Twitter Recommends Changing Your Password Following Plaintext Exposure Glitch - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Twitter Recommends Changing Your Password Following Plaintext Exposure Glitch

by

twitterlogoTwitter is suggesting that all Twitter users update their passwords following a glitch that exposed some passwords in plaintext on its internal network.

As outlined in a blog post, Twitter says that it recently found a bug that "stored passwords unmasked in an internal log." The bug was fixed, and an internal investigation shows that there was no breach or misuse.

We mask passwords through a process called hashing using a function known as bcrypt, which replaces the actual password with a random set of numbers and letters that are stored in Twitter's system. This allows our systems to validate your account credentials without revealing your password. This is an industry standard.

Due to a bug, passwords were written to an internal log before completing the hashing process. We found this error ourselves, removed the passwords, and are implementing plans to prevent this bug from happening again.

Despite the fact that no one appears to have accessed the plaintext passwords, Twitter is recommending that all users "consider" changing their passwords "out of an abundance of caution" both on Twitter and on any other site where the same password was used.

If you're a Twitter user, you can change your password on the web by accessing your Twitter settings and selecting the password option. You will need to enter a current password and then choose a new one. In the Twitter iOS app, you'll need to sign out to initiate a password change.

Using a unique password for every login is the best way to make sure you stay secure in the event of a data breach, something best managed with an app like 1Password or LastPass.

Twitter is recommending users choose a unique, strong password and then protect their accounts with two factor authentication.

Tag: Twitter

Top Rated Comments

110 months ago
THAT’s how you handle a situation like that.
Score: 21 Votes (Like | Disagree)
110 months ago
Ah, celebrities take note. For a limited time, you can claim that you didn't actually post that tweet yourself but rather someone hacked into your account due to this mistake!
Score: 14 Votes (Like | Disagree)
Porco Avatar
110 months ago
Oh no, it won't let me add a password of more than 280 characters! ;)
Score: 11 Votes (Like | Disagree)
OldSchoolMacGuy Avatar
110 months ago
All of those commenting about firing the person responsible, are completely ignorant to how the business world and technology works.

Software has bugs. There are mistakes. If you fired everyone that made a mistake, you'd set a precedent that would instill fear in everyone else. No one would want to dare make a single mistake, for fear of losing their job and thus everything grinds to a halt.

These companies have become what they are by innovating and pushing forward. You fire people for mistakes (look up the definition, I didn't say malice) then you'd either fire everyone or stop all growth and progress.

People responsible in these situations aren't fired. That's simply not how it works.
Score: 7 Votes (Like | Disagree)
dougc84 Avatar
110 months ago
My question is why the plaintext password is even sent to them for password resets. There's zero reason for that. Shouldn't it just be validated and hashed by the webpage's script before sending?
There is no hashing done by web page scripts unless the site you are on uses Javascript for both the front end and back end (such as with React, node.js, etc.). Twitter is not one of those sites. However, values are encrypted over the line due to the SSL certificate (why you see HTTPS in the browser), but those values are decrypted on the server. The web server has to handle them somehow, and certainly can't validate anything, create new records (tweets, users, etc.) or update anything (such as your user profile) if it's just garbled encryption. It is not plaintext over the line.

This is inexcusable. Which developer had the bright idea to store passwords to a log file? That should never happen, ever. There's no reason for it.
Twitter was built on Ruby on Rails. It has, I believe, since migrated to another platform, but many of the concepts still remain, regardless of framework used. In Rails, for example, everything is logged - all parameters sent from a form (login info, new tweet message, profile settings, etc.) go to the log file, as well as database transactions and manual log messages.

In real world applications, regardless of programming framework used, logging either goes to an actual file on the drive of a server, or to a drain that feeds the log line-by-line to a service (so it can be searched or you can receive alerts on errors, etc.). There are also multiple levels of logging depending on what needs priority - everything from fatal and error messages that have higher priority, to info and debug messages for general system events. Things like this would have been an info message with parameters received from a client, POSTing to a particular endpoint. Those basic info and debug messages can be omitted from production logs, which does make debugging errors more difficult, but is often done for security purposes (the "use a sledgehammer to hammer in a nail" approach).

In most cases, the application framework employs sanitizers to mask sensitive parameters from being sent to the log (i.e. passwords, credit card numbers, social security numbers, etc.). This happens in a configuration file that isn't touched often, if ever, after the application is deployed on a website. Additionally, masking sensitive parameters occurs in production but not always in local development, since building, updating, or fixing features requires a higher level of knowledge of what's going on vs. once something has gone live.

My guess is they either accidentally turned off the sanitizer, changed the password field name or are using an alias field name to prevent bots (most likely case), or never masked it in the first place and decreased the log level for debugging purposes. It's a simple mistake that isn't easily apparent.

In any case, this happened on their end, they noticed it, and they let us know. There's no indication that anything has actually been accessed. And, even still, with most accounts using 2FA, most users staying perpetually logged in, and with API keys being how external applications authenticate to your Twitter account (not with your password), the likelihood of your password even showing up in the log is very slim anyway. I'm not saying you shouldn't change your password (because you absolutely should), but this sounds much scarier than it actually is.
Score: 6 Votes (Like | Disagree)
Apple_Robert Avatar
110 months ago
I have Two Factor Authentication turned on with my Twitter account. If they had my password, it is useless to them.
Score: 5 Votes (Like | Disagree)

Popular Stories

Home Hub Command Center with Dome Base Feature

Apple Smart Home Hub to Feature iMac G4-Style Design

Wednesday September 30, 2026 4:36 am PDT by
Apple's long-rumored smart home hub will have an iMac G4-style design and a host of unique features, Bloomberg's Mark Gurman reports. The smart home hub is said to feature a square 6-inch display, with variants that can be placed on a countertop or mounted on a wall. It features a single FaceTime camera on the front, with microphones and speakers in its connected base. Gurman described the...
HomePod minis on gradient feature 1 1

Three New Apple Smart Home Products Coming on October 13

Wednesday September 30, 2026 4:04 am PDT by
Apple plans to introduce a series of new smart home products on Tuesday, October 13, according to Bloomberg's Mark Gurman. Apple reportedly plans to debut its long-awaited smart home hub device, a new HomePod mini, and a new Apple TV on the date. The new HomePod mini and Apple TV are set to retain their existing designs, but tout faster chips to support Siri AI. The new HomePod mini will...
Apple TV Sans Remote Feature

New Apple TV 4K Leaked

Friday September 25, 2026 8:16 am PDT by
MacRumors contributor Aaron Perris has uncovered an image file from Apple for an unreleased Apple TV 4K, suggesting that a new model will finally be released soon. The image is specifically for an "Apple TV 4K (4th generation)" model. Apple TV 4K (4th generation) image (on a gradient) The image reveals that the Apple TV will have the same external design as the current model, with all of its...
Latest Stories
Apple TV Still Down for Some Users Following Apple Services Outage
Apple TV Still Down for Some Users Following Apple Services Outage
6 minutes ago
PSA: Apple Mail on Mac May Stop Syncing Microsoft 365 Accounts Today
PSA: Apple Mail on Mac May Stop Syncing Microsoft 365 Accounts Today
31 minutes ago
Apple's Smart Home Hub: Everything We Know So Far
Apple's Smart Home Hub: Everything We Know So Far
11 hours ago
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
12 hours ago
Apple Invites App Updated With Three New Features
Apple Invites App Updated With Three New Features
16 hours ago
Apple Event on October 13?
Apple Event on October 13?
17 hours ago
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
19 hours ago
iPad Mini 8 to Offer These 10 New Features
iPad Mini 8 to Offer These 10 New Features
19 hours ago
DoorDash Unveils AI Food Ordering Through Apple's Messages App
DoorDash Unveils AI Food Ordering Through Apple's Messages App
21 hours ago
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
21 hours ago
Apple Still Plans to Release a New Full-Sized HomePod
Apple Still Plans to Release a New Full-Sized HomePod
22 hours ago
Apple Working to Expand HomeKit
Apple Working to Expand HomeKit
23 hours ago
Apple Smart Home Hub to Feature iMac G4-Style Design
Apple Smart Home Hub to Feature iMac G4-Style Design
23 hours ago
Three New Apple Smart Home Products Coming on October 13
Three New Apple Smart Home Products Coming on October 13
1 day ago
Apple Pay Now Available in India With Axis Bank Cards
Apple Pay Now Available in India With Axis Bank Cards
1 day ago
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
2 days ago
AirPods 5 Teardown: Batteries Removable, Case Still Tough
AirPods 5 Teardown: Batteries Removable, Case Still Tough
2 days ago
iPhone 18 Pro Owners Complain of Speaker Crackling or Popping
iPhone 18 Pro Owners Complain of Speaker Crackling or Popping
2 days ago
You Can 'Get Ready' for iPhone Duo Pre-Orders on October 12
You Can 'Get Ready' for iPhone Duo Pre-Orders on October 12
2 days ago
Apple Pay Reportedly Launching in India Today
Apple Pay Reportedly Launching in India Today
2 days ago
Apple Releases New AirPods Beta Firmware
Apple Releases New AirPods Beta Firmware
2 days ago
Apple Shares New Guide for Using iOS 27 Parental Controls
Apple Shares New Guide for Using iOS 27 Parental Controls
2 days ago
Apple Creator Studio and Final Cut Camera Get New Features
Apple Creator Studio and Final Cut Camera Get New Features
2 days ago
Apple Explains Why It Removed ICE Tracking Apps Last Year
Apple Explains Why It Removed ICE Tracking Apps Last Year
2 days ago
Amazon Expands $779.99 Apple Watch Ultra 4 Deal to More Models
Amazon Expands $779.99 Apple Watch Ultra 4 Deal to More Models
2 days ago
Switch Siri AI for ChatGPT on Your Mac
Switch Siri AI for ChatGPT on Your Mac
2 days ago
Apple Says Emergency SOS via Satellite Now Available in Norway
Apple Says Emergency SOS via Satellite Now Available in Norway
2 days ago
AppleCare Guide: Is it Worth Paying For?
AppleCare Guide: Is it Worth Paying For?
2 days ago
Apple Reportedly Planned to Replace 5,000 Support Employees With AI
Apple Reportedly Planned to Replace 5,000 Support Employees With AI
2 days ago
Apple Planning to Launch Products Faster and More Often
Apple Planning to Launch Products Faster and More Often
2 days ago

🔗 Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors