# Facebook Plain Text Password Storage Controversy

Facebook Plain Text Password Storage Controversy refers to the March 2019 disclosure that Facebook stored hundreds of millions of user passwords in unencrypted, readable form on internal servers, where roughly 20,000 employees could search them[1]. The story broke via KrebsOnSecurity and was confirmed the same day by Facebook, adding to a long run of privacy scandals hitting the company that year[2].

## Overview
The Facebook Plain Text Password Storage Controversy is the March 2019 security scandal in which Facebook admitted it had been keeping vast numbers of user passwords in unhashed, human readable form inside its own data storage systems[1]. Instead of being scrambled with the usual cryptographic hashing and salting, the passwords sat as plain strings that any of roughly 20,000 Facebook engineers and developers could search for through internal tools[3].

The issue spanned Facebook proper, Facebook Lite (the stripped down app aimed at users with poor connectivity), and Instagram, with archives of readable passwords dating back to 2012[1]. Estimates of who was exposed ran from 200 million to as many as 600 million accounts, making it one of the largest password handling failures ever disclosed by a major consumer platform[5]. The story fed directly into the wider narrative that 2018 and 2019 were catastrophic years for Facebook's privacy record after Cambridge Analytica and the 50 million account breach[5].

## How It Spread
Facebook confirmed the problem the same day Krebs published, in a Newsroom post signed by Pedro Canahuati, then Vice President of Engineering, Security and Privacy[2]. Canahuati wrote that the company would notify "hundreds of millions of Facebook Lite users, tens of millions of other Facebook users, and tens of thousands of Instagram users" whose passwords had been stored in a readable format inside internal systems[6]. The post insisted the passwords were never visible outside Facebook and that no evidence of internal abuse had been found[2].

Redditors immediately picked up the story. Threads went up on r/webdev, r/worldnews, r/privacy, and r/The_Donald, and a submission to r/news by user apetrik on March 21st drew more than 7,100 points at 97% upvoted along with about 460 comments[7]. Mainstream tech and general news outlets ran with it within hours: Wired framed it as another entry in Facebook's long list of "privacy, misuse, and security missteps" and told readers to change their passwords[3]. NPR emphasized that the archives went back to 2012 and slotted the disclosure into a running list of controversies alongside Cambridge Analytica[5]. Yahoo Finance noted that Facebook stock barely reacted, trading marginally higher at around $166 per share on the afternoon of the disclosure[4].

TechCrunch's Daily Crunch newsletter led with the story the next morning, highlighting that the flaw had been found in January but only disclosed after Krebs forced Facebook's hand[6]. CBS News aired a segment about the controversy the same day the story broke[7]. Coverage kept rolling for weeks as security researchers picked apart how a company of Facebook's scale could log raw passwords in the first place, and as regulators added the incident to their growing pile of Facebook complaints[3].

## How to Use
This is a news event rather than a template, so there is no image macro or catchphrase to reproduce. It is most often referenced in two ways online: as shorthand in security discussions when arguing why plaintext password storage is inexcusable at any scale, and as a punchline in Facebook privacy jokes, usually stacked with Cambridge Analytica and the 2018 access token breach to show a pattern of failures[5]. Security professionals commonly cite it as a case study in why hashing and salting are baseline requirements, and journalists still bring it up whenever Facebook or Meta announces a new privacy initiative[3].

## Frequently Asked Questions
### What is Facebook Plain Text Password Storage Controversy?
It is the March 2019 scandal in which Facebook admitted storing hundreds of millions of user passwords as unencrypted plain text on internal servers where thousands of employees could read them[1].

### Where did Facebook Plain Text Password Storage Controversy come from?
The story was broken on March 21st, 2019 by cybersecurity journalist Brian Krebs on KrebsOnSecurity, based on an anonymous senior Facebook source[1].

### What does Facebook Plain Text Password Storage Controversy mean?
It refers to Facebook's failure to hash or salt passwords for a subset of accounts, leaving them readable in internal logs going back to 2012[3].

### How do you use Facebook Plain Text Password Storage Controversy?
It is used online as shorthand in security debates and as a punchline in ongoing jokes about Facebook's privacy failures, usually grouped with Cambridge Analytica[5].

### Is Facebook Plain Text Password Storage Controversy still popular?
It is a classic reference point in privacy and infosec discussions, regularly cited whenever Meta announces new security or privacy plans[3].

### How many users were affected by the Facebook plaintext passwords issue?
Estimates ranged from 200 million to as many as 600 million accounts across Facebook, Facebook Lite, and Instagram[1].

### Who at Facebook responded to the controversy?
Pedro Canahuati, then VP of Engineering, Security and Privacy at Facebook, published the company's statement confirming the bug[2].

### How far back did the exposed passwords go?
According to KrebsOnSecurity, archives of plain text user passwords went back as far as 2012[1].

### How many Facebook employees could access the passwords?
Krebs reported that roughly 20,000 employees could search the data and that about 2,000 engineers or developers made around nine million internal queries touching plain text passwords[1].

### Did Facebook force users to reset their passwords?
No, Facebook software engineer Scott Renfro told KrebsOnSecurity that affected users would be notified but no password resets would be required[1].

### How did Facebook say it discovered the problem?
Facebook said it found the readable passwords during a routine internal security review in January 2019, months before the public disclosure[6].

### Did the story affect Facebook's stock price?
No, Yahoo Finance reported that Facebook shares were trading marginally higher at about $166 on the afternoon of March 21st, 2019[4].

## References
1. [https://krebsonsecurity.com/2019/03/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years/](<https://krebsonsecurity.com/2019/03/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years/>)
2. [https://about.fb.com/news/2019/03/keeping-passwords-secure/](<https://about.fb.com/news/2019/03/keeping-passwords-secure/>)
3. [https://www.wired.com/story/facebook-passwords-plaintext-change-yours/](<https://www.wired.com/story/facebook-passwords-plaintext-change-yours/>)
4. [https://finance.yahoo.com/news/facebook-password-security-195429527.html](<https://finance.yahoo.com/news/facebook-password-security-195429527.html>)
5. [https://www.npr.org/2019/03/21/705588364/facebook-stored-millions-of-user-passwords-in-plain-readable-text](<https://www.npr.org/2019/03/21/705588364/facebook-stored-millions-of-user-passwords-in-plain-readable-text>)
6. [https://techcrunch.com/2019/03/22/daily-crunch-facebook-passwords/](<https://techcrunch.com/2019/03/22/daily-crunch-facebook-passwords/>)
7. [https://knowyourmeme.com/memes/events/facebook-plain-text-password-storage-controversy](<https://knowyourmeme.com/memes/events/facebook-plain-text-password-storage-controversy>)
8. [https://www.reddit.com/r/news/comments/b3nqoi/facebook_stored_hundreds_of_millions_of_user/](<https://www.reddit.com/r/news/comments/b3nqoi/facebook_stored_hundreds_of_millions_of_user/>)

---
Source: https://meme.com/memes/facebook-plain-text-password-storage-controversy
Published by meme.com — The Internet Meme Library