Hackers raid eBay in historic breach, access 145 million records
11–20 of 100 posts
Re: Hackers raid eBay in historic breach, access 145 million records
#12Re: Hackers raid eBay in historic breach, access 145 million records
#13Seems like the kind of tactic used by spy cells to target people in certain places.
Re: Hackers raid eBay in historic breach, access 145 million records
#14Re: Hackers raid eBay in historic breach, access 145 million records
#15Billion dollar startup opportunity: un-hackable, secure databases as a service.
Re: Hackers raid eBay in historic breach, access 145 million records
#16Billion dollar startup opportunity: un-hackable, secure databases as a service.
Re: Hackers raid eBay in historic breach, access 145 million records
#17"EBay spokeswoman Amanda Miller told Reuters late on Wednesday that those passwords were encrypted and that the company had no reason to believe the hackers had broken the code that scrambled them." That seems to imply that eBay used a singular encryption key across its accounts. Surely not?
Journalists and PR people don't know the difference between encryption and hashing. eBay is steering media reports toward the password story. Much more important and potentially damaging to eBay's reputation and revenue is that 145 million user records were stolen. This could be much more damaging than the Target or Adobe breaches.
Re: Hackers raid eBay in historic breach, access 145 million records
#18"EBay spokeswoman Amanda Miller told Reuters late on Wednesday that those passwords were encrypted and that the company had no reason to believe the hackers had broken the code that scrambled them." That seems to imply that eBay used a singular encryption key across its accounts. Surely not?
Re: Hackers raid eBay in historic breach, access 145 million records
#19Seems easier to just delete my account.
Re: Hackers raid eBay in historic breach, access 145 million records
#20With such a large user database, why isn't tar pitting db requests the norm?... or at the very least, instituting something as simple as a flag on dummy record requests?