Live data from Hacker News

eBay user data for sale?

pastebin.com

91–100 of 110 posts

Re: eBay user data for sale?

#91

I have an eBay account, but I haven't used it in years, and I doubt I remember the password. How worried about this should I be? Are there plaintext passwords exposed, or do they just have a lot of properly salted hashes that aren't much use to an attacker?

The passwords look like this: pbkdf2_sha256$12000$zhMKabMgayvK$iniviUCcX9y2PYJcm0AoB3MhybRA1z2Cec1DZnLWxWc= I do not know how much time it would take to bruteforce these. Can any experienced HNers weigh in?

This is actually about as good as it gets for password hashes, so kudos to eBay.

Since these are salted and require 12000 iterations, cracking individual passwords will be quite time consuming. The preferred method in this case, though, is to go after low hanging fruit.

The way one would do this is to try something like the 500 most common passwords against all entries in the table. This won't take very long (compared to trying to brute force a bunch of individual passwords), and will probably yield a ton of passwords.

Re: eBay user data for sale?

#92
post #81

There is no evidence yet that this is real, so we're burying the post.

Just because there is no evidence doesn't mean that it should be ignored. Lots of things don't yet have evidence but it is still worth letting people know so that they are ready to take the appropriate action when the time comes.

Let's face it. Lots of posts on HN are pure speculation but they don't get buried. In this case, leaving it up won't do any harm? If it's not real, then no problem. You may have convinced a few people that they should change their passwords though, but that is a good thing. If it is real, then people will already have changed their passwords. It is win win.

Personally, I'm getting really sick of the mods deciding what news is and isn't relevant and/or suitable for me.

Re: eBay user data for sale?

#93
post #65

Earlier quoted context omitted.

Oh. I missed that. That makes sense then.

More specifically, all the sample data is from Malaysia. So you'll get mostly Chinese, Malay and Indian names. (I'm Malaysian).

Thanks!

(by the way, I want to visit Singapore in the summer once I have my finals done. But that's beside the point.)

Re: eBay user data for sale?

#94

None of the sample e-mail addresses contains "ebay", as in "example+ebay@gmail.com". I just thought that was interesting.

Does eBay even allow you to enter that? What benefit would that provide?

You can still use the "add as many dots as you want" feature in gmail, even if they don't allow the plus sign.

so.me.l.ongus.e.rname@gmail.com

Someone should make a gmail plugin for decoding directives this way.

Re: eBay user data for sale?

#97

Earlier quoted context omitted.

Does eBay even allow you to enter that? What benefit would that provide?

example+ebay@gmail.com and example@gmail.com point to the same GMail inbox; you can use the part after + sign to filter incoming mail. A quite useful feature, I must say.

I had no idea that feature existed! Nice.

Re: eBay user data for sale?

#98
post #64
post #26

Why the ":s"? Are they supposed to offer it for free? Jokes aside, this, hopefully followed by a (class-action?) lawsuit, is the only way that the companies will learn how to properly store user data. The engineers have been talking about "best practices" for a very long time, but it appears managers only understand the language of money.

Let's not attempt to justify profiting from stolen personal data. This isn't a glorious mission to save the world from poor security practices, this is somebody trying to make money selling people's personal information.

You're a brilliant hacker, you lurk on security and blackhat forums, you know exploits inside and out. One day, you decide to check the security of some big consumer websites, and you find a security hole. What do you do (choose your adventure style)?

* You're a white-hat honest hacker, and all you want is for the internet to be a safer place. You decide to report the vulnerability to the company. Unfortunately, after you sent the email to their engineering team, they told you that the security hole you found isn't critical and refuse to award you a bounty. The rest of the emails go unanswered. You try sending emails to some other departments, including customer support, sales, and legal. No response. 2 months after that, when you're taking a dump on the toilet, federal agents burst into your apartment, knock you down and arrest you without even giving you the chance to wipe your ass. You're charged with industrial espionage, breach of security, and conspiracy to defraud. It turns out that someone did read your emails, checked out the logs, found traces of you researching the security hole. Your defense that you were trying to help is summarily dismissed and you rot in jail.

* You think most people are too serious and need to relax. You decide to have some fun. You download tons of embarrassing data from the company website, write them an untraceable email demanding 1000 BTC and public disclosure of your skills. You're pretty sure they will refuse your request, which they soon do. You troll the company by disclosing that they were hacked, and decide to sell the security hole to the highest bidder. You also sell chinks of data to random hackers and credit card scammers. You retire to a tropical island, drink martini and surf all day.

Re: eBay user data for sale?

#99
post #81

There is no evidence yet that this is real, so we're burying the post.

See my post below - ebay states this when you reset your password: To protect the security and privacy of our customers, we’re asking all eBay users to reset their passwords on or after May 21, 2014. If you already reset your password and forgot it, please follow the reset process below. Learn more

Try with an ebay account and then revisit this decision.

Re: eBay user data for sale?

#100
post #98
post #64

Earlier quoted context omitted.

Let's not attempt to justify profiting from stolen personal data. This isn't a glorious mission to save the world from poor security practices, this is somebody trying to make money selling people's personal information.

You're a brilliant hacker, you lurk on security and blackhat forums, you know exploits inside and out. One day, you decide to check the security of some big consumer websites, and you find a security hole. What do you do (choose your adventure style)? * You're a white-hat honest hacker, and all you want is for the internet to be a safer place. You decide to report the vulnerability to the company. Unfortunately, afte…

If choice 1 is to supposedly be good and suffer and choice 2 is to be an asshole - there's always choice 3: walk away.
Post reply on HN