Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Facebook deploys credential analysis tool to protect users

by The Gurus
September 10, 2020
in Editor's News
Share on FacebookShare on Twitter

Facebook has announced plans to scour lists of breached credentials to identify its own users.

In a blogpost, Facebook security engineer Chris Long said that as it is common for attackers to publicly post the email addresses and passwords they steal on public ‘paste’ sites. Therefore, it has built a system dedicated to further securing people’s Facebook accounts by actively looking for these public postings, analysing them and then notifying people when it discovers that their credentials have shown up elsewhere on the internet.

He said: “To do this, we monitor a selection of different ‘paste’ sites for stolen credentials and watch for reports of large scale data breaches. We collect the stolen credentials that have been publicly posted and check them to see if the stolen email and password combination matches the same email and password being used on Facebook.

“This is a completely automated process that doesn’t require us to know or store your actual Facebook password in an unhashed form. In other words, no one here has your plain text password. To check for matches, we take the email address and password and run them through the same code that we use to check your password at login time. If we find a match, we’ll notify you the next time you log in and guide you through a process to change your password.”

He explained that the ‘pasted’ credentials are passed into a program that parses it into a standardised format and after the data has been downloaded and parsed, an automated system checks each one of them against the Facebook internal databases to see if any of the email addresses and hashed passwords match valid login information on Facebook.

“ We hash each password using our internal password hashing algorithm and the unique salt for that person. Since Facebook stores passwords securely as hashes, we can’t simply compare a password directly to the database. We need to hash it first and compare the hashes,” he said.

He went on to explain that if the email and hash combination doesn’t match, it does not take any action; a mismatch indicates that the stolen password is different than the password you use on Facebook; but if the email address and hash combination does match, it will notify the user the next time that they use Facebook and guide you through a process to change their password.

Security researcher and founder of haveibeenpwned.com Troy Hunt told IT Security Guru that he thought the concept was great, very proactive and said that it goes a long way to address the recent spate of account “hacks” that seem to boil down to nothing more than password reuse.

He said: “Facebook are big enough and have enough resources to well and  truly go this on their own. That they own all their own data already means th
at so long as they can get their hands on the breaches (and that’s not hard), they’ve got all the moving parts they need already.”

Asked on how fast a system like this could operate at, bearing in mind Facebook’s more than one billion users, Hunt said that he did not see a problem with speed as firstly, a bunch of the public dumps have some form of cryptographic storage, so unless they’re going down the password cracking path, these will be useless for their purposes.

He said: “Adobe, for example, didn’t have clear text passwords. Pastebin is a different story as there’s a lot of clear text there, but it’s also smaller dumps rarely exceeding 20k so you’d just take those, match a subset to existing Facebook account then effective ‘log in’ with them and see if they work. Yes, you’re doing a bunch of hashing which is resource intensive, but it’s relatively frequent batches of smaller data sets and they’ve got serious resources at their disposal to make it work.”

Tags: BreachFacebookProtection SystemUsers
ShareTweet
Previous Post

Microsoft acknowledges exploits of zero-day flaw

Next Post

Domestic Workers Alliance hit by email breach

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol