Hacker News new | past | comments | ask | show | jobs | submit login
Meta pays the price for storing passwords in plaintext (arstechnica.com)
22 points by mdhb 3 months ago | hide | past | favorite | 6 comments



Author of this article learned a lot about password hashing, missed the detail that this was in logs, not the database. Usually you try to avoid logging passwords, you don’t hash them in logs.


Yup. A bunch of coverage is understating this point, and the peanut gallery commenters are taking it hook, line, and sinker. Accidentally logging plaintext passwords, whilst concerningly incompetent, is not on the same level as explicitly deciding to store plaintext passwords.


Most companies have this problem, devs logging credentials all the time. Many web frameworks have a log all then blacklist mentality which leads to soo many mistakes. ex ruby on rails etc.



The fine is too low for a company of this size.


91m is a drop in the bucket for Meta. Jesus.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: