# Facebook knows my passwords to other websites? WTF?!

**URL:** <https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146>\
**Category:** The BBQ Pit\
**Created:** [November 30, 2013, 6:23pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146 "2013-11-30T18:23:29Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Grrr](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/grrr/32/146_2.png) [@Grrr](https://boards.straightdope.com/u/Grrr)\
**Post date:** [November 30, 2013, 6:23pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/1 "2013-11-30T18:23:29Z")

</div>

So I just logged on to my FB account and the damn thing is telling me I need to change my password because apparently, it doesn’t like the fact that I use the same password for FB as I do another website.

You know, I don’t mind if FB is selling my profile to advertisers, really, I couldn’t care less. But how in the fuck do these guys know what passwords I’m using for other websites? (I’m guessing it’s from websites that require you to use your FB account to make posts, but still, they shouldn’t be sharing my password with each other.)

That’s fucking bullshit!

---

<div class="post-metadata">

**Author:** ![Yorikke](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/yorikke/32/4335_2.png) [@Yorikke](https://boards.straightdope.com/u/Yorikke)\
**Post date:** [November 30, 2013, 6:46pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/2 "2013-11-30T18:46:09Z")

</div>

You say Facebook “doesn’t like” the fact. What message, exactly, does Facebook give you? does it somehow bar you from using the password, or does it simply offer a tip? And are you sure it’s not just saying that you can’t use a password that was previously used for **Facebook**?

---

<div class="post-metadata">

**Author:** ![PlainJain](https://avatars.discourse-cdn.com/v4/letter/p/5daacb/32.png) [@PlainJain](https://boards.straightdope.com/u/PlainJain)\
**Post date:** [November 30, 2013, 6:53pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/3 "2013-11-30T18:53:10Z")

</div>

> [@Shakes](#):
>
> So I just logged on to my FB account and the damn thing is telling me I need to change my password …

Screen capture?

---

<div class="post-metadata">

**Author:** ![Canadjun](https://avatars.discourse-cdn.com/v4/letter/c/76d3ee/32.png) [@Canadjun](https://boards.straightdope.com/u/Canadjun)\
**Post date:** [November 30, 2013, 7:00pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/4 "2013-11-30T19:00:37Z")

</div>

No idea exactly what happened behind the scenes, but one possibility I can think of. I have heard that account information including encrypted passwords had been stolen from at least one large organization (Adobe? not sure). Even if passwords are encrypted if you know that the same encryption method was used on two different systems you can determine whether the clear-text password is the same for both (note I didn’t say you can determine what the password **is** , just that whatever it is it is the same on both).

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [November 30, 2013, 7:02pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/5 "2013-11-30T19:02:26Z")

</div>

Are you an Adobe customer, or have you ever had an Adobe account? A shitload of Adobe passwords were breached, and FB has been warning FB users who used the same password on both sites.

> **[Facebook Warns Users After Adobe Breach – Krebs on Security](https://krebsonsecurity.com/2013/11/facebook-warns-users-after-adobe-breach/)**
>
> Facebook is mining data leaked from the recent breach at Adobe in an effort to help its users better secure their accounts. Facebook users who used the same email and password combinations at both Facebook and Adobe's site are being…

---

<div class="post-metadata">

**Author:** ![Skywatcher](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skywatcher/32/254_2.png) [@Skywatcher](https://boards.straightdope.com/u/Skywatcher)\
**Post date:** [November 30, 2013, 7:10pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/6 "2013-11-30T19:10:59Z")

</div>

With the prevalence of social media, just using the same password on Facebook and some other site is inviting trouble. Especially if the other site is associated with the email address used for Facebook.

There are those who make a hobby of trying to crack passwords used in social media then see where else those passwords are good.

---

<div class="post-metadata">

**Author:** ![ticker](https://avatars.discourse-cdn.com/v4/letter/t/d07c76/32.png) [@ticker](https://boards.straightdope.com/u/ticker)\
**Post date:** [November 30, 2013, 9:48pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/7 "2013-11-30T21:48:04Z")

</div>

> [@Canadjun](#):
>
> Even if passwords are encrypted if you know that the same encryption method was used on two different systems you can determine whether the clear-text password is the same for both (note I didn’t say you can determine what the password **is** , just that whatever it is it is the same on both).

It shouldn’t be if the site is using a secure method. It is trivially simple to ensure that the same password is encrypted to a different value on different sites, even when they use the same encryption scheme, by combining the password with a random sequence of bits and storing those bits along with the encrypted password. It is called “salting”.

---

<div class="post-metadata">

**Author:** ![Happyasaclam](https://avatars.discourse-cdn.com/v4/letter/h/7c8e57/32.png) [@Happyasaclam](https://boards.straightdope.com/u/Happyasaclam)\
**Post date:** [November 30, 2013, 10:33pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/8 "2013-11-30T22:33:57Z")

</div>

One more reason to piss on Facebook.  
Facebook is like the creepy uncle who is the life of the party, but once your alone with uncle Facebook he’s a real shithead!

Just today I drew a total tryptophan turkey induced blank trying to remember all my passwords to pay bills, collect rewards, gear up for cyber shopping, withdraw cash.

There just has to be an easier way to password haven!

---

<div class="post-metadata">

**Author:** ![Shalmanese](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Shalmanese](https://boards.straightdope.com/u/Shalmanese)\
**Post date:** [November 30, 2013, 11:01pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/9 "2013-11-30T23:01:00Z")

</div>

> [@Shakes](#):
>
> So I just logged on to my FB account and the damn thing is telling me I need to change my password because apparently, it doesn’t like the fact that I use the same password for FB as I do another website.
> 
> You know, I don’t mind if FB is selling my profile to advertisers, really, I couldn’t care less. But how in the fuck do these guys know what passwords I’m using for other websites? (I’m guessing it’s from websites that require you to use your FB account to make posts, but still, they shouldn’t be sharing my password with each other.)
> 
> That’s fucking bullshit!

It’s because the other site you were using was dumb enough to have their passwords breached. Both Facebook and Google have done this on a couple of occasions when such an event occurs.

If you don’t want that warning to come up again, use a unique password for your FB and Google accounts.

---

<div class="post-metadata">

**Author:** ![Merneith](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@Merneith](https://boards.straightdope.com/u/Merneith)\
**Post date:** [December 1, 2013, 1:22am UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/10 "2013-12-01T01:22:17Z")

</div>

> [@Happyasaclam](#):
>
> There just has to be an easier way to password haven!

There is - use a password safe to generate and save the passwords and then set a master password so that all you need to do to log in is type that one password. Try LastPass, KeePass or Roboform.

---

<div class="post-metadata">

**Author:** ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)\
**Post date:** [December 1, 2013, 1:36am UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/11 "2013-12-01T01:36:39Z")

</div>

Yeah, this is almost certainly Facebook doing something positive.

As others have pointed out, probably another website (likely Adobe) was breached, and your email/password on that site became public. And since your email/password on Facebook is the same, anybody could log into your Facebook account with that public info.

This is in fact Facebook going a step farther than most websites in protecting your privacy.

---

<div class="post-metadata">

**Author:** ![mhendo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mhendo/32/3159_2.png) [@mhendo](https://boards.straightdope.com/u/mhendo)\
**Post date:** [December 1, 2013, 2:49am UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/12 "2013-12-01T02:49:23Z")

</div>

> [@Merneith](#):
>
> There is - use a password safe to generate and save the passwords and then set a master password so that all you need to do to log in is type that one password. Try LastPass, KeePass or Roboform.

I use LastPass, and it really is excellent.

All my important sites now have nice long passwords consisting of random letters, numbers, and special characters. My main LastPass password is one that’s very easy for me to remember, but is also long enough and complex enough to make dictionary and brute force attacks almost impossible.

---

<div class="post-metadata">

**Author:** ![Grrr](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/grrr/32/146_2.png) [@Grrr](https://boards.straightdope.com/u/Grrr)\
**Post date:** [December 1, 2013, 2:50am UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/13 "2013-12-01T02:50:10Z")

</div>

I don’t have an Adobe account though.

I’ve got one password I use for all my fun media type stuff. I also use a separate E-mail for my fun type stuff. I use various other passwords for work or anything to do with money or my personal ID.

I’m just pissed because FB has effectively fucked up my system. Now, I have to remember two passwords for my fun media type stuff.

I post on The Huffpo from time to time. Huffpo makes me use my FB account to make posts. I’m thinking Huffpo is the guilty culprit.

---

<div class="post-metadata">

**Author:** ![Ferret\_Herder](https://avatars.discourse-cdn.com/v4/letter/f/e47774/32.png) [@Ferret\_Herder](https://boards.straightdope.com/u/Ferret_Herder)\
**Post date:** [December 1, 2013, 3:04am UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/14 "2013-12-01T03:04:28Z")

</div>

Dude, I literally have a few dozen passwords and usernames for work and leisure stuff. 😛

---

<div class="post-metadata">

**Author:** ![Shalmanese](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Shalmanese](https://boards.straightdope.com/u/Shalmanese)\
**Post date:** [December 1, 2013, 3:31am UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/15 "2013-12-01T03:31:28Z")

</div>

> [@Shakes](#):
>
> I don’t have an Adobe account though.
> 
> I’ve got one password I use for all my fun media type stuff. I also use a separate E-mail for my fun type stuff. I use various other passwords for work or anything to do with money or my personal ID.
> 
> I’m just pissed because FB has effectively fucked up my system. Now, I have to remember two passwords for my fun media type stuff.
> 
> I post on The Huffpo from time to time. Huffpo makes me use my FB account to make posts. I’m thinking Huffpo is the guilty culprit.

Well, no. You should change your passwords for all your fun media type stuff (to the same new password if you like). You have PROOF that your password got leaked. Literally anyone can now log into any of your fun media type stuff at any time by just downloading the right torrent.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [December 1, 2013, 3:36am UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/16 "2013-12-01T03:36:12Z")

</div>

> [@Shakes](#):
>
> You know, I don’t mind if FB is selling my profile to advertisers, really, I couldn’t care less. But how in the fuck do these guys know what passwords I’m using for other websites?

Maybe they don’t, but someone wants you to think they do. Are you 100% sure the message was from Facebook, and not from some rogue phishing program either on the site or in your computer? After getting the message, you didn’t just click on the “change your password here” link, did you?

---

<div class="post-metadata">

**Author:** ![Left\_Hand\_of\_Dorkness](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/left_hand_of_dorkness/32/7156_2.png) [@Left\_Hand\_of\_Dorkness](https://boards.straightdope.com/u/Left_Hand_of_Dorkness)\
**Post date:** [December 1, 2013, 9:27am UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/17 "2013-12-01T09:27:40Z")

</div>

> [@Musicat](#):
>
> Maybe they don’t, but someone wants you to think they do. Are you 100% sure the message was from Facebook, and not from some rogue phishing program either on the site or in your computer? After getting the message, you didn’t just click on the “change your password here” link, did you?

See post 5.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [December 1, 2013, 9:46am UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/18 "2013-12-01T09:46:09Z")

</div>

> [@Shalmanese](#):
>
> Well, no. You should change your passwords for all your fun media type stuff (to the same new password if you like). You have PROOF that your password got leaked. Literally anyone can now log into any of your fun media type stuff at any time by just downloading the right torrent.

You seem to be under the impression that people care when their passwords are breached on “fun media stuff.” The whole reason behind using the same password is that you _don’t_ care.

Granted, I personally don’t put Facebook in that category since it knows my real name and real life friends, but to each their own. I do, however, have 100s of forum accounts with the same username and password (different from this one). If my password got breached, there’s no way I would bother changing them.

I don’t think that the site should be telling me how secure I want to be. If I want to create a throwaway account where I don’t care if someone else finds it, let me. Sure, maybe let me know that something is insecure, but then let me choose whether I’m okay with that insecurity.

---

<div class="post-metadata">

**Author:** ![Grrr](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/grrr/32/146_2.png) [@Grrr](https://boards.straightdope.com/u/Grrr)\
**Post date:** [December 1, 2013, 11:06am UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/19 "2013-12-01T11:06:25Z")

</div>

> [@BigT](#):
>
> You seem to be under the impression that people care when their passwords are breached on “fun media stuff.” The whole reason behind using the same password is that you _don’t_ care.
> 
> Granted, I personally don’t put Facebook in that category since it knows my real name and real life friends, but to each their own. I do, however, have 100s of forum accounts with the same username and password (different from this one). If my password got breached, there’s no way I would bother changing them.
> 
> I don’t think that the site should be telling me how secure I want to be. If I want to create a throwaway account where I don’t care if someone else finds it, let me. Sure, maybe let me know that something is insecure, but then let me choose whether I’m okay with that insecurity.

Well said. FTR, I don’t have any friends on FB, that’s not what I use it for. I use it as a utility to post on other websites and to look at other FB accounts. I do so begrudgingly. I don’t even like FB. Even before this password nonsense.

---

<div class="post-metadata">

**Author:** ![septimus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/septimus/32/410_2.png) [@septimus](https://boards.straightdope.com/u/septimus)\
**Post date:** [December 1, 2013, 12:30pm UTC](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146/20 "2013-12-01T12:30:07Z")

</div>

> [@BigT](#):
>
> You seem to be under the impression that people care when their passwords are breached on “fun media stuff.” The whole reason behind using the same password is that you _don’t_ care.

++.  
I use “good” passwords on accounts that have financial implications, but the same trivial easy-to-remember password for message boards, etc. If someone wants to hack in to septimus@SDMB and make me look like a fool, have at it! (That might not be awfully different from the status quo.)

Most irritating was when I tried to create an account at stackoverflow. It rejected my passwords one-by-one, each time adding a single new requirement. Eventually, when I’d learned my password would need a lower-case letter AND an upper-case letter AND a digit AND a special symbol AND have a minimum length, I gave up, now always posting in “guest” mode.

[Next page](https://boards.straightdope.com/t/facebook-knows-my-passwords-to-other-websites-wtf/675146.md?page=2)
