Facebook staff had access to hundreds of millions of people's passwords

CNN's Jon Sarlin explores the different ways that the social media giant has kept competitors at bay — and why that could now spell trouble.

Posted: Mar 21, 2019 3:48 PM


Facebook revealed on Thursday it didn't properly mask the passwords of hundreds of millions of its users and stored them in an internal database that could be accessed by its staff.

The company said it discovered the passwords during a security review in January and launched an investigation. Facebook did not say for how long they had been storing passwords in this way.

It will be notifying hundreds of millions of Facebook users and tens of thousands of Instagram users if their passwords were involved.

"To be clear, these passwords were never visible to anyone outside of Facebook and we have found no evidence to date that anyone internally abused or improperly accessed them," Pedro Canahuati, a Facebook vice president wrote on Thursday.

He added that Facebook typically "masks people's passwords when they create an account so that no one at the company can see them."

Keeping passwords hashed, or encrypted, is widely regarded as fundamental to cybersecurity, as passwords exist to for users to authenticate their identity without others knowing how.

"Encrypting passwords is Security 101," said Marcus Carey, the CEO Threatcare, an Austin cybersecurity company. "If they can't get the basic principles of cybersecurity right, they are surely failing on the tougher challenges."

Facebook shared information about the security incident soon after it was first reported by Krebs on Security.

Facebook said that hundreds of millions of users of Facebook Lite had been impacted, while tens of millions of regular Facebook users were impacted.

Facebook Lite is a version of Facebook popular among people in parts of the world with less connectivity. CNN Business has asked Facebook why users of Facebook Lite were so highly impacted.

In Europe, Facebook is headquartered in Ireland, where it is regulated by the Irish Data Protection Commission. A commission spokesperson told CNN Business that Facebook had informed it of the issue and that it was awaiting further information. The commission currently has several investigations into Facebook's compliance with European data laws ongoing; the company could face fines upwards of $1 billion as a result of those investigations.

Mississippi Coronavirus Cases

Data is updated nightly.

Cases: 319381

Reported Deaths: 7354
CountyCasesDeaths
DeSoto22264265
Hinds20634421
Harrison18381316
Rankin13862282
Jackson13677248
Madison10234224
Lee10050176
Jones8458167
Forrest7821153
Lauderdale7257242
Lowndes6498149
Lamar633688
Lafayette6298120
Washington5418136
Bolivar4835133
Panola4663110
Oktibbeha466098
Pearl River4597146
Marshall4572105
Warren4440121
Pontotoc424973
Monroe4155135
Union415576
Neshoba4059179
Lincoln4007111
Hancock386087
Leflore3515125
Tate342386
Sunflower339391
Pike3366110
Alcorn324172
Scott319374
Yazoo314171
Itawamba305077
Adams304885
Copiah299766
Coahoma298383
Simpson298189
Tippah291568
Prentiss283561
Leake271774
Marion271280
Covington267083
Wayne264442
Grenada264087
George251951
Newton248563
Tishomingo231267
Winston229981
Jasper222148
Attala215073
Chickasaw210459
Holmes190374
Clay187554
Stone187433
Tallahatchie180041
Clarke178980
Calhoun174032
Yalobusha167840
Smith164034
Walthall135247
Greene131833
Lawrence131024
Montgomery128643
Noxubee127934
Perry126638
Amite126142
Carroll122330
Webster115032
Tunica108027
Jefferson Davis107833
Claiborne103030
Benton102325
Humphreys97533
Kemper96628
Franklin85023
Quitman81816
Choctaw79018
Wilkinson69332
Jefferson66228
Sharkey50917
Issaquena1696
Unassigned00

Alabama Coronavirus Cases

Cases: 547873

Reported Deaths: 11274
CountyCasesDeaths
Jefferson809141565
Mobile41984826
Madison35629523
Tuscaloosa26147458
Shelby25580254
Montgomery25075611
Baldwin21805313
Lee16248175
Calhoun14710325
Morgan14618285
Etowah14160362
Marshall12446230
Houston10757288
Elmore10292212
Limestone10179157
St. Clair10155250
Cullman9928200
Lauderdale9591248
DeKalb8963189
Talladega8455184
Walker7330280
Autauga7229113
Blount6937139
Jackson6905113
Colbert6406139
Coffee5622126
Dale4929114
Russell454541
Chilton4470116
Franklin430783
Covington4267122
Tallapoosa4127154
Escambia401180
Chambers3723123
Dallas3606156
Clarke352861
Marion3237106
Pike313978
Lawrence3124100
Winston283272
Bibb267664
Geneva257081
Marengo250665
Pickens236662
Barbour234559
Hale226678
Butler223771
Fayette217762
Henry193743
Cherokee187245
Randolph186944
Monroe179141
Washington170439
Macon162951
Clay160159
Crenshaw155157
Cleburne153144
Lamar146237
Lowndes142053
Wilcox127030
Bullock124242
Conecuh113230
Coosa111429
Perry108726
Sumter105732
Greene93434
Choctaw61725
Out of AL00
Unassigned00
Tupelo
Clear
66° wxIcon
Hi: 89° Lo: 66°
Feels Like: 66°
Columbus
Partly Cloudy
64° wxIcon
Hi: 92° Lo: 65°
Feels Like: 64°
Oxford
Clear
64° wxIcon
Hi: 87° Lo: 63°
Feels Like: 64°
Starkville
Partly Cloudy
64° wxIcon
Hi: 91° Lo: 64°
Feels Like: 64°
High pressure will continue to dominate our weather forecast through most of the work week. This will mean much more in the way of dry and hot weather will be the weather rule through our Friday. However, changes may be coming to our area for this weekend.
WTVA Radar
WTVA Temperatures
WTVA Severe Weather