Facebook's Password Breach Suggests The Public Sees Cybersecurity As Obsolete

Making matters worse, the company discovered the breach three months ago but was trying to keep it secret until a concerned whisleblower leaked details to KrebsOnSecurity, which forced the company to make a hasty admission on Thursday.

It is truly breathtaking that a company of Facebooks size and influence failed to notice that it was logging user passwords in cleartext for more than seven years and that those passwords had been exposed in more than 9 million searches over that time period.

It is important to recognize that Facebooks never-ending stream of security breaches have almost all involved its public interfaces, rather than remote hackers penetrating its networks and exfiltrating its databases.

It is even more important to remember that almost all of the companys breaches to date have involved the data of its users, not Facebooks own data.

In other words, Facebook is quite competent when it comes to securing data it views as valuable, such as its own records.

When it comes to its users, however, the companys willful disregard for the safety, security and privacy of its users now appears to extend to the companys handling of their passwords.

The vector through which the breach occurred, developer logging, reminds us of how easy it is for even the most sensitive information to leak across a company through improper logging practices. Gone are the days when companies didnt think twice about transferring user credentials in the clear and storing them in plaintext in wide-open internet-connected databases with default passwords .Yet, even companies that follow all standard security best practices can suffer breaches if they dont meticulously control how every piece of sensitive information flows through their entire infrastructure.

If a company can hemorrhage its most sensitive user data and even access credentials again and again and again and again without losing any of its users and in fact continue to grow rapidly during that period, perhaps there is no longer a reason to even bother trying to secure our networks, since users apparently no longer care if their data is stolen.

Original article
Author: Kalev Leetaru

Forbes is a global media company, focusing on business, investing, technology, entrepreneurship, leadership, and lifestyle.

Kalev Leetaru has recently written 1 articles on similar topics including :
  1. "Two billion users no longer care that Facebook shares their data with myriad companies all over the world to misuse or when it loses their data through breach after breach after breach after breach. It seems that like privacy, Facebook has taught the world to no longer care about cybersecurity". (March 23, 2019)
Posted on  , ,