sb-au logo
Story image

Twitter password glitch showcases 'extreme jumpiness' in digital sector

07 May 2018

More than 330 million Twitter users are being urged to change their passwords after an internal system glitch caused the passwords to be exposed in a log file.

Twitter is careful to state that there is no evidence the passwords were stolen, left the company’s systems or misused in any way, but issued the warning to change passwords as a precaution.

“When you set a password for your Twitter account, we use technology that masks it so no one at the company can see it. We recently identified a bug that stored passwords unmasked in an internal log,” an email to users states.

The bug was due to a problem with password hashing. The process wrote passwords to an internal log before they were hashed.

“We mask passwords through a process called hashing using a function known as bcrypt, which replaces the actual password with a random set of numbers and letters that are stored in Twitter's system. This allows our systems to validate your account credentials without revealing your password. This is an industry standard,” the company says.

The incident comes as World Password Day was celebrated to raise awareness about the importance of password security.

Commenting on the incident, GlobalData’s service director of Global Telecom Consumer Services, Platforms and Devices, Emma Mohr-McClune, says:

“The episode is symptomatic of the extreme jumpiness in the digital industry sector right now. No one can afford another data breach scandal.  It also points to the need for social media platform leadership to think through their public communications and password change recommendation processes for all vulnerability scenarios.” 

“The fact that it existed at all triggered the kind of mass security warning most digital communications providers would prefer not to have to deliver at all, especially not while the Facebook data privacy scandal is still ongoing,” Mohr-McClune concludes.

Twitter says there are steps users can take to keep their accounts safe.  

1. Change your password on Twitter and on any other service where you may have used the same password.

2. Use a strong password that you don't reuse on other services.

3. Enable login verification, also known as two factor authentication. This is the single best action you can take to increase your account security.

4. Use a password manager to make sure you're using strong, unique passwords everywhere.

“We are very sorry this happened. We recognise and appreciate the trust you place in us, and are committed to earning that trust every day,” Twitter concludes.

Story image
Sophos unearths origin of prominent cryptominer
The cryptominer was recently discovered when attackers targeted internet-facing database servers (SQL servers), and the MrbMiner was downloaded and installed.More
Story image
Alibaba Cloud and LGMS tackle hybrid and multi-cloud security
Alibaba Cloud and LGMS, a cybersecurity consulting company, are teaming up to tackle the challenge of security around digital transformation and hybrid cloud.More
Story image
Entrust acquires HyTrust, with aim to improve data encryption solutions
Entrust says the acquisition will bolster its effort to deliver data protection and compliance solutions to its customers, while accelerating their digital transformations.More
Story image
Pure Security & 6clicks take security risk management platform to market
“We are leading by example through our adoption of 6clicks, not just in Pure Security, but across the Tesserent group."More
Story image
The current state of ransomware — and its future
Discoveries made by analysts at Sophos have unearthed a new development: ransomware code appears to have been shared across ‘families’, and some of the ransomware groups seemed to work in collaboration more than in competition with one another. More
Story image
IronNet expands Asia Pacific presence with new strategic partnership
“The combination of M.Tech’s extensive network in Asia Pacific and our unparalleled expertise in threat intelligence and detection will help more enterprises across the region to proactively identify and take down known and unknown threats before they happen.”More