Bitcoin Forum
May 02, 2024, 10:33:16 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Google Has Been ‘Accidentally’ Storing Passwords in Plaintext Since 2005  (Read 248 times)
wwzsocki (OP)
Legendary
*
Offline Offline

Activity: 2730
Merit: 1708


First 100% Liquid Stablecoin Backed by Gold


View Profile WWW
May 23, 2019, 07:49:51 PM
 #1

Google typically stores its passwords in a cryptographically-scrambled hash. However, due to the bug, G Suite’s password recovery feature for administrators somehow allowed the passwords to be stored in the admin’s control panel. As of recently, Google has disabled the feature causing the security risk.

However, for a long time, the passwords were accessible to both authorized Google personnel and malicious hackers.

The plaintext bug is nothing new. In fact, Twitter and Facebook have both dealt with similar issues in the past year or so. However, Google is taking this a step further by auto-resetting passwords out of caution. So, kudos for taking that extra measure.

The trouble is, this bug has existed since at least 2005. Although the company claims the passwords were never compromised, 14 years is a long time for this to go under the radar.

If you’re a G Suite user, you should really add two-factor authentication and pray that your password was never compromised.



https://beincrypto.com/google-has-been-accidentally-storing-passwords-in-plaintext-since-2005/

1714645996
Hero Member
*
Offline Offline

Posts: 1714645996

View Profile Personal Message (Offline)

Ignore
1714645996
Reply with quote  #2

1714645996
Report to moderator
1714645996
Hero Member
*
Offline Offline

Posts: 1714645996

View Profile Personal Message (Offline)

Ignore
1714645996
Reply with quote  #2

1714645996
Report to moderator
According to NIST and ECRYPT II, the cryptographic algorithms used in Bitcoin are expected to be strong until at least 2030. (After that, it will not be too difficult to transition to different algorithms.)
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
AB de Royse777
Legendary
*
Offline Offline

Activity: 2478
Merit: 3892


Hire Bitcointalk Camp. Manager @ r7promotions.com


View Profile WWW
May 23, 2019, 07:53:01 PM
 #2

~snip~

If you’re a G Suite user, you should really add two-factor authentication and pray that your password was never compromised.



https://beincrypto.com/google-has-been-accidentally-storing-passwords-in-plaintext-since-2005/
Holly cow!
I use gmail account, does that mean the G suite password is the same? I mean gmail and G suite is same thing right? I am just confuse with this G suite?

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
wwzsocki (OP)
Legendary
*
Offline Offline

Activity: 2730
Merit: 1708


First 100% Liquid Stablecoin Backed by Gold


View Profile WWW
May 23, 2019, 07:56:55 PM
 #3

I use gmail account, does that mean the G suite password is the same? I mean gmail and G suite is same thing right? I am just confuse with this G suite?

No, I don't think so. Only the admin panel in G Suite was affected.

G Suite is an integrated suite of secure, cloud-native collaboration and productivity apps powered by Google AI. Includes Gmail, Docs, Drive, Calendar, Meet and more.

This is what description says, here is a link https://gsuite.google.com/

I am sure a lot of people is using it, especially small businesses and companies.

akamit
Hero Member
*****
Offline Offline

Activity: 1484
Merit: 595


View Profile
May 23, 2019, 08:07:21 PM
 #4

No, I don't think so. Only the admin panel in G Suite was affected.
I don't use G Suite. Then will it affect gmail?
But I thought at first that we have one pass for all Google products & services.

So are we safe from this, I mean users of adsense, analytics, adwords ?

wwzsocki (OP)
Legendary
*
Offline Offline

Activity: 2730
Merit: 1708


First 100% Liquid Stablecoin Backed by Gold


View Profile WWW
May 23, 2019, 08:15:11 PM
 #5

I don't use G Suite. Then will it affect gmail?...
So are we safe from this, I mean users of adsense, analytics, adwords ?

I don't think so but I can't guarantee that. Try to read this article (link above) to know more about this problem and what is affected.

When I was reading this headline I thought this same "oh shit my email account affected?" but I think not because one has to use GSuie and log in using Admin panel.

But I can be wrong because I have never used G Suite only knew about it and to be honest I thought is an app  Cheesy.

That is why I shared this because nobody knows how many people are using this tool, to be honest. Could be many or nobody.

TryNinja
Legendary
*
Offline Offline

Activity: 2814
Merit: 6974



View Profile WWW
May 23, 2019, 08:15:51 PM
 #6

I don't use G Suite. Then will it affect gmail?
But I thought at first that we have one pass for all Google products & services.

So are we safe from this, I mean users of adsense, analytics, adwords ?
If I understood correctly, yes.

According to the article, the flaw was on the admin password recovery page/featured.

Also, it says:
Quote
If you’re a G Suite user, you should really add two-factor authentication and pray that your password was never compromised.

Implying that normal users weren’t affected.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
suchmoon
Legendary
*
Offline Offline

Activity: 3654
Merit: 8921


https://bpip.org


View Profile WWW
May 23, 2019, 08:35:46 PM
 #7

I use gmail account, does that mean the G suite password is the same? I mean gmail and G suite is same thing right? I am just confuse with this G suite?

G Suite is their business product that includes gmail among other things, so no, it's not the same and you're likely not affected if you don't use G Suite and don't have e.g. a corporate/branded google account through your job/school/etc.

However those who use G Suite would have the same account for EVERY google product, including Android phones etc so it's a major fuckup nonetheless.
AB de Royse777
Legendary
*
Offline Offline

Activity: 2478
Merit: 3892


Hire Bitcointalk Camp. Manager @ r7promotions.com


View Profile WWW
May 24, 2019, 11:51:10 AM
 #8

~snip~

No, I don't think so. Only the admin panel in G Suite was affected.

G Suite is an integrated suite of secure, cloud-native collaboration and productivity apps powered by Google AI. Includes Gmail, Docs, Drive, Calendar, Meet and more.

This is what description says, here is a link https://gsuite.google.com/

I am sure a lot of people is using it, especially small businesses and companies.
Thank you, that's a relief from my side however this is something new to me. I hard about G Suite but never got interested to study about it. I thought it's another service extension of google like webmaster etc.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
wwzsocki (OP)
Legendary
*
Offline Offline

Activity: 2730
Merit: 1708


First 100% Liquid Stablecoin Backed by Gold


View Profile WWW
June 21, 2019, 06:03:33 PM
 #9

I have seen that nobody is talking about this here so decided to warn community because is Google and even if only G Suite admin panel was affected this is still a big thing.

Especially if this was vulnerable for almost 15 years.

Lately, in our local section, we have talked about: "how safe are passwords in browsers?" and I think I have my answer now.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!