
As Washington focused on the release of special counsel Robert Mueller’s report on April 18, Facebook quietly changed a security announcement it had published almost a month earlier. The added paragraph contained a significant revision: the company now believed that passwords belonging to millions of Instagram users had been stored in a readable format inside its systems.
Facebook first disclosed the password-storage problem on March 21. It said a routine security review in January had found that some passwords were being kept in internal data stores without the protection normally applied by its login systems. At that point, the company estimated that it would notify hundreds of millions of Facebook Lite users, tens of millions of other Facebook users and tens of thousands of Instagram users.
The April update sharply increased the Instagram figure. Facebook said investigators had discovered additional logs containing readable Instagram passwords and that the affected population was in the millions. The company did not provide a more precise number, but said it would notify those users just as it planned to notify affected Facebook users.
How the storage problem differed from normal password handling
A properly designed service does not need to retain a person’s password in readable form. Facebook explained that its usual process transforms passwords with hashing and salting techniques, including the scrypt function and a separate cryptographic key. That process lets a system confirm a login without displaying or recovering the original password.
The improperly stored records were available only within Facebook’s internal systems, according to the company. Facebook said it had found no evidence that the passwords were exposed outside the business, abused by employees or accessed improperly. It also said the underlying problems had been fixed. Those assurances reduced one category of risk, but they did not answer why the scale of the Instagram exposure changed so dramatically between March and April.
Users covered by the notification were not told that an outside attacker had their credentials. Even so, standard account precautions remained sensible: use a unique password for Instagram, avoid reusing it on email or other services, and enable two-factor authentication. Reused credentials can turn a problem at one service into access to several accounts.
Why the timing attracted attention
The update appeared at about 7 a.m. Pacific time, while Attorney General William Barr was briefing reporters before the redacted Mueller report became public. Technology reporters quickly described the move as a classic bad-news release: a material correction placed inside an old post on a day when political news dominated nearly every front page.
There is no public evidence that Facebook deliberately chose the timing to hide the revision, so that interpretation should be distinguished from the facts the company confirmed. What is clear is that a reader of the original March announcement would not have learned about the larger Instagram impact without returning to the same post or seeing subsequent coverage.
The episode added another trust problem to an already serious engineering failure. Facebook said its investigation was continuing and that it was reviewing other stored information, including access tokens. For Instagram users, the essential news was straightforward: a disclosure once measured in tens of thousands of accounts had become one measured in millions.
Recent Comments