Re: Twitter users: password change soon-ish
Robert Freiberger <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.svlug |
|---|---|
| Message-ID | <CAK5y5r42dF8wRBMsjqtJJGoqUssUD+EytBGxtwfXgB=_HVzVSg@mail.gmail.com> |
Written to an internal log (secure behind sudo) or also indexed by ELK/Splunk for everyone to see? On Thu, May 3, 2018 at 2:38 PM Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> wrote: > https://twitter.com/TwitterSupport/status/992132808192634881 > > @TwitterSupport > > We recently found a bug that stored passwords unmasked in an internal > log. We fixed the bug and have no indication of a breach or misuse by > anyone. As a precaution, consider changing your password on all services > where you’ve used this password. > > A blog entry > ( > https://blog.twitter.com/official/en_us/topics/company/2018/keeping-your-account-secure.html > ) > gives a small amount more detail: > > We mask passwords through a process called hashing using a function > known as bcrypt [...]. Due to a bug, passwords were written to an > internal log before completing the hashing process. We found this > error ourselves, removed the passwords, and are implementing plans > to prevent this bug from happening again. > > > > _______________________________________________ > svlug mailing list > [email protected] > http://lists.svlug.org/lists/listinfo/svlug > -- Robert Freiberger 510-936-1210 _______________________________________________ svlug mailing list [email protected] http://lists.svlug.org/lists/listinfo/svlug