Twitter Says Glitch Exposed 'Substantial' Number of Users' Passwords In Plain Text

Twitter is urging its more than 330 million users to change their passwords after a glitch exposed some in plain text on its internal computer network. Reuters is first to report the news: The social network said an internal investigation had found no indication passwords were stolen or misused by insiders, but that it urged all users to consider changing their passwords “out of an abundance of caution.” The blog did not say how many passwords were affected. Here’s what Twitter has to say about the bug: “We mask passwords through a process called hashing using a function known as bcrypt, which replaces the actual password with a random set of numbers and letters that are stored in Twitter’s system. This allows our systems to validate your account credentials without revealing your password. This is an industry standard. Due to a bug, passwords were written to an internal log before completing the hashing process. We found this error ourselves, removed the passwords, and are implementing plans to prevent this bug from happening again.” The social networking service is asking users to change their password “on all services where you’ve used this password.” You can do so via the password settings page.

Read more of this story at Slashdot.



Source: Slashdot – Twitter Says Glitch Exposed ‘Substantial’ Number of Users’ Passwords In Plain Text