10 ms·
eBay customers’ personal data was compromised in March
- jgrahamc 12y agoHas anyone received an email from eBay about this? I'm guessing that the phishers are going to be faster at getting out fake change password emails than eBay themselves.
- deleted 12y ago[deleted]
- freehunter 12y ago>Cyberattackers compromised a small number of employee log-in credentials This bothers me. No one cares how many employee logins were stolen. It only takes one to cause a huge amount of damage. Is anyone reading this thinking "oh, it's okay, they didn't take too many employee logins"?
- mhurron 12y ago> No one cares how many employee logins were stolen. Well that's not entirely true. First off, it indicates that the breach was relatively contained. Or at least EBay want's you to think that. The smaller the number the less chance there is that the credentials were to more privileged employees. Not every employee is created the same. Not every employee has access to account data and not every employee could send customers corporate communications. Now yes, the who they got is important over the how many, but the how many can be stated without giving too much away.
- freehunter 12y agoEven still, if the number of Unix admins at eBay was only 0.001% of the total number of employees, the fact that 100% of their Unix admins had their accounts compromised means that, yes, a small number of employees had their accounts breached but it would still result in 100% of their user accounts being breached.
- mikeash 12y agoThe whole press release is hilariously downplayed. This is very much a "hair on fire" moment for them, but the way they wrote this is so very casual. They focus on relatively unimportant aspects of what happened and leave the big stuff as an afterthought. It's like an airline captain announcing, "Due to mechanical problems, we will be late getting into New York. For those of you on connecting flights, we will re-book you on later flights at no charge, ensure that your luggage travels with you. I apologize for the inconvenience. Also, all the engines are on fire and we're probably all going to die." It seems that they think their best way forward is if most of their users don't grasp the significance of what happened.
- rahimnathwani 12y agodatabase containing encrypted passwords Does anyone know whether they used per-user salt?
- christop 12y agoSalt is used with a hash function, not encryption, AFAIK. Though whether they really are using encryption (of plaintext passwords?), or whether they actually meant hashing is another question.
- cschmidt 12y agoExactly. It seems like business oriented press releases often say passwords are "encrypted" when they really mean hashed (if you're lucky). So we can't really tell from this.
- skizm 12y agoIf they're encrypted, they're reversible. Salt doesn't matter. You would think ebay would hash passwords.
- rahimnathwani 12y agoI'm assuming they meant hashed rather than encrypted. If they were actually encrypted, then it's strange that they didn't say whether the key to decrypt them was also stolen.
- deleted 12y ago[deleted]
- danielweber 12y agoFWIW, "ebayinc.com" totally screams "phishing attempt" to me.
- jcr 12y agoIt is a legit ebay domain, but without https, verifying it is tougher. This announcement actually leaked when a "placeholder" was put up on the paypal-community.com forum: https://news.ycombinator.com/item?id=7777182 https://news.ycombinator.com/item?id=7777182 And I did some simple tests to make sure that domain was really ebay/paypal: https://news.ycombinator.com/item?id=7777419 https://news.ycombinator.com/item?id=7777419
- droopyEyelids 12y agoYou have to remember that eBay is an ancient tech company run by the old MBA types that didn't really understand what value to place on engineering. All their internal systems are maintained by vendors, VARs, and contractors. So weird stuff like the ebayinc.com domain is to be expected. As is this hack. Also it'd be interesting to know how it was detected, and how the extent of access was determined. But if my prediction is correct, we will never see a truly open blog post about it. First, because it's not clear to me that eBay "infosec" is up to the task. Second, because eBay believes more in compartmentalization, secrecy, misdirection etc. than 'openness'.
- oneeyedpigeon 12y agoTake a look at ebay's Account Management interface. Remember what it was like to use the web 15 years ago. Bear in mind that ebay owns PayPal which has quite possibly the worst api I've ever used, along with an interface that is even worse than ebay's. Wonder what the hell this company is doing other than lying back and counting the dollars. If it wasn't for a tiny amount of 'reputation' which might make others more willing to deal with me, I'd close my ebay account right now.
- lbarrow 12y agoIt's an investor relations-ey site.
- wrboyce 12y ago"The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. However, the database did not contain financial information or other confidential personal information." …So, just my entire identity then? eBay really seem to be down-playing the severity of this.
- gvb 12y agoTo put it more strongly, one phish away from ruin.
- mindslight 12y agoIf a few data strings comprise your entire identity, you should probably think about at least getting some hobbies.
- leorocky 12y ago> The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted. Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seriously the owner of PayPal should not be telling me this "we have no evidence of" bullshit because there's no alternative to PayPal that online stores actually use and changing your checking account number and routing number is very very painful. You have to get new checks, you lose checking history. Fuck.
- archon 12y agoI know it's not always practical for everyone, so I can't give it as general advice, but this kind of situation is exactly why I isolate my "real" checking account. My primary account (the one to which my paychecks are deposited) doesn't have a debit card, and I never use the account number. I have a different account that I use for online services like PayPal, and for recurring charges online that require a credit/debit card, which I transfer money into on demand. It's extra work for me, but it's also less risk. Unless somebody gains access to my online banking account, they're not going to be able to access my primary funds account.
- bentcorner 12y agoThis is also sort of how I operate. I have one checking account that my paycheck goes into, and I pay monthly/yearly recurring bills out of this account. There is nothing online for this account, the only way money gets out is that I get my bank to send somebody a check. I set up a weekly auto-transfer to a separate account which my wife and I carry around debit cards for. This is for groceries, gas, and personal shopping stuff, including online.
- vhost- 12y agoAre your accounts with two separate banks? Last time I tried to open another account with a separate bank, I got denied because I opened an account within the past year.
- panarky 12y agoThe spin is atrocious. The big story is not the headline, that users must change passwords. The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down. The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. Don't patronize me with empty platitudes like "changing passwords is a best practice". Tell me to brace for an inevitable wave of phishing and identity attacks. Tell me that bad guys will try to steal my other online accounts with this information. Tell me to trust no one because bad guys now look legit with my home address, phone number and DOB. Pro tip: put the real story in the headline. That's also a "best practice".
- joshvm 12y agoDon't forget that it was nearly three months ago. Why weren't users informed immediately? Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great. Which physical address? My default delivery? My invoice address? So a quick update from the BBC: "something it only became aware of a fortnight ago" They only just realised, essentially. Although it's worrying that it took an eCommerce site so long to catch it. And that's still two weeks when eBay knew and nobody else did.
- sschueller 12y agoIsn't there a law in California that requires data breach disclosure? Is there a time frame in that law? Three months is way to long and I am sure criminals will use what they get as soon as possible.
- panarky 12y agoYes, "the disclosure shall be made in the most expedient time possible and without unreasonable delay". http://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82 http://leginfo.legislature.ca.gov/faces/codes_displaySection... If the breach affects more than 500 California residents, an online report must be filed with the Attorney General. You can search breach reports, and I could not find any from ebay. http://oag.ca.gov/ecrime/databreach/list?field_sb24_org_name_value=ebay&field_sb24_breach_date_value%5Bmin%5D%5Bdate%5D=2014-01-01&field_sb24_breach_date_value%5Bmax%5D%5Bdate%5D=2014-05-21 http://oag.ca.gov/ecrime/databreach/list?field_sb24_org_name... You can also file a complaint against businesses that fail to disclose breaches here: http://oag.ca.gov/contact/consumer-complaint-against-business-or-company http://oag.ca.gov/contact/consumer-complaint-against-busines...
- pling 12y agoConsidering the situation, its either poor timing or related but I can't change my PayPal password. Get a blank page. Not confident. To be honest it takes the piss as they are spamming UK TV with adverts for how secure PayPal is at the moment. Really wish I never signed up but eBay has a monopoly on the payment types now.
- anujnayar 12y agoPayPal was not affected. I just tested changed my password and it worked fine. Info for eBay users are here. https://info.ebayinc.com https://info.ebayinc.com
- askew 12y agoUnfortunately, attempting to reset one's password results in: > Sorry. We're currently experiencing technical difficulties and are unable to complete the process at this time. Swamped already?
- kmfrk 12y agoAny way to delete your account?
- jr203fj2fuf 12y agohttp://pages.ebay.com/help/account/closing-account.html http://pages.ebay.com/help/account/closing-account.html
- kmfrk 12y agoBut does that actually delete all user records?
- stevekemp 12y agoIt certainly deletes the public-facings parts you can verify. However note that they claim it will take up to 180 days to delete your account. (I went through this last year, getting sufficiently annoyed to close both Ebay & Paypal accounts.)
- Theodores 12y agoThis is headline top-story news on the BBC right now therefore it must be 'big'. Yet no evidence of anyone making unauthorised access. We have had a resurgence of 'Snowden' stories in the last few days, so here is a hypothetical scenario: what does a company do if the hackers turn out to be NSA/GCHQ? It is unlikely that they would drop an email to explain that they had just stolen the whole customer database because of some 'al-qaeda' based reasoning, so you would not know it was them. If you suspected it was them then people would wonder if you had taken your meds. If you got the FBI involved then they would tell you it was some script kiddies rather than the Peeping-Tom-Brigade. Or, if you did know it was the NSA, then you might think that information was safe in their hands and not feel the need to tell the customers. I look forward to when we get stories where the NSA are explicitly blamed for a data breach instead of some random Chinese hacker, and that emails are sent out saying 'we have been hacked by the NSA again, can you change your passwords please?'. If the NSA crawled out of the darkness to deny the breach then nobody would believe them.
- planetjones 12y agoI wish the media could report these stories accurately. The BBC News ticker is currently saying: "Ebay asking people to change passwords after a cyberattack compromised database containing encrypted user details" Not True! The user details were unencrypted, bar the password.
- hpoydar 12y agoTook a trip back to 2002 and visited the Account Settings / Personal Information screen to change my password. No alerts or redirects on login to change credentials. (But evidently an exciting "deal frenzy" is important enough to highlight in all caps and red text in the nav bar). Ok, so the PayPal DB wasn't affected, but does that matter? PayPal account is fully linked up there.
- orbitingpluto 12y agoSince PayPal == eBay, I just went to change my PayPal password as well. PayPal went full retard. The security confirmation question? Please supply your full credit card number ending in ####. Um, that's the information I'm trying to protect in the first place. edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend
- saurik 12y agoDoesn't that make it the perfect question? For someone to answer the question correctly, they have to demonstrate that they don't even need to do so, because they already know the thing you wanted to protect?
- orbitingpluto 12y agoAlong that reasoning... I'm from your bank. Please give me your account # and PIN.
- saurik 12y agoNo, that doesn't work: if you really think that is a good argument, then everyone is also a fool for believing "enter your password here to log in"; remember that you are answering a password reset challenge question at the same site you would normally enter your password.
- mikeash 12y agoCredit card numbers should be way down on your list of info to protect. They're easy to change and the consequences of a compromise are small (you're not liable for any fraudulent transactions as long as you're paying the least bit attention). Worry about your checking account number and other info, but not your card numbers.
- orbitingpluto 12y agoIn my case, the credit card was the most important piece of data to protect. However I just realized that the credit card might be the only legitimate piece of data that they have left to verify against.
- ericcholis 12y agoBeing that important auxiliary details were compromised (name, phone, etc...). Beginning to think that encrypting that information should be more standard. Obviously this leads to trouble if searching by that information is required....
- twistedpair 12y agoIt's call PII, Personally Identifiable Information. In many industries, there are indeed strict requirements for protecting it... just not at Ebay, who, for it's age, probably predates any such standard practices.
- davb 12y agoAnd neither eBay nor PayPal allow me to paste a secure password from KeePassX. sigh Edit: I can now paste on eBay (not sure what went wrong the first time) but PayPal is still actively preventing pasting a new password.
- hnha 12y agoI can do that just fine, must be your browser interfering.
- davb 12y agoYou're right. It seems to be working now. When I first tried, I could paste into any field but the change password fields. However on PayPal, when pasting I received a little tooltip-style popup saying something along the lines of "Please do not copy and paste passwords.", followed by their password criteria. Pasting into other fields (including the login page password field) worked perfectly fine.
- tokenizerrr 12y agoUgh, companies misunderstanding password security is so infuriating. Yes, let me use my memorable 8 character password instead of my fully randomized 30 character password protected by a strong password I use only for that, and a keyfile I have stored on my computer. I feel so much more secure now that I'm using weaker passwords.
- robin_reala 12y agoI’ve not used Keepassx, but I have no trouble pasting from Lastpass…
- twistedpair 12y agoYou can paste in PayPal passwords on the password reset tool this week, but it's a new tool from last week when I last reset it. Wonder what made them update it?
- brador 12y agoIs this only for ebay US or are other country versions affected too?
- dijit 12y agoeveryone.
- oneweirdtrick 12y agoShouldn't eBay have emailed all their customers by now? Why are we learning about this through a blog post?
- LeoPanthera 12y agoThe news "leaked" a bit early. http://grahamcluley.com/2014/05/change-ebay-password/ http://grahamcluley.com/2014/05/change-ebay-password/
- AdmiralAsshat 12y agoWeek 1: "We have no reason to believe that any confidential information has been compromised." Week 2: "We have observed some limited and negligible instances of credit card information being compromised that coincidentally happened to be linked to eBay accounts. We consider this purely coincidental and feel it is no cause for concern." Week 3: "Oh god they took everything."
- darylfritz 12y agoeBay's password character limit is 20 characters. I use a password manager and detest sites that limit your password length to < 100 characters.
- unreal37 12y agoDo you find many sites that allow 100 character passwords? That surprises me.
- smellf 12y agoIt shouldn't matter at all - the hashing should be done on the client so they wouldn't need to worry about server resources, and all output from a given has function is the same size. Some hash functions may have upper limits, but I doubt it. Ever md5 a multi-GB iso you downloaded from the Internet to verify its integrity? It's the same thing.
- smellf 12y agoThe text on the page says that, but I had no problem using a 29 character password. I was upgrading from one with 23 characters though, maybe they grandfathered me in?
- dodyg 12y agoI would be so fuckin' mad if the passwords aren't hashed.
- ChikkaChiChi 12y agoI'm getting tired of sites that limit password length. Microsoft limits you to 16 characters. Storage is cheap and you shouldn't be skimping on the most sensitive field in your dataset.
- Sami_Lehtinen 12y agoBut don't use DuckDuckGo's password generator. http://www.sami-lehtinen.net/blog/random-passwords-using-duckduckgo http://www.sami-lehtinen.net/blog/random-passwords-using-duc...
- dang 12y agoWe changed the title because, as users pointed out, it was misleading.
- morbius 12y agoI'm so tired of large corporations not taking infosec seriously. This is a shame, in all honesty.
- ExpendableGuy 12y agoSo I logged into eBay for the first time in over a year to change my password, and noticed that eBay edited my reply to a buyer's feedback. Has anyone else heard about eBay doing this? I have no way to edit it back to the way it was from what I can tell. It's infuriating -- they changed the word "Buyer" to "Seller" to make it sound like my reply to feedback was referring to myself.
- UVB-76 12y agoRemember a couple of months ago when Icahn described eBay as the worst-run company he'd ever seen? [1] Seems rather prescient now. Their incompetence has just cost us all our personal information. [1] http://www.cnbc.com/id/101467290 http://www.cnbc.com/id/101467290
- icebraining 12y agoOh, so this explains the spam! I use a different email address for each site, and spam for ebay@[mydomain] became noticeable about two months ago. I should really pay more attention to these signs.
- UVB-76 12y agoIndeed, my primary email address sits on a personal domain, is only used on 'respectable' websites, and historically has received very little spam. The last few months have seen a substantial increase. Presumably linked to the eBay breach.