Live data from Hacker News

eBay customers’ personal data was compromised in March

ebayinc.com

11–20 of 146 posts

Re: eBay customers’ personal data was compromised in March

#11

database containing encrypted passwords Does anyone know whether they used per-user salt?

Salt is used with a hash function, not encryption, AFAIK.

Though whether they really are using encryption (of plaintext passwords?), or whether they actually meant hashing is another question.

Re: eBay customers’ personal data was compromised in March

#12

FWIW, "ebayinc.com" totally screams "phishing attempt" to me.

You have to remember that eBay is an ancient tech company run by the old MBA types that didn't really understand what value to place on engineering.

All their internal systems are maintained by vendors, VARs, and contractors.

So weird stuff like the ebayinc.com domain is to be expected. As is this hack. Also it'd be interesting to know how it was detected, and how the extent of access was determined. But if my prediction is correct, we will never see a truly open blog post about it. First, because it's not clear to me that eBay "infosec" is up to the task. Second, because eBay believes more in compartmentalization, secrecy, misdirection etc. than 'openness'.

Re: eBay customers’ personal data was compromised in March

#14
> The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted.

Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seriously the owner of PayPal should not be telling me this "we have no evidence of" bullshit because there's no alternative to PayPal that online stores actually use and changing your checking account number and routing number is very very painful. You have to get new checks, you lose checking history. Fuck.

Re: eBay customers’ personal data was compromised in March

#15
post #9

"The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. However, the database did not contain financial information or other confidential personal information." …So, just my entire identity then? eBay really seem to be down-playing the severity of this.

To put it more strongly, one phish away from ruin.

Re: eBay customers’ personal data was compromised in March

#17

> The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted. Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seri…

I know it's not always practical for everyone, so I can't give it as general advice, but this kind of situation is exactly why I isolate my "real" checking account. My primary account (the one to which my paychecks are deposited) doesn't have a debit card, and I never use the account number. I have a different account that I use for online services like PayPal, and for recurring charges online that require a credit/debit card, which I transfer money into on demand.

It's extra work for me, but it's also less risk. Unless somebody gains access to my online banking account, they're not going to be able to access my primary funds account.

Re: eBay customers’ personal data was compromised in March

#18
The spin is atrocious. The big story is not the headline, that users must change passwords.

The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down.

  The database, which was compromised between late February and
  early March, included eBay customers’ name, encrypted password,
  email address, physical address, phone number and date of birth.
Don't patronize me with empty platitudes like "changing passwords is a best practice".

Tell me to brace for an inevitable wave of phishing and identity attacks.

Tell me that bad guys will try to steal my other online accounts with this information.

Tell me to trust no one because bad guys now look legit with my home address, phone number and DOB.

Pro tip: put the real story in the headline. That's also a "best practice".

Re: eBay customers’ personal data was compromised in March

#19
Considering the situation, its either poor timing or related but I can't change my PayPal password. Get a blank page.

Not confident.

To be honest it takes the piss as they are spamming UK TV with adverts for how secure PayPal is at the moment.

Really wish I never signed up but eBay has a monopoly on the payment types now.

Post reply on HN