Page 24 - ARUBA TODAY
P. 24

A24    TECHNOLOGY
                      Friday 22 March 2019
            Facebook left millions of passwords readable by employees




            By  BARBARA  ORTUTAY  and                                                                                           passwords  exposed  inter-
            FRANK BAJAK                                                                                                         nally.  He  said  he’s  seen  a
            AP Technology Writers                                                                                               number of instances where
            SAN  FRANCISCO  (AP)  —                                                                                             much smaller organizations
            Facebook  left  millions  of                                                                                        made  such  information
            user  passwords  readable                                                                                           readily available — not just
            by its employees for years,                                                                                         to programmers but also to
            the  company  acknowl-                                                                                              customer support teams.
            edged Thursday after a se-                                                                                          Security  analyst  Troy  Hunt,
            curity  researcher  exposed                                                                                         who  runs  the  “haveibeen-
            the lapse .                                                                                                         pwned.com” data breach
            By  storing  passwords  in                                                                                          website,  said  that  the  situ-
            readable  plain  text,  Face-                                                                                       ation  is  embarrassing  for
            book violated fundamental                                                                                           Facebook, but that there’s
            computer-security  practic-                                                                                         no serious, practical impact
            es. Those call for organiza-                                                                                        unless an adversary gained
            tions and websites to save                                                                                          access  to  the  passwords.
            passwords  in  a  scrambled                                                                                         But Facebook has had ma-
            form  that  makes  it  almost                                                                                       jor breaches, most recently
            impossible  to  recover  the                                                                                        in September when attack-
            original text.                                                                                                      ers accessed some 29 mil-
            “There  is  no  valid  reason                                                                                       lion accounts .
            why  anyone  in  an  organi-                                                                                        Jake  Williams,  president
            zation, especially the size of    In this Aug. 21, 2018, file photo a Facebook start page is shown on a smartphone in Surfside, Fla.    of  Rendition  Infosec,  said
            Facebook,  needs  to  have                                                                         Associated Press   storing  passwords  in  plain
            access to users’ passwords  left the passwords of some  pany  wants  to  encourage     Facebook  bought  Insta-     text is “unfortunately more
            in plain text,” said cyberse-  600  million  Facebook  us-  small  groups  of  people  to   gram in 2012.           common than most of the
            curity expert Andrei Baryse-  ers  vulnerable.  In  a  blog  carry  on  encrypted  con-  Recorded  Future’s  Baryse-  industry  talks  about”  and
            vich of Recorded Future.     post , Facebook said it will  versations   that   neither   vich  said  he  could  not  re-  tends to happen when de-
            Facebook  said  there  is  no  likely  notify  “hundreds  of  Facebook  nor  any  other   call  any  major  company  velopers are trying to rid a
            evidence  its  employees  millions”  of  Facebook  Lite  outsider can read.            caught  leaving  so  many  system of bugs. q
            abused access to this data.  users, millions of Facebook  The  fact  that  the  com-
            But  thousands  of  employ-  users and tens of thousands  pany  couldn’t  manage
            ees  could  have  searched  of Instagram users that their  to do something as simple  First artificial intelligence
            them.  The  company  said  passwords  were  stored  in  as  encrypting  passwords,     Google Doodle features Bach
            the passwords were stored  plain  text.  Facebook  Lite  however,  raises  questions
            on  internal  company  serv-  is  a  version  designed  for  about its ability to manage
            ers,  where  no  outsiders  people  with  older  phones  more  complex  encryption
            could access them.           or low-speed internet con-   issues — such in messaging
            The  incident  reveals  yet  nections. It is used primarily  — flawlessly.
            another  huge  and  basic  in developing countries.       Facebook  said  it  discov-
            oversight  at  a  company  Last week, Facebook CEO  ered the problem in Janu-
            that insists it is a responsible  Mark  Zuckerberg  touted  a  ary. But security researcher
            guardian  for  the  personal  new  “privacy-focused  vi-  Brian  Krebs  wrote  that  in
            data  of  its  2.2  billion  us-  sion “ for the social network  some cases the passwords
            ers  worldwide.  The  secu-  that  would  emphasize  pri-  had  been  stored  in  plain
            rity  blog  KrebsOnSecurity  vate  communication  over  text  since  2012.  Facebook
            said  Facebook  may  have  public  sharing.  The  com-    Lite  launched  in  2015  and


                                                                                                   This  image  provided  by  Google  shows  the  animated  Google
                                                                                                   Doodle on Thursday, March 21, 2019.
                                                                                                                                            Associated Press
                                                                                                   MOUNTAIN VIEW, Calif. (AP)  ture  music  style.”  Bach’s
                                                                                                   —  Google  is  celebrating  chorales  were  known  for
                                                                                                   composer  Johann  Sebas-     having four voices carrying
                                                                                                   tian Bach with its first artifi-  their own melodic line.
                                                                                                   cial  intelligence-powered  To develop the AI Doodle,
                                                                                                   Doodle.                      Google  teams  created  a
                                                                                                   Thursday’s       animated  machine-learning      model
                                                                                                   Google  Doodle  shows  the  that was trained on 306 of
                                                                                                   composer  playing  an  or-   Bach’s chorale harmoniza-
                                                                                                   gan  in  celebration  of  his  tions.
                                                                                                   March  21,  1685,  birthday  Another  team  worked  to
                                                                                                   under  the  old  Julian  cal-  allow  machine  learning
                                                                                                   endar. It encourages users  to  occur  within  the  web
                                                                                                   to compose their own two-    browser  instead  of  on  its
                                                                                                   measure melody.              servers.
                                                                                                   Google  says  the  Doodle  The Doodle will prompt us-
                                                                                                   uses  machine  learning  to  ers who are unsure of how
                                                                                                   “harmonize  the  custom  to interact with the animat-
                                                                                                   melody  into  Bach’s  signa-  ed graphic.q
   19   20   21   22   23   24   25   26   27   28   29