pwshub.com

Meta Fined $102M for Storing Facebook Passwords in Plain Text

Meta received a slap on the wrist on Friday to the tune of 91 million euros ($102 million) for breaking Europe's strict privacy rules. The company hadn't put enough protections in place to secure people's social media passwords, and realized it was accidentally storing them in plain text.

The Irish Data Protection Commissioner, which is in charge of ensuring Meta abides by Europe's General Data Protection Regulation, issued the fine following a five year investigation, stretching back to 2019. It was looking at whether Meta had failed to meet its obligations of guaranteeing users appropriate privacy and security, and reporting any problems to DPC.

"It is widely accepted that user passwords should not be stored in plaintext, considering the risks of abuse that arise from persons accessing such data," said Deputy Commissioner Graham Doyle in a statement. "It must be borne in mind, that the passwords the subject of consideration in this case, are particularly sensitive, as they would enable access to users' social media accounts."

The GDPR, which came into force in 2018, holds companies to high standards when it comes to protecting people's privacy. As part of the rules, companies must be proactive in ensuring that they're transparent about any potential privacy problems they discover. In line with these rules, Meta reported the problem when it made the discovery.

"As part of a security review in 2019, we found that a subset of FB users' passwords were temporarily logged in a readable format within our internal data systems," said a spokesperson for the company on Friday. "We took immediate action to fix this error, and there is no evidence that these passwords were abused or accessed improperly."

It's not the first and only time Meta has fallen foul of privacy rules, but the company claimed it's now taken steps to make sure something similar can't happen in the future and users' passwords are fully protected.

Source: cnet.com

Related stories
2 weeks ago - Following a lengthy investigation, Meta has been fined €91 million (nearly $106 million) by the Irish Data Protection Commissioner (DPC) for storing certain Facebook user passwords in plaintext on its internal systems – that is, without...
2 weeks ago - GOT HASHES? — Company failed to follow one of the most sacrosanct rules for password storage. Getty...
2 weeks ago - Skip to content Linking Meta smart glasses to a face search engine can ID strangers in a...
1 month ago - View Forever, more like it, as Meta's privacy feature again revealed to be futile with a little light hacking A fix deployed by Meta to stop people repeatedly viewing WhatsApp’s so-called View Once messages – photos, videos, and voice...
1 month ago - It promised vanishing messages, but now 'it's privacy theater' Video  A popular privacy feature in WhatsApp is "completely broken and can be trivially bypassed," according to developers at cryptowallet startup Zengo.…
Other stories
4 minutes ago - FBI officials arrested an Alabama man Thursday for allegedly hacking the Securities and Exchange Commission’s X account this year as part of an...
4 minutes ago - Former President and CEO of Sony Interactive Entertainment America, Shawn Layden, says the industry has stopped focusing on making fun games and instead spends all its energy on monetization. Developers, or rather the middle management...
5 minutes ago - Five months in, only 200 units reached customers, Qualy tells El Reg Qualcomm has officially pulled the plug on its Snapdragon for Windows Dev Kits less than five months after the X-Elite powered mini-PCs were announced.…
35 minutes ago - US becomes more vulnerable to outbreaks at vaccination rates fall into 92 percent range.
40 minutes ago - Meat delivery is convenient, sure, but is it a good deal? We did some math comparing ButcherBox's prices with a popular grocery chain to find out.