Oh look! Another breach on social media. No biggie.
Twitter is currently encouraging everyone to change their passwords after discovering a “bug” that “stored passwords unmasked in an internal log.”
LOVELY!
When you set a password for your Twitter account, we use technology that masks it so no one at the company can see it. We recently identified a bug that stored passwords unmasked in an internal log. We have fixed the bug, and our investigation shows no indication of breach or misuse by anyone.
Out of an abundance of caution, we ask that you consider changing your password on all services where you’ve used this password.
Twitter added:
We mask passwords through a process called hashing using a function known as bcrypt, which replaces the actual password with a random set of numbers and letters that are stored in Twitter’s system. This allows our systems to validate your account credentials without revealing your password. This is an industry standard.
Due to a bug, passwords were written to an internal log before completing the hashing process. We found this error ourselves, removed the passwords, and are implementing plans to prevent this bug from happening again.
#BREAKING: Twitter announces it accidentally stored passwords unsecured on an internal system, recommends all 330 million+ users change their passwords https://t.co/a5xHIigonh pic.twitter.com/YQ6gX69OJ3
— CBS Los Angeles (@CBSLA) May 3, 2018
We recently discovered a bug where account passwords were being written to an internal log before completing a masking/hashing process. We’ve fixed, see no indication of breach or misuse, and believe it’s important for us to be open about this internal defect. https://t.co/BJezo7Gk00
— jack (@jack) May 3, 2018
This particular remark rubbed a lot of people the wrong way:
We are sharing this information to help people make an informed decision about their account security. We didn’t have to, but believe it’s the right thing to do. https://t.co/yVKOqnlITA
— Parag Agrawal (@paraga) May 3, 2018
“We didn’t have to.” What a snide remark.
“We didn’t have to.” Such arrogance at Twitter.
— Mark Dice (@MarkDice) May 3, 2018
Srsly wtf
— Ned Pyle (@NerdPyle) May 3, 2018
Really? You don’t think that the potential to store 300 million passwords in an unmasked state shouldn’t confer SOME obligation to your users? “We didn’t have to” Just. WOW.
— Lester Lee (@lesterleesm) May 3, 2018
Probably should’ve left off that 2nd sentence, Parag.
— sicarious (@Sicarious_) May 3, 2018
You really are incredibly bad at this.
— Tremors was a documentary. (@turnageb) May 3, 2018
This tweet is corporate douchebaggery at its finest.
— Isaac (@isaac_s) May 3, 2018
“We didn’t have to”
That’s an interesting thing to include.
— michelle wolf stan account (@hannahtraining) May 3, 2018
this would’ve been a vastly better statement without the “we didn’t have to”.
— Eric Neustadter (e) (@thevowel) May 3, 2018
“We didn’t have to hide our idiocy so please give us a cookie for alerting people that we had possibly caused them harm”
— The ChiaClellan Man (@mlse) May 3, 2018
Basically.
He apologized after the fact, but still.
I should not have said we didn’t have to share. I have felt strongly that we should. My mistake. https://t.co/Cqbs1KiUWd
— Parag Agrawal (@paraga) May 3, 2018
Whatever dude. We know how you guys at Twitter really feel.
Openly admitting our mistakes quickly, learning, and moving on. I love my teammates. https://t.co/pn9sgUf1Op
— jack (@jack) May 3, 2018
Stuff it, Jack.
Change your password just to be safe, peeps!