One would also think that eBay would have a strong interest in developing trust between themselves and their customers, but there is little evidence of that recognition. Specifically, the going corporate standard for a major security breach among eBay's corporate peers is (a) full and (b) immediate disclosure.
By (a) full, note, that eBay has come our with a very murky statement about exactly what happened. There is nothing more substantial than "you should change your password but we don't think there is any danger". Well, was there general database access? Did attackers had access to production servers? All of them? Is there any impartial 3rd party audit that stands behind eBays security statements? Further, as part of a full disclose, it's good procedure to disclose how passwords were stored if they expect to establish trust. They have had 2 weeks at least to prepare their statements and they can't do better than the useless "passwords were encrypted"?. There are really only two possibilities here: (1) passwords were combined with a random salt and then hashed or (2) they were morons. And right now given their public statement it looks like (2).
By (b) immediate, note, its not unreasonable to expect that a certain percentage of eBay's users use the same username / password for both their eBay and their PayPal accounts. So for a couple of weeks now eBay has been aware of a potential financial danger to their customers and they have been sitting on the problem. Fail.
Security breaches happen to everyone. There is no faulting eBay there. The fault is with all aspects of their response. They have had a major security breach and they have not responded with a proportional disclosure. And that implies that security isn't their largest company problem.