

Meta fined $102M for storing passwords in plain text

engadget.com

1–10 of 136 posts

Re: Meta fined $102M for storing passwords in plain text

#2
> a senior employee told Krebs on Security back then that the incident involved up to 600 million passwords. Some of the passwords had been stored in easily readable format in the company's servers since 2012. They were also reportedly searchable by over 20,000 Facebook employees

I thought this was gonna be some limited faux pas... but no. That's terrible.

Re: Meta fined $102M for storing passwords in plain text

#4
This is a very imaginative use of the word “breach”, according to the details reported in the article at least. Internal staff (inadvertently) had access to users plaintext passwords. The article doesn’t mention any use of these credentials in a breach though, and doesn’t make any refutation of Meta’s claim that this never occurred. Internal staff having access to my data is what I would normally expect from a service like the ones Meta operates. It’s a bad mistake to make, but contriving these circumstances into being a “breach” is a bit more mask-off than I’m used to the Data Protection agencies being. Hope Ireland makes good use of its $102M.

Re: Meta fined $102M for storing passwords in plain text

#6
post #3

Context: This is for a 2019 data breach on a system that was created in 2012. The GDPR was instated in 2018 (has it really been that long? Wow feels like yesterday) and Meta failed to disclose the 2019 data breach properly under GDPR, hence the fine.

GDPR fine is 4% of global turnover from previous fiscal year. 102m seems low to me.

Re: Meta fined $102M for storing passwords in plain text

#8
I really don't get how companies so large do stupid things like this.

Hashing and salting passwords isn't some newly introduced advanced rocket science, it's literally a 101-level "obvious" thing. How can a huge corporation like Meta/Facebook can do this is beyond my imagination.

Re: Meta fined $102M for storing passwords in plain text

#9
post #3

Context: This is for a 2019 data breach on a system that was created in 2012. The GDPR was instated in 2018 (has it really been that long? Wow feels like yesterday) and Meta failed to disclose the 2019 data breach properly under GDPR, hence the fine.

GDPR fine is 4% of global turnover from previous fiscal year. 102m seems low to me.

Thats the maximal fine I think, the judges can set the amount depending on the severity of the violation.

Re: Meta fined $102M for storing passwords in plain text

#10
post #3

Context: This is for a 2019 data breach on a system that was created in 2012. The GDPR was instated in 2018 (has it really been that long? Wow feels like yesterday) and Meta failed to disclose the 2019 data breach properly under GDPR, hence the fine.

Honest question: How was it discovered?

Was it reported by a pentester? (ex-)employee? Facebook itself? How do we know that it goes back to 2012?

I know in the public sector you have to disclose such things to ICO, but does that also apply to private companies? Who is going to hold them accountable?

Post reply on HN