Live data from Hacker News

eBay customers’ personal data was compromised in March

ebayinc.com

21–30 of 146 posts

Re: eBay customers’ personal data was compromised in March

#21

database containing encrypted passwords Does anyone know whether they used per-user salt?

Salt is used with a hash function, not encryption, AFAIK. Though whether they really are using encryption (of plaintext passwords?), or whether they actually meant hashing is another question.

Exactly. It seems like business oriented press releases often say passwords are "encrypted" when they really mean hashed (if you're lucky). So we can't really tell from this.

Re: eBay customers’ personal data was compromised in March

#22
post #6

>Cyberattackers compromised a small number of employee log-in credentials This bothers me. No one cares how many employee logins were stolen. It only takes one to cause a huge amount of damage. Is anyone reading this thinking "oh, it's okay, they didn't take too many employee logins"?

> No one cares how many employee logins were stolen. Well that's not entirely true. First off, it indicates that the breach was relatively contained. Or at least EBay want's you to think that. The smaller the number the less chance there is that the credentials were to more privileged employees. Not every employee is created the same. Not every employee has access to account data and not every employee could send cus…

Even still, if the number of Unix admins at eBay was only 0.001% of the total number of employees, the fact that 100% of their Unix admins had their accounts compromised means that, yes, a small number of employees had their accounts breached but it would still result in 100% of their user accounts being breached.

Re: eBay customers’ personal data was compromised in March

#24
This is headline top-story news on the BBC right now therefore it must be 'big'. Yet no evidence of anyone making unauthorised access.

We have had a resurgence of 'Snowden' stories in the last few days, so here is a hypothetical scenario: what does a company do if the hackers turn out to be NSA/GCHQ? It is unlikely that they would drop an email to explain that they had just stolen the whole customer database because of some 'al-qaeda' based reasoning, so you would not know it was them. If you suspected it was them then people would wonder if you had taken your meds. If you got the FBI involved then they would tell you it was some script kiddies rather than the Peeping-Tom-Brigade.

Or, if you did know it was the NSA, then you might think that information was safe in their hands and not feel the need to tell the customers.

I look forward to when we get stories where the NSA are explicitly blamed for a data breach instead of some random Chinese hacker, and that emails are sent out saying 'we have been hacked by the NSA again, can you change your passwords please?'. If the NSA crawled out of the darkness to deny the breach then nobody would believe them.

Re: eBay customers’ personal data was compromised in March

#26

> The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted. Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seri…

Okay, so let's imagine for a moment that the "secure, encrypted" database of card numbers has also been compromised. The attacker would have the plaintext name and address, and an encrypted 16 digit number, with an entropy of at most 53 bits - maybe 66 bits if the expiry date is included. That's before you take card number check digits and geographically-likely prefix codes into account, which will reduce the entropy. (Edit: yes, they wouldn't store the CVV). And don't get me started on showing the user the last four digits of the card number. It wouldn't take much effort in this day and age for the attacker to try all possible card numbers, and then they have name, address, and card number. Game over, man.

Wouldn't it be possible for them instead to store a token generated from the card number and Ebay/Paypal's incoming bank account number, which can only be used for paying into that particular account?

Re: eBay customers’ personal data was compromised in March

#27
Took a trip back to 2002 and visited the Account Settings / Personal Information screen to change my password. No alerts or redirects on login to change credentials. (But evidently an exciting "deal frenzy" is important enough to highlight in all caps and red text in the nav bar). Ok, so the PayPal DB wasn't affected, but does that matter? PayPal account is fully linked up there.

Re: eBay customers’ personal data was compromised in March

#28

> The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted. Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seri…

Okay, so let's imagine for a moment that the "secure, encrypted" database of card numbers has also been compromised. The attacker would have the plaintext name and address, and an encrypted 16 digit number, with an entropy of at most 53 bits - maybe 66 bits if the expiry date is included. That's before you take card number check digits and geographically-likely prefix codes into account, which will reduce the entropy…

But what does it matter if they figure out your card number? You're not liable for fraudulent transactions. It's pretty easy to get a new card number. Your issuer takes a hit, but whatever, not my problem.

Checking account info is much, much worse. It's much harder to reverse fraudulent transactions there, and much harder to get a new number.

Re: eBay customers’ personal data was compromised in March

#29
post #20

Unfortunately, attempting to reset one's password results in: > Sorry. We're currently experiencing technical difficulties and are unable to complete the process at this time. Swamped already?

Why are they not automatically resetting passwords?

Re: eBay customers’ personal data was compromised in March

#30

> The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted. Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seri…

Okay, so let's imagine for a moment that the "secure, encrypted" database of card numbers has also been compromised. The attacker would have the plaintext name and address, and an encrypted 16 digit number, with an entropy of at most 53 bits - maybe 66 bits if the expiry date is included. That's before you take card number check digits and geographically-likely prefix codes into account, which will reduce the entropy…

[deleted]
Post reply on HN