In another privacy bomb, Facebook admits storing millions of Instagram passwords in plain text
Last month Facebook Inc. admitted that it had stored thousands of Instagram users’ passwords in plain text, open for viewing by people at certain levels in the company. Today the company said that number is actually in the millions.
“Since this post was published, we discovered additional logs of Instagram passwords being stored in a readable format,” Facebook said in an update Thursday on the original admission. “We now estimate that this issue impacted millions of Instagram users.”
Facebook said in the original post that the issue affected “tens of thousands of Instagram users,” adding that “hundreds of millions of Facebook Lite users” had also had their passwords exposed. The company has stated that there is currently no evidence of abuse of this mistake, but reports suggested about 20,000 people may have had access to the passwords.
“This is an issue that has already been widely reported, but we want to be clear that we simply learned there were more passwords stored in this way,” a company spokesperson said in a statement.
You could say it’s been a bad year or so for Facebook, perhaps the nadir being the Cambridge Analytica scandal, but issues and subsequent apologies have been pretty much constant for a while now. Today the bad news virtually came back-to-back with more bad news.
Just hours before the Instagram revelation, Facebook revealed that it had unintentionally uploaded the email contacts of 1.5 million users to its systems. If you joined Facebook anytime between May 2016 and March 2019, you could be a victim.
During the sign-up process, users were asked to provide email and password, after which Facebook then imported contacts without notifying the user. There was no way to opt out. Users were notified with an “importing contacts” message, but there was nothing the user could do to stop it.
The company has since said it’s in the process of deleting this data and will let its customers know when the process is complete, but this latest mistake isn’t exactly a good look for a company whose standards seem so full of holes.
Image: Shopcatalog/Flickr
Since you’re here …
… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.
If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.