4 ms·
The article indicates it was searchable and used for something by employees, so most of these comments to the effect of ‘they must have been doing this accident
by code_duck 8y ago
The article indicates it was searchable and used for something by employees, so most of these comments to the effect of ‘they must have been doing this accidentally because Facebook is just so big therefore they are excused’ are invalid. Some group of people did this on purpose and knew it was happening.
- chatmasta 8y agoYou're probably being downvoted for speculation, but that sounds completely reasonable to me. At least one person had to have noticed a password in a log file they were viewing at some time. Most people viewing log files know that passwords should not be there. It would trigger alarm bells, and depending on the person, also excitement -- you have somebody's facebook password. It's conceivable that someone then told their friend at work, and a few of these 2,000 developers knew of this secret internal stash of passwords they could access whenever they wanted to "prank" someone on facebook...
- YokoZar 8y agoWhy would humans be reading these log files?
- chatmasta 8y agoFor plenty of reasons, I'm sure. From the article: > My Facebook insider said access logs showed some 2,000 engineers or developers made approximately nine million internal queries for data elements that contained plain text user passwords.
- YokoZar 8y agoThat doesn't sound like a human reading the log. It sounds like automation. A script counting the number of successful logins, for instance, could read the same data element that unintentionally contained passwords.
- code_duck 8y agoWe don’t have enough information to make that judgment.
- code_duck 8y agoWhen you’re developing a feature like this, don’t you look at the data that you’re logging in to make sure things are working properly? I would imagine that Facebook has many layers of abstraction, but in somewhere, incompetence or inattention must be involved, sometimes known as negligence, if not outright knowledge of this. The definition of that is a complex thing, but if someone could have reasoned that this was logging plaintext passwords, and either saw it and didn’t bother to change things, or didn’t think about it carefully enough to realize that it was doing this, it would be considered negligent. I know that I would feel that my trust in this organization has been betrayed, as a user.
- tptacek 8y agoThe logs being in a searchable index makes it more likely that the password storage was inadvertent, not less. It implies that the primary usage model for the logs was targeted queries, not people starting at the top of the logs and reading down in such a way that nothing could have been missed.
- code_duck 8y agoMy interpretation was that they were using the plaintext password as one of the searchable fields, presumably for development related to authentication.