Meta fined $102M for storing passwords in plain text
1–10 of 136 posts
Re: Meta fined $102M for storing passwords in plain text
#2I thought this was gonna be some limited faux pas... but no. That's terrible.
Re: Meta fined $102M for storing passwords in plain text
#3Re: Meta fined $102M for storing passwords in plain text
#4Re: Meta fined $102M for storing passwords in plain text
#5Re: Meta fined $102M for storing passwords in plain text
#6Context: This is for a 2019 data breach on a system that was created in 2012. The GDPR was instated in 2018 (has it really been that long? Wow feels like yesterday) and Meta failed to disclose the 2019 data breach properly under GDPR, hence the fine.
Re: Meta fined $102M for storing passwords in plain text
#7Re: Meta fined $102M for storing passwords in plain text
#8Hashing and salting passwords isn't some newly introduced advanced rocket science, it's literally a 101-level "obvious" thing. How can a huge corporation like Meta/Facebook can do this is beyond my imagination.
Re: Meta fined $102M for storing passwords in plain text
#9Context: This is for a 2019 data breach on a system that was created in 2012. The GDPR was instated in 2018 (has it really been that long? Wow feels like yesterday) and Meta failed to disclose the 2019 data breach properly under GDPR, hence the fine.
GDPR fine is 4% of global turnover from previous fiscal year. 102m seems low to me.
Re: Meta fined $102M for storing passwords in plain text
#10Context: This is for a 2019 data breach on a system that was created in 2012. The GDPR was instated in 2018 (has it really been that long? Wow feels like yesterday) and Meta failed to disclose the 2019 data breach properly under GDPR, hence the fine.
Was it reported by a pentester? (ex-)employee? Facebook itself? How do we know that it goes back to 2012?
I know in the public sector you have to disclose such things to ICO, but does that also apply to private companies? Who is going to hold them accountable?