TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

eBay customers’ personal data was compromised in March

187 pointsby patchoulolabout 11 years ago

27 comments

panarkyabout 11 years ago
The spin is atrocious. The big story is not the headline, that users must change passwords.<p>The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down.<p><pre><code> The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. </code></pre> Don&#x27;t patronize me with empty platitudes like &quot;changing passwords is a best practice&quot;.<p>Tell me to brace for an inevitable wave of phishing and identity attacks.<p>Tell me that bad guys will try to steal my other online accounts with this information.<p>Tell me to trust no one because bad guys now look legit with my home address, phone number and DOB.<p>Pro tip: put the real story in the headline. That&#x27;s also a &quot;best practice&quot;.
评论 #7778458 未加载
评论 #7778594 未加载
评论 #7778890 未加载
评论 #7778538 未加载
评论 #7778780 未加载
评论 #7780435 未加载
leorockyabout 11 years ago
&gt; The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted.<p>Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seriously the owner of PayPal should not be telling me this &quot;we have no evidence of&quot; bullshit because there&#x27;s no alternative to PayPal that online stores actually use and changing your checking account number and routing number is very very painful. You have to get new checks, you lose checking history. Fuck.
评论 #7778373 未加载
评论 #7778496 未加载
评论 #7778437 未加载
评论 #7780285 未加载
评论 #7778533 未加载
评论 #7778904 未加载
wrboyceabout 11 years ago
&quot;The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. However, the database did not contain financial information or other confidential personal information.&quot;<p>…So, just my entire identity then? eBay really seem to be down-playing the severity of this.
评论 #7778363 未加载
评论 #7779399 未加载
danielweberabout 11 years ago
FWIW, &quot;ebayinc.com&quot; totally screams &quot;phishing attempt&quot; to me.
评论 #7778262 未加载
评论 #7778245 未加载
评论 #7778279 未加载
AdmiralAsshatabout 11 years ago
Week 1: &quot;We have no reason to believe that any confidential information has been compromised.&quot;<p>Week 2: &quot;We have observed some limited and negligible instances of credit card information being compromised that coincidentally happened to be linked to eBay accounts. We consider this purely coincidental and feel it is no cause for concern.&quot;<p>Week 3: &quot;Oh god they took everything.&quot;
jgrahamcabout 11 years ago
Has anyone received an email from eBay about this? I&#x27;m guessing that the phishers are going to be faster at getting out fake change password emails than eBay themselves.
orbitingplutoabout 11 years ago
Since PayPal == eBay, I just went to change my PayPal password as well.<p>PayPal went full retard. The security confirmation question?<p>Please supply your full credit card number ending in ####.<p>Um, that&#x27;s the information I&#x27;m trying to protect in the first place.<p>edit: sorry about the &quot;full retard&quot; - trying to quote from Tropic Thunder&#x2F;RDJ. did not mean to offend
评论 #7778527 未加载
评论 #7778559 未加载
评论 #7778942 未加载
评论 #7778683 未加载
评论 #7778650 未加载
评论 #7778556 未加载
freehunterabout 11 years ago
&gt;Cyberattackers compromised a small number of employee log-in credentials<p>This bothers me. No one cares how many employee logins were stolen. It only takes one to cause a huge amount of damage. Is anyone reading this thinking &quot;oh, it&#x27;s okay, they didn&#x27;t take too many employee logins&quot;?
评论 #7778181 未加载
评论 #7778506 未加载
Theodoresabout 11 years ago
This is headline top-story news on the BBC right now therefore it must be &#x27;big&#x27;. Yet no evidence of anyone making unauthorised access.<p>We have had a resurgence of &#x27;Snowden&#x27; stories in the last few days, so here is a hypothetical scenario: what does a company do if the hackers turn out to be NSA&#x2F;GCHQ? It is unlikely that they would drop an email to explain that they had just stolen the whole customer database because of some &#x27;al-qaeda&#x27; based reasoning, so you would not know it was them. If you suspected it was them then people would wonder if you had taken your meds. If you got the FBI involved then they would tell you it was some script kiddies rather than the Peeping-Tom-Brigade.<p>Or, if you did know it was the NSA, then you might think that information was safe in their hands and not feel the need to tell the customers.<p>I look forward to when we get stories where the NSA are explicitly blamed for a data breach instead of some random Chinese hacker, and that emails are sent out saying &#x27;we have been hacked by the NSA again, can you change your passwords please?&#x27;. If the NSA crawled out of the darkness to deny the breach then nobody would believe them.
评论 #7778565 未加载
davbabout 11 years ago
And neither eBay nor PayPal allow me to paste a secure password from KeePassX. <i>sigh</i><p>Edit: I can now paste on eBay (not sure what went wrong the first time) but PayPal is still actively preventing pasting a new password.
评论 #7778809 未加载
评论 #7778586 未加载
评论 #7778576 未加载
oneweirdtrickabout 11 years ago
Shouldn&#x27;t eBay have emailed all their customers by now? Why are we learning about this through a blog post?
评论 #7779291 未加载
dangabout 11 years ago
We changed the title because, as users pointed out, it was misleading.
plingabout 11 years ago
Considering the situation, its either poor timing or related but I can&#x27;t change my PayPal password. Get a blank page.<p>Not confident.<p>To be honest it takes the piss as they are spamming UK TV with adverts for how secure PayPal is at the moment.<p>Really wish I never signed up but eBay has a monopoly on the payment types now.
评论 #7778926 未加载
Sami_Lehtinenabout 11 years ago
But don&#x27;t use DuckDuckGo&#x27;s password generator. <a href="http://www.sami-lehtinen.net/blog/random-passwords-using-duckduckgo" rel="nofollow">http:&#x2F;&#x2F;www.sami-lehtinen.net&#x2F;blog&#x2F;random-passwords-using-duc...</a>
bradorabout 11 years ago
Is this only for ebay US or are other country versions affected too?
评论 #7779154 未加载
askewabout 11 years ago
Unfortunately, attempting to reset one&#x27;s password results in:<p>&gt; Sorry. We&#x27;re currently experiencing technical difficulties and are unable to complete the process at this time.<p>Swamped already?
评论 #7778452 未加载
评论 #7778425 未加载
hpoydarabout 11 years ago
Took a trip back to 2002 and visited the Account Settings &#x2F; Personal Information screen to change my password. No alerts or redirects on login to change credentials. (But evidently an exciting &quot;deal frenzy&quot; is important enough to highlight in all caps and red text in the nav bar). Ok, so the PayPal DB wasn&#x27;t affected, but does that matter? PayPal account is fully linked up there.
ExpendableGuyabout 11 years ago
So I logged into eBay for the first time in over a year to change my password, and noticed that eBay edited my reply to a buyer&#x27;s feedback.<p>Has anyone else heard about eBay doing this? I have no way to edit it back to the way it was from what I can tell. It&#x27;s infuriating -- they changed the word &quot;Buyer&quot; to &quot;Seller&quot; to make it sound like my reply to feedback was referring to myself.
UVB-76about 11 years ago
Remember a couple of months ago when Icahn described eBay as the worst-run company he&#x27;d ever seen? [1]<p>Seems rather prescient now. Their incompetence has just cost us all our personal information.<p>[1] <a href="http://www.cnbc.com/id/101467290" rel="nofollow">http:&#x2F;&#x2F;www.cnbc.com&#x2F;id&#x2F;101467290</a>
ericcholisabout 11 years ago
Being that important auxiliary details were compromised (name, phone, etc...). Beginning to think that encrypting that information should be more standard. Obviously this leads to trouble if searching by that information is required....
评论 #7778681 未加载
kmfrkabout 11 years ago
Any way to delete your account?
评论 #7778507 未加载
rahimnathwaniabout 11 years ago
<i>database containing encrypted passwords</i><p>Does anyone know whether they used per-user salt?
评论 #7778251 未加载
评论 #7778366 未加载
icebrainingabout 11 years ago
Oh, so this explains the spam! I use a different email address for each site, and spam for ebay@[mydomain] became noticeable about two months ago. I should really pay more attention to these signs.
评论 #7780501 未加载
ChikkaChiChiabout 11 years ago
I&#x27;m getting tired of sites that limit password length. Microsoft limits you to 16 characters.<p>Storage is cheap and you shouldn&#x27;t be skimping on the most sensitive field in your dataset.
dodygabout 11 years ago
I would be so fuckin&#x27; mad if the passwords aren&#x27;t hashed.
darylfritzabout 11 years ago
eBay&#x27;s password character limit is 20 characters. I use a password manager and detest sites that limit your password length to &lt; 100 characters.
评论 #7778648 未加载
评论 #7779553 未加载
morbiusabout 11 years ago
I&#x27;m so tired of large corporations not taking infosec seriously. This is a shame, in all honesty.