eBay customers’ personal data was compromised in March
ebayinc.com
ebayinc.com
The big story is that ebay leaked personally identifiable information. Naturally this is buried four paragraphs down.
The database, which was compromised between late February and
early March, included eBay customers’ name, encrypted password,
email address, physical address, phone number and date of birth.
Don't patronize me with empty platitudes like "changing passwords is a best practice".Tell me to brace for an inevitable wave of phishing and identity attacks.
Tell me that bad guys will try to steal my other online accounts with this information.
Tell me to trust no one because bad guys now look legit with my home address, phone number and DOB.
Pro tip: put the real story in the headline. That's also a "best practice".
Do I need to update my PayPal account too? (my email is the same, but both passwords are long and randomised so not too bothered). So now they know my email address and my home address - and my date of birth, always convenient. Oh and as someone pointed out, I have PayPal automatically linked to my eBay account. Great.
Which physical address? My default delivery? My invoice address?
So a quick update from the BBC: "something it only became aware of a fortnight ago"
They only just realised, essentially. Although it's worrying that it took an eCommerce site so long to catch it. And that's still two weeks when eBay knew and nobody else did.
http://leginfo.legislature.ca.gov/faces/codes_displaySection...
If the breach affects more than 500 California residents, an online report must be filed with the Attorney General.
You can search breach reports, and I could not find any from ebay.
http://oag.ca.gov/ecrime/databreach/list?field_sb24_org_name...
You can also file a complaint against businesses that fail to disclose breaches here:
http://oag.ca.gov/contact/consumer-complaint-against-busines...
P.S. I wonder if they were expecting a lot of resets, hence the redesign rollout?
if passwords are being hashed, which i guess i would have to believe they are, at least in the BOA case, what's the point of restricting character counts (especially to 20), or choosing random characters to exclude?
Note that this validation may take the form of validating to someone, shall we say, less than fully competent, or it could be an actual means to protect yourself.
The additional search space from 62^N to 200^N isn't especially worth worrying about, IMO.
http://msdn.microsoft.com/en-us/library/bb355989.aspx (to cite just one way that these things come into being; someone finds that you can do input validation easily, and they do it, maybe because they're overly cautious, maybe because someone they need to convince is overly cautious, maybe some other reason) IMO, this is not an especially terrible "flaw" in a site.
1. Legacy systems. The system that was built 15 years ago might have limited the field for performance or storage reasons and it was never updated. Or maybe the Palm Pilot app only supports 20 characters in a text field and nobody has the source code but there's still a dedicated bunch of 200 users who do $50,000 in sales every year and nobody wants to piss them off. Or maybe they're just afraid the monster has gotten too big and they don't know what'll break if they change anything. Better to play it conservative so you're not the person who shut a group of users out of the system.
2. Just because. True story: I was working on an internal app for a company years back and I asked my manager if there were any particular password restrictions we needed to honor, any kind of company policies or weird accessibility concerns or something [1]. So what does he do? He emails the marketing stakeholder and asks her what the password rules should be. She doesn't know anything about security, so she concocts something completely arbitrary based on stuff she's seen on other sites. 6-10 characters, at least one number & one symbol, etc. And those were the requirements I had to implement, because that's what the stakeholder wants, even though that was the answer to completely the wrong question.
> if passwords are being hashed, which i guess i would have to believe they are
I wouldn't assume that. Think about a bank where you have call center staff who know a certain customer by name because he calls every Thursday saying he can't remember which of his grandkids' names he used as a password and could you please tell him because the rent is due Monday and he needs to transfer money from savings to checking because his Social Security check is late this month. And so on. You know how old guys are with their stories. You're reading one now. The CSR doesn't want to walk him through the steps of resetting his password over the phone…again. The faster he can get him logged in, the sooner he'll go away.
"We need a way to display that guy's password to a CSR," the head of the department tells the CEO over golf, knowing if he gets the department's average call time under two minutes he gets an extra $100,000 this year. So, the edict comes down from the highest levels of the company that the passwords have to be encrypted & reversible instead of hashed.
Now, this story is completely fictitious, but I've been in similar situations where the all-important call-center & support metrics trumped security. It happens. It shouldn't, but it happens.
[1] Maybe even a legacy Palm Pilot app…
Is the security surrounding password resets so bad that it's more secure to force easier to remember passwords?
Who comes up with these damn ideas when you are dealing people's money and information?
Likewise, Newegg claims that you have to have special characters, but my password has none.
I'd suggest trying the password you want and seeing if it gets rejected. In a lot of cases, some programmer may have fixed the crazy password scheme and forgotten to update the page text.
Unfortunately there's nothing inevitable about this! b^)
On March 15th I received at that email address a "New York Lotto" phishing email. That is the only spam I got so far on that email account.
So I would assume that they have at least some Paypal subscribers data, including email and home city (and maybe address).
Which is exactly why we took 3 months to inform you, you've been hacked. It's because we care. Don't you see?
Holy crap, isn't that enough to do some social engineering and get a new credit card or something equally serious?!
Made me retch too. Pardon me, but how did your security snafu get to be about telling me what I ought to do? Some sort of amateur reverse psychology? A Jedi mind-trick? Kind of implies that we somehow have responsibility for it too. "Yes, yes, we allowed this to happen, but if you'd only make yourself aware of best practices, you wouldn't have anything to worry about."
Very condescending. Just tell me what I need to do to mitigate your screw up. Skip the security lesson and misdirection.
I also don't see an apology, but merely "regrets". I'm guessing their legal department weighed in on this one, but that omission, along with the spin, and the whole picture just reads like a big CYA and a "screw you!" to customers.
Ebay being hacked kind of scares the hell out of me because PayPal has my checking account information with direct access to withdraw funds. A hacker could rob me blind. Like seriously the owner of PayPal should not be telling me this "we have no evidence of" bullshit because there's no alternative to PayPal that online stores actually use and changing your checking account number and routing number is very very painful. You have to get new checks, you lose checking history. Fuck.
It's extra work for me, but it's also less risk. Unless somebody gains access to my online banking account, they're not going to be able to access my primary funds account.
I have one checking account that my paycheck goes into, and I pay monthly/yearly recurring bills out of this account. There is nothing online for this account, the only way money gets out is that I get my bank to send somebody a check.
I set up a weekly auto-transfer to a separate account which my wife and I carry around debit cards for. This is for groceries, gas, and personal shopping stuff, including online.
It's two checking accounts in the same bank. Just call your bank and ask them to make you another account.
With my bank I don't even have to call them, I can make one from the account page.
By having it in the same bank I can leave the PayPal account always at 0, and transfer the money easily to the other account.
Banks are not always as smart as they should be and sometimes allow an account of a customer 'in good standing' or with a credit balance on another account to be overdrawn. Especially when it is done via direct debit.
This sort of thing can really bite you.
a) My wife isn't into tech as much as I am and has a much lower threshold for acceptable complexity
b) More importantly, any software that I found had a large maintenance burden. Having her ask "do we have enough to go to dinner tonight?" requires me to have the books up-to-date almost on a daily basis. Too much work.
Now, the question of how much do we have to spend for specific activities has a very simple answer: how much is in the "spending" bank account, and it's easy to prorate that over a week's time.
A previous attempt at this was over a month's time frame, but that's too long of a time span. It's easy to overspend earlier in the month and fail to mentally take into account bigger things near the end of the month.
I also tried being "squishy" with the amount, moving it around depending on how much we overspent for the previous week (e.g., put something on our credit card because we actually needed to). This also doesn't work out too well, because it impairs predictability, even if it balances the books better. Plus, I want to get us off the mindset of using the credit card when we overspend a week. I was, frankly, being a tightwad with the weekly amounts and loosened it up a little to give us a bit more buffer.
Setting a weekly fixed amount made our money conversations easier. I'm still undoing financial damage from earlier (paying off credit card debt and building up savings for yearly bills), but this is an abstraction my wife doesn't need to worry about (she knows about it but doesn't need to deal with it).
This was all tangential to protecting yourself from badness, but it was a nice side effect.
In every case Chase refunded me in full within a few days. This isn't something every bank does?
It might take you some time to get it back, but the bank is legally required to get it back to you.
For business accounts this protection does not apply.
Wouldn't it be possible for them instead to store a token generated from the card number and Ebay/Paypal's incoming bank account number, which can only be used for paying into that particular account?
Checking account info is much, much worse. It's much harder to reverse fraudulent transactions there, and much harder to get a new number.
I've never had a checking account compromise, but I'm pretty sure it would be a massive pain in the ass by comparison.
A compromise of your routing and account number for your checking account is potentially much worse. It's harder to take advantage of, but it's also much harder to fix.
(I'm not sure if you were treating the debit card as analogous to credit cards or account numbers, so treat this as confirmation/correction/elaboration/whatever as appropriate.)
From what I recall with the Target incident, their cost is something like $2-5 for each replacement card, so it's not entirely trivial. If you requested a new one on a regular basis for no good reason, they might put a stop to it one way or another.
As far as peace of mind goes, since the consequences are so mild, I wouldn't worry about it.
So I'm trying an arbitrage trade. Just sold short ebay at 51.62 and hedged by buying amzn at 305.44.
If this is more serious than the press release indicates, ebay should deteriorate relative to amzn.
Obviously this is harder to do if you are a merchant who takes large amounts of money through paypal. In those cases though the merchant should have already segmented the paypal hooked bank account from the primary business account. If you are a merchant and have not done this, now is a good time.
1. You cannot remove a primary credit card from your profile. There is only one option "Edit" where you can change expiration date and Billing Address. Entering incorrect expiration date does not work. It only allowed me to change billing address.
2. Removing checking account is not confirmed. Once I've clicked "Remove" button I was redirected to login screen. Now when I try to access my bank account I am signed out and redirected to login.
I hate calling them, but looks like that's my only option.
…So, just my entire identity then? eBay really seem to be down-playing the severity of this.
This announcement actually leaked when a "placeholder" was put up on the paypal-community.com forum:
https://news.ycombinator.com/item?id=7777182
And I did some simple tests to make sure that domain was really ebay/paypal:
All their internal systems are maintained by vendors, VARs, and contractors.
So weird stuff like the ebayinc.com domain is to be expected. As is this hack. Also it'd be interesting to know how it was detected, and how the extent of access was determined. But if my prediction is correct, we will never see a truly open blog post about it. First, because it's not clear to me that eBay "infosec" is up to the task. Second, because eBay believes more in compartmentalization, secrecy, misdirection etc. than 'openness'.
If it wasn't for a tiny amount of 'reputation' which might make others more willing to deal with me, I'd close my ebay account right now.
Week 2: "We have observed some limited and negligible instances of credit card information being compromised that coincidentally happened to be linked to eBay accounts. We consider this purely coincidental and feel it is no cause for concern."
Week 3: "Oh god they took everything."
PayPal went full retard. The security confirmation question?
Please supply your full credit card number ending in ####.
Um, that's the information I'm trying to protect in the first place.
edit: sorry about the "full retard" - trying to quote from Tropic Thunder/RDJ. did not mean to offend
However I just realized that the credit card might be the only legitimate piece of data that they have left to verify against.
I'm not usually big on political correctness but you could so easily replace that phrase with something that's not taking the piss out of people.
By the way, the euphemism treadmill of this subject has proceeded to the point where "mentally handicapped" and "mentally challenged" are also now politically-incorrect. The preferred term is now "intellectually disabled" or "learning disabled" (which to me is far more insulting than "mentally retarded", from a literal perspective, but less evasive than "developmentally delayed").
This bothers me. No one cares how many employee logins were stolen. It only takes one to cause a huge amount of damage. Is anyone reading this thinking "oh, it's okay, they didn't take too many employee logins"?
Well that's not entirely true. First off, it indicates that the breach was relatively contained. Or at least EBay want's you to think that.
The smaller the number the less chance there is that the credentials were to more privileged employees. Not every employee is created the same. Not every employee has access to account data and not every employee could send customers corporate communications.
Now yes, the who they got is important over the how many, but the how many can be stated without giving too much away.
They focus on relatively unimportant aspects of what happened and leave the big stuff as an afterthought. It's like an airline captain announcing, "Due to mechanical problems, we will be late getting into New York. For those of you on connecting flights, we will re-book you on later flights at no charge, ensure that your luggage travels with you. I apologize for the inconvenience. Also, all the engines are on fire and we're probably all going to die."
It seems that they think their best way forward is if most of their users don't grasp the significance of what happened.
We have had a resurgence of 'Snowden' stories in the last few days, so here is a hypothetical scenario: what does a company do if the hackers turn out to be NSA/GCHQ? It is unlikely that they would drop an email to explain that they had just stolen the whole customer database because of some 'al-qaeda' based reasoning, so you would not know it was them. If you suspected it was them then people would wonder if you had taken your meds. If you got the FBI involved then they would tell you it was some script kiddies rather than the Peeping-Tom-Brigade.
Or, if you did know it was the NSA, then you might think that information was safe in their hands and not feel the need to tell the customers.
I look forward to when we get stories where the NSA are explicitly blamed for a data breach instead of some random Chinese hacker, and that emails are sent out saying 'we have been hacked by the NSA again, can you change your passwords please?'. If the NSA crawled out of the darkness to deny the breach then nobody would believe them.
"Ebay asking people to change passwords after a cyberattack compromised database containing encrypted user details"
Not True! The user details were unencrypted, bar the password.
Edit: I can now paste on eBay (not sure what went wrong the first time) but PayPal is still actively preventing pasting a new password.
However on PayPal, when pasting I received a little tooltip-style popup saying something along the lines of "Please do not copy and paste passwords.", followed by their password criteria.
Pasting into other fields (including the login page password field) worked perfectly fine.
Perhaps my region (UK) still uses the old password change page? For clarification, I'm using the change password function once logged in and not doing a forgotten password reset.
This doesn't let me paste, giving the aforementioned tip that I should copy/paste.
Not confident.
To be honest it takes the piss as they are spamming UK TV with adverts for how secure PayPal is at the moment.
Really wish I never signed up but eBay has a monopoly on the payment types now.
> Sorry. We're currently experiencing technical difficulties and are unable to complete the process at this time.
Swamped already?
Has anyone else heard about eBay doing this? I have no way to edit it back to the way it was from what I can tell. It's infuriating -- they changed the word "Buyer" to "Seller" to make it sound like my reply to feedback was referring to myself.
Seems rather prescient now. Their incompetence has just cost us all our personal information.
However note that they claim it will take up to 180 days to delete your account. (I went through this last year, getting sufficiently annoyed to close both Ebay & Paypal accounts.)
Does anyone know whether they used per-user salt?
Though whether they really are using encryption (of plaintext passwords?), or whether they actually meant hashing is another question.
The last few months have seen a substantial increase. Presumably linked to the eBay breach.
Storage is cheap and you shouldn't be skimping on the most sensitive field in your dataset.