Facebook Plain Text Password Storage Controversy

2019eventclassic

Facebook Plain Text Password Storage Controversy refers to the March 2019 disclosure that Facebook stored hundreds of millions of user passwords in unencrypted, readable form on internal servers, where roughly 20,000 employees could search them1. The story broke via KrebsOnSecurity and was confirmed the same day by Facebook, adding to a long run of privacy scandals hitting the company that year2.

Overview

The Facebook Plain Text Password Storage Controversy is the March 2019 security scandal in which Facebook admitted it had been keeping vast numbers of user passwords in unhashed, human readable form inside its own data storage systems1. Instead of being scrambled with the usual cryptographic hashing and salting, the passwords sat as plain strings that any of roughly 20,000 Facebook engineers and developers could search for through internal tools3.

The issue spanned Facebook proper, Facebook Lite (the stripped down app aimed at users with poor connectivity), and Instagram, with archives of readable passwords dating back to 20121. Estimates of who was exposed ran from 200 million to as many as 600 million accounts, making it one of the largest password handling failures ever disclosed by a major consumer platform5. The story fed directly into the wider narrative that 2018 and 2019 were catastrophic years for Facebook's privacy record after Cambridge Analytica and the 50 million account breach5.

How It Spread

Facebook confirmed the problem the same day Krebs published, in a Newsroom post signed by Pedro Canahuati, then Vice President of Engineering, Security and Privacy2. Canahuati wrote that the company would notify "hundreds of millions of Facebook Lite users, tens of millions of other Facebook users, and tens of thousands of Instagram users" whose passwords had been stored in a readable format inside internal systems6. The post insisted the passwords were never visible outside Facebook and that no evidence of internal abuse had been found2.

Redditors immediately picked up the story. Threads went up on r/webdev, r/worldnews, r/privacy, and r/The_Donald, and a submission to r/news by user apetrik on March 21st drew more than 7,100 points at 97% upvoted along with about 460 comments7. Mainstream tech and general news outlets ran with it within hours: Wired framed it as another entry in Facebook's long list of "privacy, misuse, and security missteps" and told readers to change their passwords3. NPR emphasized that the archives went back to 2012 and slotted the disclosure into a running list of controversies alongside Cambridge Analytica5. Yahoo Finance noted that Facebook stock barely reacted, trading marginally higher at around $166 per share on the afternoon of the disclosure4.

TechCrunch's Daily Crunch newsletter led with the story the next morning, highlighting that the flaw had been found in January but only disclosed after Krebs forced Facebook's hand6. CBS News aired a segment about the controversy the same day the story broke7. Coverage kept rolling for weeks as security researchers picked apart how a company of Facebook's scale could log raw passwords in the first place, and as regulators added the incident to their growing pile of Facebook complaints3.

How to Use This Meme

This is a news event rather than a template, so there is no image macro or catchphrase to reproduce. It is most often referenced in two ways online: as shorthand in security discussions when arguing why plaintext password storage is inexcusable at any scale, and as a punchline in Facebook privacy jokes, usually stacked with Cambridge Analytica and the 2018 access token breach to show a pattern of failures5. Security professionals commonly cite it as a case study in why hashing and salting are baseline requirements, and journalists still bring it up whenever Facebook or Meta announces a new privacy initiative3.

Frequently Asked Questions