Re: Twitter users: password change soon-ish

Robert Freiberger <[email protected]>
Newsgroups gmane.org.user-groups.linux.svlug
Message-ID <CAK5y5r42dF8wRBMsjqtJJGoqUssUD+EytBGxtwfXgB=_HVzVSg@mail.gmail.com>
Written to an internal log (secure behind sudo) or also indexed by
ELK/Splunk for everyone to see?

On Thu, May 3, 2018 at 2:38 PM Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> wrote:

> https://twitter.com/TwitterSupport/status/992132808192634881
>
>   @TwitterSupport
>
>   We recently found a bug that stored passwords unmasked in an internal
>   log.  We fixed the bug and have no indication of a breach or misuse by
>   anyone.  As a precaution, consider changing your password on all services
>   where you’ve used this password.
>
> A blog entry
> (
> https://blog.twitter.com/official/en_us/topics/company/2018/keeping-your-account-secure.html
> )
> gives a small amount more detail:
>
>   We mask passwords through a process called hashing using a function
>   known as bcrypt [...].  Due to a bug, passwords were written to an
>   internal log before completing the hashing process.  We found this
>   error ourselves, removed the passwords, and are implementing plans
>   to prevent this bug from happening again.
>
>
>
> _______________________________________________
> svlug mailing list
> [email protected]
> http://lists.svlug.org/lists/listinfo/svlug
>
-- 
Robert Freiberger
510-936-1210

_______________________________________________
svlug mailing list
[email protected]
http://lists.svlug.org/lists/listinfo/svlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.