5 ms·
This would never happen at Amazon and I am sure at every other major tech company. There are systems in place to prevent exactly this.
by zeko1195 7y ago
This would never happen at Amazon and I am sure at every other major tech company. There are systems in place to prevent exactly this.
- s3buckets 7y agoFunny that you mention Amazon, because open S3 buckets have been implicated in dozens of security breaches. It's not so much that Amazon is the culpable party in those instances, but so many times, have I encountered a headline citing a "massive exposure of protected data" and somewhere in the body of the article, someone had dropped everything into an S3 bucket marked open read for public everyone. So, is it Amazon's fault? This sort of thing was an FTP server thing, before S3 reduced the hardware infrastructure overhead of setting up and maintaining your own secure FTP server... But, then again, lowering the technical bar meant letting in more and more non-experts, and naive, or otherwise less competant people. This, of course, broadens market penetration, and increases revenue. So, to add barriers, irritating warnings, nanny-goat advisories, hazard alarms to such a versatile and useful product might seem tantamount to leaving money on the table. After all, the goal of the product is ease of use. And, by the way, how does one solve the problem of bone-headed users? But, you know, there's the real distinction between an AWS S3 data breach and a Facebook data breach: with S3, you've shot yourself in the foot. Facebook, on the other hand, is pointing a gun at you.
- tptacek 7y agoI don't know enough about Amazon to call bullshit on this, but I do know enough about other major tech companies to call bullshit on this.
- OrgNet 7y agoWhich other large company store plain text passwords? How long before they start trying to re-use the passwords to log in other services without your consent
- ceejayoz 7y ago> Which other large company store plain text passwords? That's not really what Facebook is saying they did. They accidentally logged passwords to a log file somewhere. They're not saying they stored them in the users database in plain text.
- OrgNet 7y agoRight, but it has the same end result. Also, I guess they don't look at their log files? The passwords were there in clear text for 7 years apparently: https://techcrunch.com/2019/03/21/facebook-plaintext-passwords/ https://techcrunch.com/2019/03/21/facebook-plaintext-passwor...
- ceejayoz 7y ago> Right, but it has the same end result. Irrelevant. The point was that "we accidentally logged something sensitive" is something any big tech company can (and is likely to) do. Deliberately storing passwords as plaintext in the users table much less so. > Also, I guess they don't look at their log files? If they were temporarily logging something for a particular reason, and forgot to turn it off, there'd be no reason to.
- tptacek 7y agoThis is supremely silly. They logged passwords by accident. It wasn't a user acquisition feature.
- OrgNet 7y agoNo, it is silly to think that they didn't know about it... ie: for 7 years, no one looked at those passwords? They can't be that dumb... Anyways, what other companies should we avoid, according to you (the ones that you referenced in your previous comment)? Are you protecting your friends at Facebook, and yourself, because you know that you are likely to do the same mistake?
- stevietopsiders 7y agoI work at AMZN and am actually a "security certifier" who is in charge of making sure that services don't do stuff like this. There are numerous policies about what customer information you can handle/log/store and how to handle/log/store it. In addition, before your service can serve traffic, a certifier will go through and audit your code to make sure that you aren't logging any PII or other dangerous-to-log data. Plenty of fallible human actors involved, but the processes are definitely in place to prevent behavior like this.
- crescentfresh 7y agoI think you're assuming the passwords were stored in readable format as a matter of design. That would get reviewed and flagged at any moderately competent tech company. I think it was probably something more inane like a POST body being logged. That could slip through a reviewer's crack easily. Not defending this breach in any way.
- angstrom 7y agoGateways filter that before internal services see anything. There's not any reason to be playing with passwords beneath the Authentication layer. Credentials should be exchanged for the customer identity and expirable nonce. If that mistake happened in the authentication/authorization layer then it becomes a big question of competence.