Live data from Hacker News

eBay customers’ personal data was compromised in March

ebayinc.com

131–140 of 146 posts

Re: eBay customers’ personal data was compromised in March

#131

> The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted. Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seri…

Thanks for reminding about this. I was using a separate checking account just for Paypal. Until they "restricted" my PP account. Since I've stopped using PayPal now I keep some money on that checking account. Went to update my profile...

1. You cannot remove a primary credit card from your profile. There is only one option "Edit" where you can change expiration date and Billing Address. Entering incorrect expiration date does not work. It only allowed me to change billing address.

2. Removing checking account is not confirmed. Once I've clicked "Remove" button I was redirected to login screen. Now when I try to access my bank account I am signed out and redirected to login.

I hate calling them, but looks like that's my only option.

Re: eBay customers’ personal data was compromised in March

#132
post #52
post #18

The spin is atrocious. The big story is not the headline, that users must change passwords. The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down. The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. Don't patronize me…

> customers’ name, encrypted password, email address, physical address, phone number and date of birth Holy crap, isn't that enough to do some social engineering and get a new credit card or something equally serious?!

Not directly -- I don't think I've ever seen a (U.S.) credit card application which didn't also want your social security number. That said, it's a pretty good start.

Re: eBay customers’ personal data was compromised in March

#133
post #73

Earlier quoted context omitted.

I tried this around an hour ago and can't paste, it's being explicitly blocked. Perhaps my region (UK) still uses the old password change page? For clarification, I'm using the change password function once logged in and not doing a forgotten password reset.

I'm referring to a new Bootstrappy dialog (blue and white candy buttons) available when you login from Paypal.com

Ah. I don't see that. I see the new front screen (with large HTML5 video background) but when I log in I've got a rather dated interface http://imgur.com/KVSREgH

This doesn't let me paste, giving the aforementioned tip that I should copy/paste.

Re: eBay customers’ personal data was compromised in March

#134
post #31
post #18

The spin is atrocious. The big story is not the headline, that users must change passwords. The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down. The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. Don't patronize me…

Don't forget that it was nearly three months ago. Why weren't users informed immediately? Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great. Which phy…

[deleted]

Re: eBay customers’ personal data was compromised in March

#135

Earlier quoted context omitted.

this always gets me, and every time i ask i can't seem to find a direct answer why so many sites have this 20 character limit. bank of america does as well, with the additional restriction that you can't use the following characters: $ & ^ ! []. bluecross/blueshield allows up to 30 characters, but only numbers and letters. if passwords are being hashed, which i guess i would have to believe they are, at least in the…

Choosing random characters to exclude (or alternately, only permitting a subset of characters) can make the task of validating that you aren't subject to an injection attack easier. Note that this validation may take the form of validating to someone, shall we say, less than fully competent, or it could be an actual means to protect yourself. The additional search space from 62^N to 200^N isn't especially worth worry…

Blocking random characters prevents password managers from being able to choose random passwords, though.

Re: eBay customers’ personal data was compromised in March

#137
post #31
post #18

The spin is atrocious. The big story is not the headline, that users must change passwords. The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down. The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. Don't patronize me…

Don't forget that it was nearly three months ago. Why weren't users informed immediately? Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great. Which phy…

[deleted]

Re: eBay customers’ personal data was compromised in March

#138
post #18

The spin is atrocious. The big story is not the headline, that users must change passwords. The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down. The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. Don't patronize me…

>Don't patronize me with empty platitudes like "changing passwords is a best practice".

Made me retch too. Pardon me, but how did your security snafu get to be about telling me what I ought to do? Some sort of amateur reverse psychology? A Jedi mind-trick? Kind of implies that we somehow have responsibility for it too. "Yes, yes, we allowed this to happen, but if you'd only make yourself aware of best practices, you wouldn't have anything to worry about."

Very condescending. Just tell me what I need to do to mitigate your screw up. Skip the security lesson and misdirection.

I also don't see an apology, but merely "regrets". I'm guessing their legal department weighed in on this one, but that omission, along with the spin, and the whole picture just reads like a big CYA and a "screw you!" to customers.

Re: eBay customers’ personal data was compromised in March

#139

Earlier quoted context omitted.

Damn, PayPal updated their password reset UI in the last week, but you can still only enter 20 characters for a site that holds cold hard (electronic) cash. Really guys? If you're really hashing them, why does the length matter? The DB column width doesn't need to change. Want us to submit a patch? P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?

this always gets me, and every time i ask i can't seem to find a direct answer why so many sites have this 20 character limit. bank of america does as well, with the additional restriction that you can't use the following characters: $ & ^ ! []. bluecross/blueshield allows up to 30 characters, but only numbers and letters. if passwords are being hashed, which i guess i would have to believe they are, at least in the…

http://security.stackexchange.com/questions/33470/what-techn...

Re: eBay customers’ personal data was compromised in March

#140

Oh, so this explains the spam! I use a different email address for each site, and spam for ebay@[mydomain] became noticeable about two months ago. I should really pay more attention to these signs.

Indeed, my primary email address sits on a personal domain, is only used on 'respectable' websites, and historically has received very little spam.

The last few months have seen a substantial increase. Presumably linked to the eBay breach.

Post reply on HN