Live data from Hacker News

Hackers raid eBay in historic breach, access 145 million records

reuters.com

11–20 of 100 posts

Re: Hackers raid eBay in historic breach, access 145 million records

#13
> Cyberattackers compromised a small number of employee log-in credentials, allowing unauthorized access to eBay's corporate network, the company said. Working with law enforcement and leading security experts, the company is aggressively investigating the matter and applying the best forensics tools and practices to protect customers.

Seems like the kind of tactic used by spy cells to target people in certain places.

Re: Hackers raid eBay in historic breach, access 145 million records

#17
post #6

"EBay spokeswoman Amanda Miller told Reuters late on Wednesday that those passwords were encrypted and that the company had no reason to believe the hackers had broken the code that scrambled them." That seems to imply that eBay used a singular encryption key across its accounts. Surely not?

Journalists and PR people don't know the difference between encryption and hashing. eBay is steering media reports toward the password story. Much more important and potentially damaging to eBay's reputation and revenue is that 145 million user records were stolen. This could be much more damaging than the Target or Adobe breaches.

Target had payment info. That trumps this easily.

Re: Hackers raid eBay in historic breach, access 145 million records

#18

"EBay spokeswoman Amanda Miller told Reuters late on Wednesday that those passwords were encrypted and that the company had no reason to believe the hackers had broken the code that scrambled them." That seems to imply that eBay used a singular encryption key across its accounts. Surely not?

Like panarky, I wouldn't take that on face value. I'm going to guess that a significant number of people use the same password for Ebay as for Paypal. Someone's got a lot of incentive to generate some hashes tonight..

Re: Hackers raid eBay in historic breach, access 145 million records

#20

With such a large user database, why isn't tar pitting db requests the norm?... or at the very least, instituting something as simple as a flag on dummy record requests?

A flag on dummy record requests? You mean have records that don't correspond to real accounts, and audit access to them? How would you censor them from legitimate full traversals of the user database? How would you tar-pit attackers without throttling such legitimate processes?
Post reply on HN