Earlier quoted context omitted.
Why are they not automatically resetting passwords?
Ebay is asking for passwords to be reset. PayPal is not affected.
eBay customers’ personal data was compromised in March
91–100 of 146 posts
Re: eBay customers’ personal data was compromised in March
#92Earlier quoted context omitted.
It really shouldn't be. I had a card compromised in the Target breach and they sent me a new one without my intervention. I've had fraudulent charges made before, and it's been trivial to get it fixed. I've never had a checking account compromise, but I'm pretty sure it would be a massive pain in the ass by comparison.
Mentioned above, but relevant here too. I've had my debit card compromised several times, and it was still trivial - one phone call and was refunded in a few days.
A compromise of your routing and account number for your checking account is potentially much worse. It's harder to take advantage of, but it's also much harder to fix.
(I'm not sure if you were treating the debit card as analogous to credit cards or account numbers, so treat this as confirmation/correction/elaboration/whatever as appropriate.)
Re: eBay customers’ personal data was compromised in March
#93Earlier quoted context omitted.
Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?
Ebay claims that 20 characters is the max, but it's a lie - mine is 29. Likewise, Newegg claims that you have to have special characters, but my password has none. I'd suggest trying the password you want and seeing if it gets rejected. In a lot of cases, some programmer may have fixed the crazy password scheme and forgotten to update the page text.
Re: eBay customers’ personal data was compromised in March
#94Storage is cheap and you shouldn't be skimping on the most sensitive field in your dataset.
Re: eBay customers’ personal data was compromised in March
#95Re: eBay customers’ personal data was compromised in March
#96Earlier quoted context omitted.
Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?
Ebay claims that 20 characters is the max, but it's a lie - mine is 29. Likewise, Newegg claims that you have to have special characters, but my password has none. I'd suggest trying the password you want and seeing if it gets rejected. In a lot of cases, some programmer may have fixed the crazy password scheme and forgotten to update the page text.
Re: eBay customers’ personal data was compromised in March
#97Re: eBay customers’ personal data was compromised in March
#98Earlier quoted context omitted.
Ebay claims that 20 characters is the max, but it's a lie - mine is 29. Likewise, Newegg claims that you have to have special characters, but my password has none. I'd suggest trying the password you want and seeing if it gets rejected. In a lot of cases, some programmer may have fixed the crazy password scheme and forgotten to update the page text.
I just changed mine to a random 32, but I suspect ebay just silently threw away the last 12. Will test ...
Re: eBay customers’ personal data was compromised in March
#99Earlier quoted context omitted.
Don't forget that it was nearly three months ago. Why weren't users informed immediately? Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great. Which phy…
Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?
Re: eBay customers’ personal data was compromised in March
#100Earlier quoted context omitted.
It can still be very inconvenient.
It really shouldn't be. I had a card compromised in the Target breach and they sent me a new one without my intervention. I've had fraudulent charges made before, and it's been trivial to get it fixed. I've never had a checking account compromise, but I'm pretty sure it would be a massive pain in the ass by comparison.