Live data from Hacker News

eBay customers’ personal data was compromised in March

ebayinc.com

31–40 of 146 posts

Re: eBay customers’ personal data was compromised in March

#31
post #18

The spin is atrocious. The big story is not the headline, that users must change passwords. The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down. The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. Don't patronize me…

Don't forget that it was nearly three months ago. Why weren't users informed immediately?

Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great.

Which physical address? My default delivery? My invoice address?

So a quick update from the BBC: "something it only became aware of a fortnight ago"

They only just realised, essentially. Although it's worrying that it took an eCommerce site so long to catch it. And that's still two weeks when eBay knew and nobody else did.

Re: eBay customers’ personal data was compromised in March

#32

> The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted. Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seri…

If ebay is spinning this, burying the lede, minimizing the real severity, eventually the truth will be known.

So I'm trying an arbitrage trade. Just sold short ebay at 51.62 and hedged by buying amzn at 305.44.

If this is more serious than the press release indicates, ebay should deteriorate relative to amzn.

Re: eBay customers’ personal data was compromised in March

#33
post #28

Earlier quoted context omitted.

Okay, so let's imagine for a moment that the "secure, encrypted" database of card numbers has also been compromised. The attacker would have the plaintext name and address, and an encrypted 16 digit number, with an entropy of at most 53 bits - maybe 66 bits if the expiry date is included. That's before you take card number check digits and geographically-likely prefix codes into account, which will reduce the entropy…

But what does it matter if they figure out your card number? You're not liable for fraudulent transactions. It's pretty easy to get a new card number. Your issuer takes a hit, but whatever, not my problem. Checking account info is much, much worse. It's much harder to reverse fraudulent transactions there, and much harder to get a new number.

It can still be very inconvenient.

Re: eBay customers’ personal data was compromised in March

#34

>Cyberattackers compromised a small number of employee log-in credentials This bothers me. No one cares how many employee logins were stolen. It only takes one to cause a huge amount of damage. Is anyone reading this thinking "oh, it's okay, they didn't take too many employee logins"?

The whole press release is hilariously downplayed. This is very much a "hair on fire" moment for them, but the way they wrote this is so very casual.

They focus on relatively unimportant aspects of what happened and leave the big stuff as an afterthought. It's like an airline captain announcing, "Due to mechanical problems, we will be late getting into New York. For those of you on connecting flights, we will re-book you on later flights at no charge, ensure that your luggage travels with you. I apologize for the inconvenience. Also, all the engines are on fire and we're probably all going to die."

It seems that they think their best way forward is if most of their users don't grasp the significance of what happened.

Re: eBay customers’ personal data was compromised in March

#36
Since PayPal == eBay, I just went to change my PayPal password as well.

PayPal went full retard. The security confirmation question?

Please supply your full credit card number ending in ####.

Um, that's the information I'm trying to protect in the first place.

edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend

Re: eBay customers’ personal data was compromised in March

#38
post #31
post #18

The spin is atrocious. The big story is not the headline, that users must change passwords. The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down. The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. Don't patronize me…

Don't forget that it was nearly three months ago. Why weren't users informed immediately? Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great. Which phy…

Isn't there a law in California that requires data breach disclosure? Is there a time frame in that law? Three months is way to long and I am sure criminals will use what they get as soon as possible.

Re: eBay customers’ personal data was compromised in March

#39

Since PayPal == eBay, I just went to change my PayPal password as well. PayPal went full retard. The security confirmation question? Please supply your full credit card number ending in ####. Um, that's the information I'm trying to protect in the first place. edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend

Doesn't that make it the perfect question? For someone to answer the question correctly, they have to demonstrate that they don't even need to do so, because they already know the thing you wanted to protect?

Re: eBay customers’ personal data was compromised in March

#40

> The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted. Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seri…

Not practical when you want to pull money out, but I only have paypal hooked up to my CC. This very reason is why I never hooked it up to my bank account. When I do get people who paypal me money, which is not often, I just use the money to load my sbux card or something.

Obviously this is harder to do if you are a merchant who takes large amounts of money through paypal. In those cases though the merchant should have already segmented the paypal hooked bank account from the primary business account. If you are a merchant and have not done this, now is a good time.

Post reply on HN