More than 330 million Twitter users are being urged to change their passwords after an internal system glitch caused the passwords to be exposed in a log file.
Twitter is careful to state that there is no evidence the passwords were stolen, left the company’s systems or misused in any way, but issued the warning to change passwords as a precaution.
“When you set a password for your Twitter account, we use technology that masks it so no one at the company can see it. We recently identified a bug that stored passwords unmasked in an internal log,” an email to users states.
The bug was due to a problem with password hashing. The process wrote passwords to an internal log before they were hashed.
“We mask passwords through a process called hashing using a function known as bcrypt, which replaces the actual password with a random set of numbers and letters that are stored in Twitter's system. This allows our systems to validate your account credentials without revealing your password. This is an industry standard,” the company says.
The incident comes as World Password Day was celebrated to raise awareness about the importance of password security.
Commenting on the incident, GlobalData’s service director of Global Telecom Consumer Services, Platforms and Devices, Emma Mohr-McClune, says:
“The episode is symptomatic of the extreme jumpiness in the digital industry sector right now. No one can afford another data breach scandal. It also points to the need for social media platform leadership to think through their public communications and password change recommendation processes for all vulnerability scenarios.”
“The fact that it existed at all triggered the kind of mass security warning most digital communications providers would prefer not to have to deliver at all, especially not while the Facebook data privacy scandal is still ongoing,” Mohr-McClune concludes.
Twitter says there are steps users can take to keep their accounts safe.
1. Change your password on Twitter and on any other service where you may have used the same password.
2. Use a strong password that you don't reuse on other services.
3. Enable login verification, also known as two factor authentication. This is the single best action you can take to increase your account security.
4. Use a password manager to make sure you're using strong, unique passwords everywhere.
“We are very sorry this happened. We recognise and appreciate the trust you place in us, and are committed to earning that trust every day,” Twitter concludes.