Home / Tech News / Featured Tech News / Kaspersky Lab advises how all Twitter users should change their passwords following hashing glitch

Kaspersky Lab advises how all Twitter users should change their passwords following hashing glitch

Like many online companies, Twitter uses a hashing protocol to ensure that user passwords are masked when they hit servers, protecting them from potential prying eyes. Unfortunately, a bug has been disrupting this process for “several months” and has resulted in Twitter advising that all 336 million users should change their passwords immediately.

Twitter CTO Parag Agrawal explained that the fault in its bcrypt hashing function resulted in user passwords to be exposed in plaintext, “written to an internal log before completing the hashing process.”

“We found this error ourselves, removed the passwords, and are implementing plans to prevent this bug from happening again,” explained Agrawal, while noting that there are no signs of foul play. “We have fixed the bug, and our investigation shows no indication of breach or misuse by anyone.”

The exact number of affected users hasn’t been revealed, and the advice extending to all 336 million users seems more precautionary than an indication of all users being affected. Kaspersky Lab has commended the platform for taking responsibility by communicating this clearly with account holders, while offering its own advice on improving password security.

twitterphone2.jpg

“This story does however, highlight the importance of using unique passwords for all online accounts, as well as two-factor authentication for added security, where it’s available,” explains Principal Security Researcher at Kaspersky Lab David Emm in an email to KitGuru.

Every password should be at least 15 characters long, however the longer the password, the more secure it will be, explains Kaspersky Lab. This should avoid all personal details such as the user’s birthday, partner’s name, family details and anything else that can be guessed or identified through online profiles.

Going as far as to avoid real words will benefit the user tremendously, especially with the inclusion of different cased letters, numbers and symbols. This should differ per account, avoiding catastrophe across multiple platforms if one is breached.

Users can make use of third-party password management systems such as LastPass or 1Password, which helps users easily achieve all of this with one master password. Most of all, however, users should always be making use of two-factor authentication, to which Twitter’s Agrawal notes “is the single best action you can take to increase your account security.”

Discuss on our Facebook page, or over on Twitter.

KitGuru Says: It’s entirely possible that Twitter’s open and honest attitude stems from being closely watched thanks to the Facebook debacle, but it’s a refreshing take on the ‘swept-under-the-rug’ attitude nonetheless. Make sure to change your passwords when you can and diversify them as much as possible. When was the last time you changed your password?

Become a Patron!

Check Also

Computex 2025: Montech’s most ambitious line-up yet

Montech has released some very interesting cases in recent years. This week at Computex, Leo stopped by their booth to get a look at all the latest in PC cases, as well as some new coolers and peripherals.

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!