Instagram is notifying users affected by the accidental exposure of plaintext passwords via its Download Your Data tool, which was ironically intended to preserve their privacy.
Download Your Data, a new feature introduced earlier this year, gives account holders a way to view all the information Instagram has: photos and videos shared, comments, and profile information, for example. The tool was developed amid privacy concerns following Facebook's Cambridge Analytica scandal and the rollout of General Data Privacy Regulation in Europe.
Unfortunately, Download Your Data may have exposed users' passwords, The Information reports. For a short period of time, users who logged in to the tool could see their password in the page's URL. The password was only exposed to the user but was stored on Facebook's servers – a problem for anyone on a shared machine or compromised network, Fortune notes.
Instagram has fixed the bug and has deleted saved passwords. Read more details here.
Black Hat Europe returns to London Dec 3-6 2018 with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.