Google Apologises for Saving Some G Suite Passwords in Plain Text for Over a Decade

Google said it has notified G Suite administrators to change the impacted passwords.

Advertisement
By Indo-Asian News Service | Updated: 22 May 2019 10:36 IST
Google Apologises for Saving Some G Suite Passwords in Plain Text for Over a Decade

Google on Wednesday extended an apology to its G Suite customers after revealing that it stored passwords of some enterprise users in plaintext for years.

Storing passwords without cryptographic hashes expose them to hacking risk as they become readable.

The issue has been around since 2005 and Google, in a statement, said it is working with enterprise administrators to ensure that the users reset their passwords.

"We recently notified a subset of our enterprise G Suite customers that some passwords were stored in our encrypted internal systems unhashed.

Advertisement

"This is a G Suite issue that affects business users only -- no free consumer Google accounts were affected," said Suzanne Frey, Vice President, Engineering, Cloud Trust at Google, adding that the company neither lived up to its own standards nor those of its customers.

"We apologise to our users and will do better," she added.

Advertisement

If you have a Google account, Google's core sign-in system is designed not to know your password.

When you set your password, instead of remembering the exact characters of the password, the company scrambles it with a "hash function", so it becomes something like "72i32hedgqw23328", and that's what is stored with your username.

Advertisement

"Both are then also encrypted before being saved to disk. The next time you try to sign in, we again scramble your password the same way. If it matches the stored string then you must have typed the correct password, so your sign-in can proceed," explained Frey.

In its enterprise product G Suite, Google found that some passwords were stored unhashed in plaintext.

"To be clear, these passwords remained in our secure encrypted infrastructure. This issue has been fixed and we have seen no evidence of improper access to or misuse of the affected passwords," Google claimed.

Google said it has notified G Suite administrators to change the impacted passwords.

Twitter recently advised all its 330 million users to change passwords owing to a breach.

Facebook in March revealed it fixed a security issue wherein millions of its users' passwords were stored in plain text and "readable" format for years and according to reports, were searchable by thousands of its employees.

After admitting it "unintentionally" uploaded emails of nearly 1.5 million of new users, Facebook later revealed that millions of Instagram passwords were also stored on its servers in a readable format.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Google, G Suite
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 15s Pro Design, Camera Details Teased Ahead of Launch Today
  2. OTT Releases of the Week: Truth or Trouble, Motorheads, and More
  3. Tecno Pova Curve 5G India Launch Date Announced
  4. Sam Altman Reportedly Drops Clues About 'Secret' AI Device With Jony Ive
  5. SpaceX Successfully Launches 23 Starlink Satellites on Brand-New Falcon 9 Rocket
  1. WhatsApp Rolls Out Voice Chat Feature for All Group Chats With End-to-End Encryption
  2. SpaceX Successfully Launches 23 Starlink Satellites on Brand-New Falcon 9 Rocket
  3. Polaris Wasn’t Always the North Star: How Earth’s Wobble Shifts the Celestial Pole
  4. Scientists Warn of Inadequate Solar Storm Forecasting: What You Need to Know
  5. NASA’s Perseverance Explores Mars' Oldest Rocks in Krokodillen Region
  6. New Study Uses AI to Reveal Dry Origins of Mars’ Mysterious Slope Streaks
  7. Ancient 14,000-Year-Old Solar Storm Revealed as Strongest Ever Recorded in Earth’s History
  8. New Study Confirms TeV Halos Are Common in Middle-Aged Pulsars
  9. Capuchin Monkeys Abduct Baby Howler Monkeys on Panama’s Jicarón Island, New Study Reveals
  10. Sneaky Links: Dating After Dark Now Streaming on Netflix: What You Need to Know
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.