sb-eu logo
Story image

Twitter password glitch showcases 'extreme jumpiness' in digital sector

07 May 2018

More than 330 million Twitter users are being urged to change their passwords after an internal system glitch caused the passwords to be exposed in a log file.

Twitter is careful to state that there is no evidence the passwords were stolen, left the company’s systems or misused in any way, but issued the warning to change passwords as a precaution.

“When you set a password for your Twitter account, we use technology that masks it so no one at the company can see it. We recently identified a bug that stored passwords unmasked in an internal log,” an email to users states.

The bug was due to a problem with password hashing. The process wrote passwords to an internal log before they were hashed.

“We mask passwords through a process called hashing using a function known as bcrypt, which replaces the actual password with a random set of numbers and letters that are stored in Twitter's system. This allows our systems to validate your account credentials without revealing your password. This is an industry standard,” the company says.

The incident comes as World Password Day was celebrated to raise awareness about the importance of password security.

Commenting on the incident, GlobalData’s service director of Global Telecom Consumer Services, Platforms and Devices, Emma Mohr-McClune, says:

“The episode is symptomatic of the extreme jumpiness in the digital industry sector right now. No one can afford another data breach scandal.  It also points to the need for social media platform leadership to think through their public communications and password change recommendation processes for all vulnerability scenarios.” 

“The fact that it existed at all triggered the kind of mass security warning most digital communications providers would prefer not to have to deliver at all, especially not while the Facebook data privacy scandal is still ongoing,” Mohr-McClune concludes.

Twitter says there are steps users can take to keep their accounts safe.  

1. Change your password on Twitter and on any other service where you may have used the same password.

2. Use a strong password that you don't reuse on other services.

3. Enable login verification, also known as two factor authentication. This is the single best action you can take to increase your account security.

4. Use a password manager to make sure you're using strong, unique passwords everywhere.

“We are very sorry this happened. We recognise and appreciate the trust you place in us, and are committed to earning that trust every day,” Twitter concludes.

Story image
Cyber-risk to critical infrastructure reaches all-time high — report
New research from Nozomi Networks Labs found that attackers are doubling down on high-value targets and weaponising the software supply chain.More
Story image
Veeam reports growth as demand for modern data protection increases
“Even with the unforeseen challenges and circumstances that began in early 2020, Veeam continued its rapid growth with its second consecutive year of bookings over $1 billion."More
Story image
Kaseya acquires RocketCyber to bring SOC solutions to more businesses
"With this acquisition, we've doubled down on our security investments to provide our customers with access to experts who can continuously monitoring their IT environments without the cost and complexity of disparate tools.”More
Story image
How to stay ahead of the next cyber breach
With so many people working from home, the corresponding surge in app usage, unmanaged devices, web traffic and accessing internal resources is making security a much trickier prospect.More
Story image
Endace and Corelight step in to enhance incident response workflows
Endace and Corelight have entered into a strategic partnership to deliver security teams with insights and detailed forensic data to further enable rapid incident response.More
Link image
Why strong authentication is passwordless in 2021
Passwordless authentication is not only good practice, it is also increasingly becoming a regulated standard. Here's why robust solutions, like True Passwordless Authentication, are the way of the future.More