Meta pays the price for storing passwords in plaintext
arstechnica.com
arstechnica.com
EU privacy regulator fines Meta 91M euros over password storage https://news.ycombinator.com/item?id=41669912 - September 2024 (28 comments)
I think every developer has some idea how this could have happened.
Someone is working on a bug. "I'll print this state out to console and remove before committing." Forgets to remove it and does git add *. Its overlooked in code review and is then pushed to prod. Once running, the stdout of the process is automatically shipped to some log database. And just like that, there are now passwords in plaintext in the log database.
Sloppy as hell? Sure. Malicious? Highly unlikely.
Then a month later someone queries that table and....oh shit.