Live data from Hacker News

eBay customers’ personal data was compromised in March

ebayinc.com

1–10 of 146 posts

Re: eBay customers’ personal data was compromised in March

#4
>Cyberattackers compromised a small number of employee log-in credentials

This bothers me. No one cares how many employee logins were stolen. It only takes one to cause a huge amount of damage. Is anyone reading this thinking "oh, it's okay, they didn't take too many employee logins"?

Re: eBay customers’ personal data was compromised in March

#6

>Cyberattackers compromised a small number of employee log-in credentials This bothers me. No one cares how many employee logins were stolen. It only takes one to cause a huge amount of damage. Is anyone reading this thinking "oh, it's okay, they didn't take too many employee logins"?

> No one cares how many employee logins were stolen.

Well that's not entirely true. First off, it indicates that the breach was relatively contained. Or at least EBay want's you to think that.

The smaller the number the less chance there is that the credentials were to more privileged employees. Not every employee is created the same. Not every employee has access to account data and not every employee could send customers corporate communications.

Now yes, the who they got is important over the how many, but the how many can be stated without giving too much away.

Re: eBay customers’ personal data was compromised in March

#9
"The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. However, the database did not contain financial information or other confidential personal information."

…So, just my entire identity then? eBay really seem to be down-playing the severity of this.

Re: eBay customers’ personal data was compromised in March

#10

FWIW, "ebayinc.com" totally screams "phishing attempt" to me.

It is a legit ebay domain, but without https, verifying it is tougher.

This announcement actually leaked when a "placeholder" was put up on the paypal-community.com forum:

https://news.ycombinator.com/item?id=7777182

And I did some simple tests to make sure that domain was really ebay/paypal:

https://news.ycombinator.com/item?id=7777419

Post reply on HN