Instagram accidentally exposed user passwords through its data download tool
theverge.com
theverge.com
Uh-huh.
If that's the case, how did they extract the plaintext password from the stored password to embed in the URL?
Possible scenarios are
1. They are lying and stored plaintext passwords.
2. They do hash/salt to store the password in the db but they also use the plaintext password provided from the client side for other things as well.
3. Or they have secretly developed technology to reverse the hash/salt.
I'm feeling nice so my guess is #2. They do hash/salt in the db and use that for password matching but they also do stuff with the plaintext. It's hard to imagine #1 being true for a major tech company like FB and even harder for #3 being true.