eBay user data for sale?
pastebin.com
pastebin.com
A quick google search shows
• http://pastebin.com/L7CYznfK
• http://pastebin.com/4YRgEwPb
that have the same message with different bitcoin addresses.
[0] https://blockchain.info/address/1e4aLP3jKD9wRAcSRNVb7VHbd7Kb...
What's to stop me from emailing one of those txn-ids to KbcdPfA@hushmail.com and stealing the dump?
Try with an ebay account and then revisit this decision.
Let's face it. Lots of posts on HN are pure speculation but they don't get buried. In this case, leaving it up won't do any harm? If it's not real, then no problem. You may have convinced a few people that they should change their passwords though, but that is a good thing. If it is real, then people will already have changed their passwords. It is win win.
Personally, I'm getting really sick of the mods deciding what news is and isn't relevant and/or suitable for me.
[1] http://www.digitalnewsasia.com/security/ebay-hackers-offer-d...
[2] http://www.reddit.com/r/netsec/comments/267015/ebay_user_dat...
Jokes aside, this, hopefully followed by a (class-action?) lawsuit, is the only way that the companies will learn how to properly store user data. The engineers have been talking about "best practices" for a very long time, but it appears managers only understand the language of money.
* You're a white-hat honest hacker, and all you want is for the internet to be a safer place. You decide to report the vulnerability to the company. Unfortunately, after you sent the email to their engineering team, they told you that the security hole you found isn't critical and refuse to award you a bounty. The rest of the emails go unanswered. You try sending emails to some other departments, including customer support, sales, and legal. No response. 2 months after that, when you're taking a dump on the toilet, federal agents burst into your apartment, knock you down and arrest you without even giving you the chance to wipe your ass. You're charged with industrial espionage, breach of security, and conspiracy to defraud. It turns out that someone did read your emails, checked out the logs, found traces of you researching the security hole. Your defense that you were trying to help is summarily dismissed and you rot in jail.
* You think most people are too serious and need to relax. You decide to have some fun. You download tons of embarrassing data from the company website, write them an untraceable email demanding 1000 BTC and public disclosure of your skills. You're pretty sure they will refuse your request, which they soon do. You troll the company by disclosing that they were hacked, and decide to sell the security hole to the highest bidder. You also sell chinks of data to random hackers and credit card scammers. You retire to a tropical island, drink martini and surf all day.
Also, pentesting sites without their consent is a poor choice to begin with, which is closely linked to why the "I was just trying to help" defense works so poorly.
Deciding to "have some fun" by exposing people's private information and profiting from that "fun" are pretty terribly hobbies.
How worried about this should I be? Are there plaintext passwords exposed, or do they just have a lot of properly salted hashes that aren't much use to an attacker?
pbkdf2_sha256$12000$zhMKabMgayvK$iniviUCcX9y2PYJcm0AoB3MhybRA1z2Cec1DZnLWxWc=
I do not know how much time it would take to bruteforce these. Can any experienced HNers weigh in?cipher/hash: pbkdf2_sha256
cost factor: 12000
salt: zhMKabMgayvK
hash: iniviUCcX9y2PYJcm0AoB3MhybRA1z2Cec1DZnLWxWc=
This exact technique (pretty much) is described here: http://exyr.org/2011/hashing-passwords/. It's a decent, secure way to hash passwords.
Cost factor of 12000 seems solid to me (depends on the hardware they're running on but I'd say brute forcing your way through that would be pretty impossible)
A PBKDF2 cost factor/iteration count of 12000 and 32-byte output means each candidate passphrase costs 12002 SHA256 blocks.
I can buy a crappy bitcoin miner which will do 2GH/s for about USD19.
Let's say we're going to use the Gawker leak as our dictionary. That's ~200,000 candidate passwords.
For a given user, I can therefore find their password (if it exists in the Gawker set) in 12002 * 200000 = 2.4GH SHA256 applications. That will take 1.2 seconds.
So for all 125 million eBay users, that's about 4 years. This work is trivially parallelisable, so buying more or faster hardware is brutally effective.
Note: there is obviously, and hopefully, a non-negligible probability that a user's password isn't in that set. Brute force of (say) the whole 8 printable-ASCII character password space would take longer but would be guaranteed to find to find about 50% (from Adobe leak) of user's passwords.
<algorithm>$<cost>$<salt>/<encrypted_password>
It's more than I expected from eBay, I think because of the likes of LinkedIn and their user credential leak, I expected bad habits from larger companies.Rainbow tables can't be used against the passwords, so each one will need to be computed individually to either find the result or a collision. That's likely why the seller is only asking for $1000.
Since these are salted and require 12000 iterations, cracking individual passwords will be quite time consuming. The preferred method in this case, though, is to go after low hanging fruit.
The way one would do this is to try something like the 500 most common passwords against all entries in the table. This won't take very long (compared to trying to brute force a bunch of individual passwords), and will probably yield a ton of passwords.
I think cracking difficulty depends on how many "iterations" they use though.
hash_func$iterations$salt$derived_key
One person estimated an 8-GPU cracking machine two years ago at about 539 billion hashes per minute. At 128k hashes for one password, you could make about 70,182 attempts per second.
But here[1] is a five-machine cluster from a year and a half ago with 25 GPUs. Its speed? 63 billion per second against SHA1. This results in 492,187 attempts per second. Assuming SHA256 is about 50% slower, this would be around 246,093 per second.
Some password dictionaries contain millions of words. But if your password is '0Password', it'll probably be cracked in a couple of seconds on modern hardware.
[1] http://arstechnica.com/security/2012/12/25-gpu-cluster-crack...
However, if you were targeting a specific user and they didn't use a particularly strong password, it's possible that you could brute force it.
EDIT: I stand corrected, see the reply by sp332 below.
Plaintext uniquely identifying information like Date of Birth was included, however.
Plus you already have your email publicly displayed here ... and i found some weird stuff about amateur ... xxx movies when i googled you T_T
Also, you're an idiot.
so.me.l.ongus.e.rname@gmail.com
Someone should make a gmail plugin for decoding directives this way.
I do this with almost every website as a way to segregate or block mail if needed. It's pretty eye opening to see what companies trade or sell your email addresses.
Kudos to to whoever moved quickly on this one. A fool and his money...
0.5 BTC here
"It is sometimes cited as the notional end of the Middle Ages by historians..."
there is surprisingly large amount of Asian-sounding and Middle-East-sounding names there. Not sure how the data was chosen, but I would expect more... white-sounding names.
(I'm Malaysian).
(by the way, I want to visit Singapore in the summer once I have my finals done. But that's beside the point.)
Likely the poster means person information. Name, date of birth, address, back up email, phone number should be encrypted. Even just using the users password as a key would be better then clear text.