Live data from Hacker News

eBay customers’ personal data was compromised in March

ebayinc.com

41–50 of 146 posts

Re: eBay customers’ personal data was compromised in March

#41
post #18

The spin is atrocious. The big story is not the headline, that users must change passwords. The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down. The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. Don't patronize me…

my thoughts exactly - this is a terribly spun statement by eBay. My personal data has now been leaked to unknown parties and they make light of it by droning on about "best practice" and passwords.

Re: eBay customers’ personal data was compromised in March

#42
post #28

Earlier quoted context omitted.

But what does it matter if they figure out your card number? You're not liable for fraudulent transactions. It's pretty easy to get a new card number. Your issuer takes a hit, but whatever, not my problem. Checking account info is much, much worse. It's much harder to reverse fraudulent transactions there, and much harder to get a new number.

It can still be very inconvenient.

It really shouldn't be. I had a card compromised in the Target breach and they sent me a new one without my intervention. I've had fraudulent charges made before, and it's been trivial to get it fixed.

I've never had a checking account compromise, but I'm pretty sure it would be a massive pain in the ass by comparison.

Re: eBay customers’ personal data was compromised in March

#44
post #39

Since PayPal == eBay, I just went to change my PayPal password as well. PayPal went full retard. The security confirmation question? Please supply your full credit card number ending in ####. Um, that's the information I'm trying to protect in the first place. edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend

Doesn't that make it the perfect question? For someone to answer the question correctly, they have to demonstrate that they don't even need to do so, because they already know the thing you wanted to protect?

Along that reasoning... I'm from your bank. Please give me your account # and PIN.

Re: eBay customers’ personal data was compromised in March

#46

Since PayPal == eBay, I just went to change my PayPal password as well. PayPal went full retard. The security confirmation question? Please supply your full credit card number ending in ####. Um, that's the information I'm trying to protect in the first place. edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend

Credit card numbers should be way down on your list of info to protect. They're easy to change and the consequences of a compromise are small (you're not liable for any fraudulent transactions as long as you're paying the least bit attention). Worry about your checking account number and other info, but not your card numbers.

Re: eBay customers’ personal data was compromised in March

#47

Since PayPal == eBay, I just went to change my PayPal password as well. PayPal went full retard. The security confirmation question? Please supply your full credit card number ending in ####. Um, that's the information I'm trying to protect in the first place. edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend

>> "PayPal went full retard."

I'm not usually big on political correctness but you could so easily replace that phrase with something that's not taking the piss out of people.

Re: eBay customers’ personal data was compromised in March

#48

This is headline top-story news on the BBC right now therefore it must be 'big'. Yet no evidence of anyone making unauthorised access. We have had a resurgence of 'Snowden' stories in the last few days, so here is a hypothetical scenario: what does a company do if the hackers turn out to be NSA/GCHQ? It is unlikely that they would drop an email to explain that they had just stolen the whole customer database because…

I wish the media could report these stories accurately. The BBC News ticker is currently saying:

"Ebay asking people to change passwords after a cyberattack compromised database containing encrypted user details"

Not True! The user details were unencrypted, bar the password.

Re: eBay customers’ personal data was compromised in March

#49
post #43

And neither eBay nor PayPal allow me to paste a secure password from KeePassX. sigh Edit: I can now paste on eBay (not sure what went wrong the first time) but PayPal is still actively preventing pasting a new password.

I can do that just fine, must be your browser interfering.

Re: eBay customers’ personal data was compromised in March

#50

Since PayPal == eBay, I just went to change my PayPal password as well. PayPal went full retard. The security confirmation question? Please supply your full credit card number ending in ####. Um, that's the information I'm trying to protect in the first place. edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend

>> "PayPal went full retard." I'm not usually big on political correctness but you could so easily replace that phrase with something that's not taking the piss out of people.

I suppose I could. I was going for the "Tropic Thunder" line. But really, political correctness? Has anyone ever called an actually mentally handicapped person "retarded" in the past thirty years?
Post reply on HN