San Francisco, Mar 21: Facebook on Thursday admitted that millions of passwords were stored in plain text on its internal servers, a security slip that left them readable by the social networking giant's employees.
"To be clear, these passwords were never visible to anyone outside of Facebook and we have found no evidence to date that anyone internally abused or improperly accessed them," vice president of engineering, security, and privacy Pedro Canahuati said in a blog post.
The blunder was uncovered during a routine security review early this year, according to Canahuati.
He said that the Silicon Valley company expected to notify hundreds of millions of Facebook Lite users; tens of millions of other Facebook users, and tens of thousands of Instagram users whose passwords may have been vulnerable to prying eyes.
The basic security shortcoming was revealed on the heels of a series of controversies centered on whether Facebook properly safeguards the privacy and data of its users.
The basic data defense mistake would also appear contrary to the "Hacker Way" mantra that Facebook co-founder Mark Zuckerberg has espoused at the social network.
"One Hacker Way" is the main address of Facebook's vast campus in the California city of Menlo Park.
Brian Krebs of security news website KrebsOnSecurity.com cited an unnamed Facebook source as saying the internal investigation had so far indicated that as many as 600 million users of the social network had account passwords stored in plain text files searchable by more than 20,000 employees.
The exact number has yet to be determined, but archives with unencrypted user passwords were found dating back to the year 2012, according to Krebs.
"We have fixed these issues and as a precaution we will be notifying everyone whose passwords we have found were stored in this way," Canahuati said.
Let the Truth be known. If you read VB and like VB, please be a VB Supporter and Help us deliver the Truth to one and all.
New Delhi (PTI): Observing that crores of public monies had been siphoned off, the Supreme Court on Thursday dismissed industrialist Anil Ambani's three separate pleas, challenging the Bombay High Court order that allowed the proceedings, initiated by banks against him and Reliance Communications Ltd to classify their bank accounts as fraud, to continue.
A bench of Chief Justice Surya Kant and Justices Joymalya Bagchi and Vipul M Pancholi permitted Ambani to pursue his plea before the high court's single judge bench against the banks' show cause notices to declare the accounts as fraud.
"Hard-earned public money to the tune of thousands of crores has been siphoned. Did you make good losses to banks and financial institutions," the bench said.
Ambani and the firm were represented by senior advocates Kapil Sibal and Shyam Divan, who said the order would lead to the "civil death" of their clients.
Refusing to interfere with the February 23 order of the Bombay High Court's division bench, the SC said, "We see no ground to interfere with the judgment of the High Court (division bench). It is clarified that the observations of the Division Bench shall have no bearing in the pending suit. The (single judge bench) High Court is requested to expedite the disposal of the suit (filed by Ambani against the show cause notices issued by banks on move to declare the accounts as fraud)."
The bench requested the single judge bench to expeditiously decide Ambani's plea against the show cause notices issued by three banks.
The apex court passed the order while hearing three separate pleas filed by Ambani who had challenged a February 23 order of a division bench of the high court.
The division bench had quashed a single judge bench interim order that stayed proceedings initiated against him and Reliance Communications Ltd to classify their bank accounts as fraud.
The division bench allowed the appeals filed by three public sector banks and auditor firm BDO India LLP against the December 2025 interim order passed by a single bench.
The single judge bench order had stayed all present and future action by Indian Overseas Bank, IDBI Bank, and Bank of Baroda, noting that the action was based on a legally flawed forensic audit and violated the Reserve Bank of India's mandatory guidelines.
Ambani challenged the show cause notices issued by Indian Overseas Bank, IDBI and Bank of Baroda before the single bench, seeking to declare his and Reliance Communications' accounts as fraudulent.
At the outset, Sibal said there was a question of law that must be decided. The bench said, "the matter pertains to siphoning of thousands of crores of public money," and any intervention at this stage would prejudice the ongoing investigation by probe agencies.
"Please go and raise all these issues before the high court … show cause notices have been issued. You have your own remedy against them...institutions have been duped crores of rupees," the CJI said, adding, "it's a case of siphoning off… We can't really express any opinion as we don't want to prejudice."
Sibal submitted that Ambani had conveyed his willingness to amicably resolve and settle all pending matters with the banks.
Earlier, the high court's division bench quashed the single bench order and termed it "illegal and perverse."
The banks had challenged a December 2025 single-bench order granting interim relief to Ambani and his company.
The order cited violations of mandatory RBI rules and a classic case of banks "waking up from deep slumber" after years.
The three banks in their appeal said the forensic audit, which led to accounts being classified as "fraud", was legally valid and based on serious findings of fund siphoning and misutilisation.
This was recorded in the report submitted by the audit firm BDO LLP, they contended.
The banks, in their plea, also said Ambani had raised a technical challenge to the forensic audit before the single bench.
Ambani, as an interim relief, sought a stay of the notices and an injunction against any coercive action on the ground that BDO LLP was not qualified to conduct the forensic audit as its signatory was not a chartered accountant.
BDO LLP is an accounting consultant firm and not an audit firm, Ambani claimed. The single bench agreed with Ambani and stayed the action by the banks.
