- password goes through filter check onSubmit and some flag is set on the account immediately, it's added to a queue, pw is hashed and stored
- "account moderation" worker picks up task from its gigantic queue of Chinese accounts that need some automated action taking on them, bans account, notifies user, does whatever else needs to be done when closing an account for a service like WeChat
Edit just to remark: a lot of people commenting on this thread are making some pretty big assumptions about both what apps do do and should do with passwords.
In my experience, you can more or less say this: most companies and applications in 2020 do hash passwords before storing them in the database.
Beyond that, all bets are off.
To be clear, I wouldn't bet it all that the passwords are stored in plaintext. But I would bet it all that the CCP has their own special key and/or backdoor access which allows them to continue having omnipotence and omniscience while keeping pesky foreign powers out.
I doubt it. The CCP is bad, but it's also pretty rational. Doing this would just be dumb.
My first foray into options trading I lost around 3% of my net worth, and I'd say I'm more than twice as confident about this than I was about that.
I'd evaluate the odds of the CCP doing something, to be in line with the odds of them benefiting from doing something, regardless of the expense/risk to their populace.
There's nothing I'd really put past them, we know for a fact they harvest organs from political dissidents, but we're skeptical on if they'd store passwords plaintext?
Given people tend to re-use passwords, I'd imagine having a massive trove of plaintext passwords for all Chinese citizens, or even anyone who communicates with them, would be incredibly useful.
Not to mention the fact that they have to maintain a list of anti-CCP passwords, which would be a tedious process, or they'd have to automate something to detect anti-CCP sentiment. I think an interesting experiment would be to see what less obvious anti-CCP passwords get you banned. With enough probing and data, I'd possibly increase my wager to 10%.
As a well known and outspoken critic of the CCP, she might be elevated to the status where they actually just have a person reading everything she types into WeChat 24/7. Do you think they fully staff the night shift, or would the ban have taken twice as long outside of Chinese business hours?
Would I bet that the Chinese Government has this properly implemented and can't access passwords once set? Yeah no way.
Just in terms of security policies this is nuts.
Inspecting the political contents of passwords is nuts and tyranny.
Inspecting the contents of passwords at all is nuts and spectacularly bad.
Like choosing business associates based on their politics, just at a larger scale.
Evaluating a passwords' strength or complexity is incredibly routine.
Because the CCP is a totalitarian state with an interest in controlling expression, even in passwords?
Just because WeChat does numerous, dislikable things, doesn't mean they monitor passwords. Or did this.
Is there like only one xi jingling in the whole china? If not, what at others supposed to do?
Change their surnames
And why would you do fuckery with a journalists password? Seems like especially stupid thing to do
Surely the least likely of all possible explanations, but an easter egg blocking passwords that are variations of "I refuse to cooperate" would be a hidden artistic statement in its own way.
Would you trust the third party that flagged this as offensive:
F*ckCCP89
Edit: given that her account was permanently deleted after just 45 seconds, I actually think some party member working at WeChat is monitoring her activities in real-time. The password probably get him angry enough to push the permadelete button.
Would a native Chinese speaker even have that visceral emotional reaction to English profanity? I'm curious about how that impact translates.
I'd also assume they'd assign the english speaking North American dissidents to a monitoring person who speaks good english.
Also, I have hard time seeing an automated system that deletes someone's account including all data for using the f-word in their password.
People reuse passwords, so its likely that WeChat passwords allow access to other systems (like Facebook, Twitter, Alibaba, Amazon,...)
This attack angle of just collecting passwords for government has not yet occured to me before.
And then people getting surprised from where do those ginormous plaintext password leaks come from.
All kinds of popular online forum engines were being hacked for password captures since times immemorial. PHPBB still uses server side hashing for example.
Now, for people concerned, take a look who was the party who sank crypto forms at W3C.
Direct access via the companies themselves is probably much more valuable today.
In the case of China in particular we know that part of the "Great Firewall" have IP addresses associated with Chinese residential ISPs, whether those are "hijacked" or the relevant agency just asks nicely we do not know. So it may be that "Chinese central government intelligence agency" and "My neighbour's WiFi" are similar IP addresses if you live there.
But yes multi-factor authentication can reduce the impact of credential stuffing attacks.
WeChat service will receive the password in plaintext. It's able to do processing on that plaintext value.
It is likely storing a hashed version of the password in the database.
At some point all passwords are plain text, be it on the client or whatever, they could simply check it before it is encrypted and stored, even on the client end if they wanted to.
In the OP case it could be many factors added together that led to the banning.
This underscores how precious and fragile the freedom of speech is.