Live data from Hacker News

eBay customers’ personal data was compromised in March

ebayinc.com

141–146 of 146 posts

Re: eBay customers’ personal data was compromised in March

#141
post #87

Earlier quoted context omitted.

You think that's bad? Charles Schwab Bank only allows you 8 characters for the password. No special characters either.

AMEX also has surprising restrictive passwords. Is the security surrounding password resets so bad that it's more secure to force easier to remember passwords?

So does Discover. When I wouldn't take "just because" for an answer, IIRC the explanation was that it resulted in fewer password reset requests, so I believe your take is correct.

Re: eBay customers’ personal data was compromised in March

#142
post #87

Earlier quoted context omitted.

You think that's bad? Charles Schwab Bank only allows you 8 characters for the password. No special characters either.

AMEX also has surprising restrictive passwords. Is the security surrounding password resets so bad that it's more secure to force easier to remember passwords?

It's more likely to be cheaper: less support calls/emails.

Re: eBay customers’ personal data was compromised in March

#143
post #16

database containing encrypted passwords Does anyone know whether they used per-user salt?

If they're encrypted, they're reversible. Salt doesn't matter. You would think ebay would hash passwords.

I'm assuming they meant hashed rather than encrypted. If they were actually encrypted, then it's strange that they didn't say whether the key to decrypt them was also stolen.

Re: eBay customers’ personal data was compromised in March

#144
post #73

Earlier quoted context omitted.

I tried this around an hour ago and can't paste, it's being explicitly blocked. Perhaps my region (UK) still uses the old password change page? For clarification, I'm using the change password function once logged in and not doing a forgotten password reset.

I'm referring to a new Bootstrappy dialog (blue and white candy buttons) available when you login from Paypal.com

Go through this screen and you can paste. Just did, but no pic here because I don't want to reset the password yet again.

http://imgur.com/M2NTNpd

Re: eBay customers’ personal data was compromised in March

#145

Earlier quoted context omitted.

>> "PayPal went full retard." I'm not usually big on political correctness but you could so easily replace that phrase with something that's not taking the piss out of people.

I suppose I could. I was going for the "Tropic Thunder" line. But really, political correctness? Has anyone ever called an actually mentally handicapped person "retarded" in the past thirty years?

I got that you were going for a "Tropic Thunder" ref, but it doesn't fit. It sounds like you're saying ebay is stupid, but the TT is satirizing actors pretending to be stupid. And, TT gets away with the bit because it pushes PC-ness further towards not shitting on mentally disabled folks. Mayhaps it should, but slang use of the word "retarded" doesn't automatically offend me. I just don't think your use worked.

Re: eBay customers’ personal data was compromised in March

#146
post #93
post #82

Earlier quoted context omitted.

Ebay claims that 20 characters is the max, but it's a lie - mine is 29. Likewise, Newegg claims that you have to have special characters, but my password has none. I'd suggest trying the password you want and seeing if it gets rejected. In a lot of cases, some programmer may have fixed the crazy password scheme and forgotten to update the page text.

Are you sure that your password is actually 29 characters? Try changing some of the last nine characters and see if it will still let you log in; they may just be dropping the last nine silently.

If I leave off or change the last few characters I can't log in. They don't truncate the password.
Post reply on HN