Twitter asks more than 330 million users to change passwords after a glitch

Twitter discovered the bug a few weeks ago and has reported it to some regulators, said the person, who was not authorized to discuss the matter

Twitter
Photo: Shutterstock
Reuters
2 min read Last Updated : Nov 29 2019 | 2:14 PM IST
Twitter Inc urged its more than 330 million users to change their passwords after a glitch caused some of them to be stored in plain text on its internal computer system.

The social network said it had fixed the glitch and that an internal investigation had found no indication passwords were stolen or misused by insiders, but it urged all users to consider changing their passwords “out of an abundance of caution.”

The blog did not say how many passwords were affected. But a person familiar with the company’s response said the number was “substantial” and that they were exposed for “several months.”

Twitter discovered the bug a few weeks ago and has reported it to some regulators, said the person, who was not authorized to discuss the matter.

The disclosure comes as lawmakers and regulators around the world scrutinize the way that companies store and secure consumer data, after a string of security incidents that have come to light at firms including Equifax Inc, Facebook Inc and Uber.

The European Union is due to start enforcing a strict new privacy law, known as the General Data Protection Regulation, that includes steep fees for violating its terms.

The glitch was related to Twitter’s use of a technology known as “hashing” that masks passwords as a user enters them by replacing them with numbers and letters, according to the blog.

A bug caused the passwords to be written on an internal computer log before the hashing process was completed, the blog said.  

“We are very sorry this happened,” the Twitter blog said.

Twitter’s share price was down 1 percent in extended trade at $30.35, after gaining 0.4 percent during the session.

The company advised users to take precautions to ensure that their accounts are safe, including changing passwords and enabling Twitter’s two-factor authentication service to help prevent accounts from being hijacked.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :Twitter

Next Story