7 ms·
I don't think they can make money off plain text passwords? They can only lose money from that, if it's discovered and they are fined and lose some users. They
by _cs2017_ 7y ago
I don't think they can make money off plain text passwords? They can only lose money from that, if it's discovered and they are fined and lose some users.
They can make money from contact lists, but IIUC the article said they didn't use the contact lists. Also, given that it only affected a couple million users (like 0.1% of their user base), the damage to their reputation would far outweigh any benefits of actually using those contact lists.
On the last item, the collection of email passwords, the only benefit would be if they actually use those passwords to get information, so the above point covers it.
Let me know if I'm missing something.
- wavefunction 7y agohow about extracting a user's contacts with their plaintext passwords that would usually be hashed into a database (at least in my professional experience) and thus unusable by facebook?
- deleted 7y ago[deleted]
- _cs2017_ 7y agoYou can do many evil things with passwords. But, according to the articles, that's not what happened. They did download contact lists, even though they never used the plaintext passwords they stored in the logs. The users involved in the two incidents were different.