Live data from Hacker News

eBay customers’ personal data was compromised in March

ebayinc.com

81–90 of 146 posts

Re: eBay customers’ personal data was compromised in March

#81

Earlier quoted context omitted.

For those of us who don't have this setup, suppose this kind of breach does occur and money is taken from a checking account. Is this covered by the bank somehow? Can that money be returned?

Depends on the bank, but it's definitely not protected by law the way a credit card is, at least in the US. That goes for debit cards too by the way.

I've had my debit card used at least half a dozen time by thieves (they must skim the magnetic information off it at gas stations or something), including a thousand dollar charge at an ATM while I was abroad.

In every case Chase refunded me in full within a few days. This isn't something every bank does?

Re: eBay customers’ personal data was compromised in March

#82
post #31

Earlier quoted context omitted.

Don't forget that it was nearly three months ago. Why weren't users informed immediately? Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great. Which phy…

Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?

Ebay claims that 20 characters is the max, but it's a lie - mine is 29.

Likewise, Newegg claims that you have to have special characters, but my password has none.

I'd suggest trying the password you want and seeing if it gets rejected. In a lot of cases, some programmer may have fixed the crazy password scheme and forgotten to update the page text.

Re: eBay customers’ personal data was compromised in March

#83
post #19

Considering the situation, its either poor timing or related but I can't change my PayPal password. Get a blank page. Not confident. To be honest it takes the piss as they are spamming UK TV with adverts for how secure PayPal is at the moment. Really wish I never signed up but eBay has a monopoly on the payment types now.

PayPal was not affected. I just tested changed my password and it worked fine. Info for eBay users are here. https://info.ebayinc.com

Re: eBay customers’ personal data was compromised in March

#84
post #42

Earlier quoted context omitted.

It can still be very inconvenient.

It really shouldn't be. I had a card compromised in the Target breach and they sent me a new one without my intervention. I've had fraudulent charges made before, and it's been trivial to get it fixed. I've never had a checking account compromise, but I'm pretty sure it would be a massive pain in the ass by comparison.

Mentioned above, but relevant here too. I've had my debit card compromised several times, and it was still trivial - one phone call and was refunded in a few days.

Re: eBay customers’ personal data was compromised in March

#85

Since PayPal == eBay, I just went to change my PayPal password as well. PayPal went full retard. The security confirmation question? Please supply your full credit card number ending in ####. Um, that's the information I'm trying to protect in the first place. edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend

Thats on;y the case if you do the password reset when you are already logged into your account. Its another layer to prevent people changing your password on a shared computer if you stepped away for example. Doesn't happen if you are not logged in

Re: eBay customers’ personal data was compromised in March

#86

Earlier quoted context omitted.

Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?

this always gets me, and every time i ask i can't seem to find a direct answer why so many sites have this 20 character limit. bank of america does as well, with the additional restriction that you can't use the following characters: $ & ^ ! []. bluecross/blueshield allows up to 30 characters, but only numbers and letters. if passwords are being hashed, which i guess i would have to believe they are, at least in the…

Legacy systems. There's almost certainly some ancient backend system that deals with passwords, and can't handle long passwords or certain special characters. I would not assume that bank passwords are being hashed properly.

Re: eBay customers’ personal data was compromised in March

#87

Earlier quoted context omitted.

Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?

You think that's bad? Charles Schwab Bank only allows you 8 characters for the password. No special characters either.

AMEX also has surprising restrictive passwords.

Is the security surrounding password resets so bad that it's more secure to force easier to remember passwords?

Re: eBay customers’ personal data was compromised in March

#88
post #29
post #20

Unfortunately, attempting to reset one's password results in: > Sorry. We're currently experiencing technical difficulties and are unable to complete the process at this time. Swamped already?

Why are they not automatically resetting passwords?

Ebay is asking for passwords to be reset. PayPal is not affected.

Re: eBay customers’ personal data was compromised in March

#89

Earlier quoted context omitted.

Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?

You think that's bad? Charles Schwab Bank only allows you 8 characters for the password. No special characters either.

The 2 banks I have to deal with online both require 5 characters. Fwiw, they at least lock your account after 3 wrong entries.

Re: eBay customers’ personal data was compromised in March

#90
post #57
post #49

Earlier quoted context omitted.

I can do that just fine, must be your browser interfering.

You're right. It seems to be working now. When I first tried, I could paste into any field but the change password fields. However on PayPal, when pasting I received a little tooltip-style popup saying something along the lines of "Please do not copy and paste passwords.", followed by their password criteria. Pasting into other fields (including the login page password field) worked perfectly fine.

Ugh, companies misunderstanding password security is so infuriating. Yes, let me use my memorable 8 character password instead of my fully randomized 30 character password protected by a strong password I use only for that, and a keyfile I have stored on my computer. I feel so much more secure now that I'm using weaker passwords.
Post reply on HN