Google stored some passwords in text files for 14 years

In their blog Google announced a recently discovered bug that resulted in the passwords of some G Suite users being stored in an unencrypted format within plain text files. This bug has existed since 2005. However, Google claims that it hasn't found any evidence that any of these passwords were accessed by malicious actors or misused. Nonetheless, the company will reset all potentially affected passwords and inform G Suite administrators about the issue.

G Suite is the enterprise version of Gmail and other Google applications, and evidently, the issue arose in this product due to a feature specifically designed for businesses. In the early days of the service, company administrators could use G Suite applications to manually set user passwords, say, before a new employee joined the system. If they utilized this option, the admin console stored such passwords in plain text instead of hashing them. Later, Google removed this capability from administrators, but the passwords remained in text files.

Google stored some passwords in text files for 14 years

In its publication, Google carefully explains how cryptographic hashing works to clarify the nuances related to the bug. Although passwords were stored in plain view, they were located on Google servers, so unauthorized individuals could only gain access to them by hacking servers (if they weren't Google employees).

Google did not disclose the number of potentially affected users, only noting that it concerns a "subset of G Suite enterprise customers" — likely anyone who used G Suite in 2005. And while Google was unable to find evidence that anyone maliciously exploited this access, it is unclear who may have had access to these text files.

In any case, the issue has already been resolved, and Google expressed regret in its publication about the problem: "We take the security of our enterprise customers very seriously and are proud to promote industry-leading account security practices. In this instance, we did not meet our standards or those of our customers. We apologize to users and promise to do better in the future."



Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster