4 ms·
"3 months ago"... And "eBay suggest users chanche their password"... Wait, what? I suggest a policy where important breaches in security are disclosed within a
by digitalengineer 12y ago
"3 months ago"... And "eBay suggest users chanche their password"... Wait, what? I suggest a policy where important breaches in security are disclosed within a short timeframe.
- watson 12y agoThey didn't know about the breach until about two weeks ago [1], though that doesn't normally excuse that they waited two weeks to go public with the knowledge. One reason to hold back this information is if going public would make their investigation harder OR if going public would increase the security risk (e.g. if the security hole used wasn't yet fixed and going public meant disclosing something about how the hackers got access). But according to what had been made public so far this doesn't seem to be the case. [1] http://www.ebayinc.com/in_the_news/story/ebay-inc-ask-ebay-users-change-passwords http://www.ebayinc.com/in_the_news/story/ebay-inc-ask-ebay-u...
- digitalengineer 12y agoAgree. Those should be the only reason not to disclose breaches (to the public).