Live data from Hacker News

eBay customers’ personal data was compromised in March

ebayinc.com

91–100 of 146 posts

Re: eBay customers’ personal data was compromised in March

#91
post #29

Earlier quoted context omitted.

Why are they not automatically resetting passwords?

Ebay is asking for passwords to be reset. PayPal is not affected.

that doesn't answer my questions, why do the stolen passwords work, why aren't they just sending password reset emails?

Re: eBay customers’ personal data was compromised in March

#92
post #42

Earlier quoted context omitted.

It really shouldn't be. I had a card compromised in the Target breach and they sent me a new one without my intervention. I've had fraudulent charges made before, and it's been trivial to get it fixed. I've never had a checking account compromise, but I'm pretty sure it would be a massive pain in the ass by comparison.

Mentioned above, but relevant here too. I've had my debit card compromised several times, and it was still trivial - one phone call and was refunded in a few days.

Debit cards mostly give you the same protections as credit cards. They're worse in that the money comes out of your account immediately (but is supposed to be returned when you report fraud), and the rules are different and less favorable if your PIN is also compromised, but overall it's not too bad.

A compromise of your routing and account number for your checking account is potentially much worse. It's harder to take advantage of, but it's also much harder to fix.

(I'm not sure if you were treating the debit card as analogous to credit cards or account numbers, so treat this as confirmation/correction/elaboration/whatever as appropriate.)

Re: eBay customers’ personal data was compromised in March

#93
post #82

Earlier quoted context omitted.

Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?

Ebay claims that 20 characters is the max, but it's a lie - mine is 29. Likewise, Newegg claims that you have to have special characters, but my password has none. I'd suggest trying the password you want and seeing if it gets rejected. In a lot of cases, some programmer may have fixed the crazy password scheme and forgotten to update the page text.

Are you sure that your password is actually 29 characters? Try changing some of the last nine characters and see if it will still let you log in; they may just be dropping the last nine silently.

Re: eBay customers’ personal data was compromised in March

#96
post #82

Earlier quoted context omitted.

Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?

Ebay claims that 20 characters is the max, but it's a lie - mine is 29. Likewise, Newegg claims that you have to have special characters, but my password has none. I'd suggest trying the password you want and seeing if it gets rejected. In a lot of cases, some programmer may have fixed the crazy password scheme and forgotten to update the page text.

I just changed mine to a random 32, but I suspect ebay just silently threw away the last 12. Will test ...

Re: eBay customers’ personal data was compromised in March

#98
post #82

Earlier quoted context omitted.

Ebay claims that 20 characters is the max, but it's a lie - mine is 29. Likewise, Newegg claims that you have to have special characters, but my password has none. I'd suggest trying the password you want and seeing if it gets rejected. In a lot of cases, some programmer may have fixed the crazy password scheme and forgotten to update the page text.

I just changed mine to a random 32, but I suspect ebay just silently threw away the last 12. Will test ...

Nope, give them a tiny amount of credit: they're not arbitrarily restricting password length. It's just the instructions that are out-of-date (or just plain incorrect).

Re: eBay customers’ personal data was compromised in March

#99
post #31

Earlier quoted context omitted.

Don't forget that it was nearly three months ago. Why weren't users informed immediately? Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great. Which phy…

Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?

I discovered yesterday that Microsoft (yes, Microsoft!) limits their passwords to between 8 and 16 characters. I'm not sure ANYONE really knows how to implement security even half-properly; I really wish OpenID had taken off.

Re: eBay customers’ personal data was compromised in March

#100
post #42

Earlier quoted context omitted.

It can still be very inconvenient.

It really shouldn't be. I had a card compromised in the Target breach and they sent me a new one without my intervention. I've had fraudulent charges made before, and it's been trivial to get it fixed. I've never had a checking account compromise, but I'm pretty sure it would be a massive pain in the ass by comparison.

Did the bank charge you for the replacement cards? Is there any real reason not to just regularly - say every 3 months - request a new card for peace of mind?
Post reply on HN