Google sorry for saving users'' password in readable form : The Tribune India

Join Whatsapp Channel

Google sorry for saving users'' password in readable form

SAN FRANCISCO: Google on Wednesday extended an apology to its G Suite customers after revealing that it stored passwords of some enterprise users in plaintext for years.

Google sorry for saving users'' password in readable form

Photo for representative only.



San Francisco

Google on Wednesday extended an apology to its G Suite customers after revealing that it stored passwords of some enterprise users in plaintext for years.

Storing passwords without cryptographic hashes expose them to hacking risk as they become readable.

The issue has been around since 2005 and Google, in a statement, said it is working with enterprise administrators to ensure that the users reset their passwords.

"We recently notified a subset of our enterprise G Suite customers that some passwords were stored in our encrypted internal systems unhashed.”

"This is a G Suite issue that affects business users only -- no free consumer Google accounts were affected," said Suzanne Frey, Vice President, Engineering, Cloud Trust at Google, adding that the company neither lived up to its own standards nor those of its customers.

"We apologise to our users and will do better," she added.

If you have a Google account, Google's core sign-in system is designed not to know your password.

When you set your password, instead of remembering the exact characters of the password, the company scrambles it with a "hash function", so it becomes something like "72i32hedgqw23328", and that's what is stored with your username.

"Both are then also encrypted before being saved to disk. The next time you try to sign in, we again scramble your password the same way. If it matches the stored string then you must have typed the correct password, so your sign-in can proceed," explained Frey.

In its enterprise product G Suite, Google found that some passwords were stored unhashed in plaintext.

"To be clear, these passwords remained in our secure encrypted infrastructure. This issue has been fixed and we have seen no evidence of improper access to or misuse of the affected passwords," Google claimed.

Google said it has notified G Suite administrators to change the impacted passwords.

Twitter recently advised all its 330 million users to change passwords owing to a breach.

Facebook in March revealed it fixed a security issue wherein millions of its users' passwords were stored in plain text and "readable" format for years and according to reports, were searchable by thousands of its employees.

After admitting it "unintentionally" uploaded emails of nearly 1.5 million of new users, Facebook later revealed that millions of Instagram passwords were also stored on its servers in a readable format.

IANS

Top News

Lok Sabha election 2024: Voting under way in 88 constituencies; Rahul Gandhi, Hema Malini in fray

Over 63 per cent turnout in Phase 2 of Lok Sabha polls; Tripura records 79.46 per cent, Manipur 77.32 Over 63 per cent turnout in Phase 2 of Lok Sabha polls; Tripura records 79.46 per cent, Manipur 77.32

The Election Commission says polling remained largely peacef...

Arvind Kejriwal as CM even after arrest puts political interest over national interest: Delhi High Court

Arvind Kejriwal as CM even after arrest puts political interest over national interest: Delhi High Court

The court says the Delhi government is ‘interested in approp...

Amritpal Singh to contest Lok Sabha poll from Punjab’s Khadoor Sahib, confirms mother

Amritpal Singh to contest Lok Sabha poll from Punjab’s Khadoor Sahib, confirms mother

The formal announcement is made by his mother Balwinder Kaur...

Supreme Court to deliver verdict on PILs seeking 100 per cent cross-verification of EVM votes with VVPAT today

Supreme Court dismisses PILs seeking 100% cross-verification of EVM votes with VVPAT slips

Bench however, issues certain directions to Election Commiss...

Will stop functioning in India if made to break encryption of messages: WhatsApp to Delhi High Court

Will stop functioning in India if made to break encryption of messages: WhatsApp to Delhi High Court

Facebook and Whatsapp have recently challenged the new rules...


Cities

View All