Live data from Hacker News

eBay customers’ personal data was compromised in March

ebayinc.com

61–70 of 146 posts

Re: eBay customers’ personal data was compromised in March

#62

Since PayPal == eBay, I just went to change my PayPal password as well. PayPal went full retard. The security confirmation question? Please supply your full credit card number ending in ####. Um, that's the information I'm trying to protect in the first place. edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend

[deleted]

Re: eBay customers’ personal data was compromised in March

#63
post #17

> The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted. Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seri…

I know it's not always practical for everyone, so I can't give it as general advice, but this kind of situation is exactly why I isolate my "real" checking account. My primary account (the one to which my paychecks are deposited) doesn't have a debit card, and I never use the account number. I have a different account that I use for online services like PayPal, and for recurring charges online that require a credit/d…

For those of us who don't have this setup, suppose this kind of breach does occur and money is taken from a checking account. Is this covered by the bank somehow? Can that money be returned?

Re: eBay customers’ personal data was compromised in March

#64
post #43

And neither eBay nor PayPal allow me to paste a secure password from KeePassX. sigh Edit: I can now paste on eBay (not sure what went wrong the first time) but PayPal is still actively preventing pasting a new password.

I’ve not used Keepassx, but I have no trouble pasting from Lastpass…

You can paste in PayPal passwords on the password reset tool this week, but it's a new tool from last week when I last reset it. Wonder what made them update it?

Re: eBay customers’ personal data was compromised in March

#65

Being that important auxiliary details were compromised (name, phone, etc...). Beginning to think that encrypting that information should be more standard. Obviously this leads to trouble if searching by that information is required....

It's call PII, Personally Identifiable Information. In many industries, there are indeed strict requirements for protecting it... just not at Ebay, who, for it's age, probably predates any such standard practices.

Re: eBay customers’ personal data was compromised in March

#66

Since PayPal == eBay, I just went to change my PayPal password as well. PayPal went full retard. The security confirmation question? Please supply your full credit card number ending in ####. Um, that's the information I'm trying to protect in the first place. edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend

When I tried to change my password to a twenty character pass phrase, I wasn't allowed because it was "too weak". Adding a single digit made it "strong." I am not particularly comforted by this.

Re: eBay customers’ personal data was compromised in March

#67
post #31

Earlier quoted context omitted.

Don't forget that it was nearly three months ago. Why weren't users informed immediately? Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great. Which phy…

Isn't there a law in California that requires data breach disclosure? Is there a time frame in that law? Three months is way to long and I am sure criminals will use what they get as soon as possible.

Yes, "the disclosure shall be made in the most expedient time possible and without unreasonable delay".

http://leginfo.legislature.ca.gov/faces/codes_displaySection...

If the breach affects more than 500 California residents, an online report must be filed with the Attorney General.

You can search breach reports, and I could not find any from ebay.

http://oag.ca.gov/ecrime/databreach/list?field_sb24_org_name...

You can also file a complaint against businesses that fail to disclose breaches here:

http://oag.ca.gov/contact/consumer-complaint-against-busines...

Re: eBay customers’ personal data was compromised in March

#68
post #17

Earlier quoted context omitted.

I know it's not always practical for everyone, so I can't give it as general advice, but this kind of situation is exactly why I isolate my "real" checking account. My primary account (the one to which my paychecks are deposited) doesn't have a debit card, and I never use the account number. I have a different account that I use for online services like PayPal, and for recurring charges online that require a credit/d…

For those of us who don't have this setup, suppose this kind of breach does occur and money is taken from a checking account. Is this covered by the bank somehow? Can that money be returned?

Depends on the bank, but it's definitely not protected by law the way a credit card is, at least in the US. That goes for debit cards too by the way.

Re: eBay customers’ personal data was compromised in March

#69
post #31

Earlier quoted context omitted.

Don't forget that it was nearly three months ago. Why weren't users informed immediately? Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great. Which phy…

Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?

this always gets me, and every time i ask i can't seem to find a direct answer why so many sites have this 20 character limit. bank of america does as well, with the additional restriction that you can't use the following characters: $ & ^ ! []. bluecross/blueshield allows up to 30 characters, but only numbers and letters.

if passwords are being hashed, which i guess i would have to believe they are, at least in the BOA case, what's the point of restricting character counts (especially to 20), or choosing random characters to exclude?

Post reply on HN