If you own a Twitter account, you should change passwords, just to be safe. Twitter warns all 330 million of its users of an internal glitch found on its network. The company’s message appears as a forced pop-up advising users to set a new password to keep their account secure.

Jack Dorsey, chief executive of Twitter tweets, “We recently discovered a bug where account passwords were being written to an internal log before completing a masking/hashing process.”
“We’ve fixed, see no indication of breach or misuse, and believe it’s important to be open about this internal defect.”
However, as a precaution, he urges that everyone change their passwords anyway. This includes any other accounts which use the same password.

Parag Agrawal, Twitter’s chief technology officer provides a blog post with further details.
Twitter masks passwords through ‘hashing’ using a function known as bcrypt. This replaces passwords with a random set of numbers and letters, then stored in Twitter’s system. Doing so allows Twitter to validate credentials while protecting passwords. However, the bug writes these passwords to an internal log first before the hashing process ends. The password essentially emerges naked before it has put its clothes on.
Twitter regrets the mishap and lists down four steps for users to keep their accounts safe:
- Change your password on Twitter and on any other service where you may have used the same password.
- Use a strong password that you don’t reuse on other websites.
- Enable login verification. This is the single best action you can take to increase your account security.
- Use a password manager to make sure you’re using strong, unique passwords everywhere.
Users may change passwords from Twitter’s settings.
Details on the number of affected users or how long the bug has existed are not known.
(Source: Twitter)



