Arthur Posted May 21, 2014 Posted May 21, 2014 You may want to change your password. Source: Business Wire eBay Inc. said beginning later today it will be asking eBay users to change their passwords because of a cyberattack that compromised a database containing encrypted passwords and other non-financial data. After conducting extensive tests on its networks, the company said it has no evidence of the compromise resulting in unauthorized activity for eBay users, and no evidence of any unauthorized access to financial or credit card information, which is stored separately in encrypted formats. However, changing passwords is a best practice and will help enhance security for eBay users. Information security and customer data protection are of paramount importance to eBay Inc., and eBay regrets any inconvenience or concern that this password reset may cause our customers. We know our customers trust us with their information, and we take seriously our commitment to maintaining a safe, secure and trusted global marketplace. Cyberattackers compromised a small number of employee log-in credentials, allowing unauthorized access to eBay's corporate network, the company said. Working with law enforcement and leading security experts, the company is aggressively investigating the matter and applying the best forensics tools and practices to protect customers. The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. However, the database did not contain financial information or other confidential personal information. The company said that the compromised employee log-in credentials were first detected about two weeks ago. Extensive forensics subsequently identified the compromised eBay database, resulting in the company’s announcement today. The company said it has seen no indication of increased fraudulent account activity on eBay. The company also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users. PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted. Beginning later today, eBay users will be notified via email, site communications and other marketing channels to change their password. In addition to asking users to change their eBay password, the company said it also is encouraging any eBay user who utilized the same password on other sites to change those passwords, too. The same password should never be used across multiple sites or accounts. 1
sonofsanta Posted May 21, 2014 Posted May 21, 2014 "However, the database did not contain financial information or other confidential personal information." No, only my full name, date of birth and full home address. There's nothing can be done with that Another appropriate time to point out how marvellous https://lastpass.com/ is. 1
rush_tech Posted May 21, 2014 Posted May 21, 2014 Just changed mine! another lastpass user here very useful:D
Griff Posted May 21, 2014 Posted May 21, 2014 Lastpass never heard of it...just watched the video...I want to be like bob.
Garacesh Posted May 21, 2014 Posted May 21, 2014 (edited) I use Keepass.. Same sort of program, I assume. I'll be changing mine when I get home. The 'Auto-type' function is awesome. I don't even need to know what my passwords are. Also has the advantage of meaning I can't get on eBay/etc and buy stuff when I'm not on my home PC, which is nice. Not that I actually have a problem with that. Edited May 21, 2014 by Garacesh
sonofsanta Posted May 21, 2014 Posted May 21, 2014 I use Keepass.. Same sort of program, I assume. I'll be changing mine when I get home. The 'Auto-type' function is awesome. I don't even need to know what my passwords are. Also has the advantage of meaning I can't get on eBay/etc and buy stuff when I'm not on my home PC, which is nice. Not that I actually have a problem with that. We use KeePass at work, also marvellous. Works a bit better for the multiple-users-in-one-location scenario though (e.g. us lot in the office), where LastPass is a better fit for one-user-in-multiple-locations.
pete Posted May 21, 2014 Posted May 21, 2014 They didn't say when they discovered the breach. Does anyone know is this is "we've just noticed and are telling you now" or "we sat on the information for nearly two months and then decided to tell you"?
IrritableTech Posted May 21, 2014 Posted May 21, 2014 Agreed, password managers are the way to go these days. I'm a heavy Lastpass user with 2FA built in. $12 a year is nothing.
IrritableTech Posted May 21, 2014 Posted May 21, 2014 They didn't say when they discovered the breach. Does anyone know is this is "we've just noticed and are telling you now" or "we sat on the information for nearly two months and then decided to tell you"? There was a leak of this news story this morning... Paypal put up an announcement that ebay were asking users to change passwords before ebay did. Lots of speculation at that point. Data leaked late Feb early March... eBay Inc. To Ask eBay Users To Change Passwords | ebay inc
Garacesh Posted May 21, 2014 Posted May 21, 2014 (edited) We use KeePass at work, also marvellous. Works a bit better for the multiple-users-in-one-location scenario though (e.g. us lot in the office), where LastPass is a better fit for one-user-in-multiple-locations. How does LastPass benefit more from one-user-in-different-locations? Portable encrypted database, I'd assume? I just have Keepass on my machine at home. Google is synched to my phone, as it's an Android, and most of the other sites I use aren't really work sites anyway.. Reddit, Facebook, eBay, PayPal, etc. I've pretty much changed up everything since the HeartBleed bug, even sites that purportedly weren't affected. Edited May 21, 2014 by Garacesh
sonofsanta Posted May 21, 2014 Posted May 21, 2014 They didn't say when they discovered the breach. Does anyone know is this is "we've just noticed and are telling you now" or "we sat on the information for nearly two months and then decided to tell you"? "The database, which was compromised between late February and early March..." "The company said that the compromised employee log-in credentials were first detected about two weeks ago." So they've sat on it for a fortnight, with it going unnoticed for two months before that. As the BBC News story mentions, the real danger is that the personal information that was compromised can be used on password reset forms elsewhere. Luckily my eBay username is different from every other site - only because my usual choice was already taken when I signed up back in the day. 1
Garacesh Posted May 21, 2014 Posted May 21, 2014 Luckily my eBay username is different from every other site - only because my usual choice was already taken when I signed up back in the day. I pretty much use the same username everywhere. Except eBay and Steam. Then again, most of my accounts are videogame accounts, so most of the time my account 'name' is my e-mail address. eBay and Steam names are different, for intentional reasons
pete Posted May 21, 2014 Posted May 21, 2014 Dammit, I read the BBC article (which didn't mention the when), rather than RTFA linked from BusinessWire.
sonofsanta Posted May 21, 2014 Posted May 21, 2014 How does LastPass benefit more from one-user-in-different-locations? Portable encrypted database, I'd assume? I just have Keepass on my machine at home. Google is synched to my phone, as it's an Android, and most of the other sites I use aren't really work sites anyway.. Reddit, Facebook, eBay, PayPal, etc. I've pretty much changed up everything since the HeartBleed bug, even sites that purportedly weren't affected. LastPass is a website with browser extension - so I have the extension installed on my Firefox at work and at home (also available on Chrome), and can have it on my phone for $12 a year if I wish. If I'm somewhere without the extension, I can log into the website and get at my passwords - bit clunky, but works. There's various levels of security set up to protect the data, including local-only encryption. I've got mine set up with 2FA using Google Authenticator as well. HeartBleed: LastPass updated overnight to tell you not only which websites had been compromised, but also which ones hadn't updated yet, and therefore weren't worth changing your password on yet.
Garacesh Posted May 21, 2014 Posted May 21, 2014 Passwords stored externally? Colour me paranoid, but no thanks. I'd prefer to keep them locally on my machine.
Norphy Posted May 21, 2014 Posted May 21, 2014 I can see the attraction in services like LastPass and the like but I wonder how long it will be before we see a headline like LastPass password database stolen Everyone will be royally screwed then
sonofsanta Posted May 21, 2014 Posted May 21, 2014 (edited) Passwords stored externally? Colour me paranoid, but no thanks. I'd prefer to keep them locally on my machine. The passwords aren't stored externally - only an encrypted dump of them, with the decryption key stored on the device. They tell you repeatedly not to lose your master password, because if you do, you're stuffed - they've no way of getting to them. Still, no system is perfect short of memorising a unique password for every site, so whichever route you go (LastPass/KeePass) it's fundamentally weaker than that - as ever with security, you have to choose where on the spectrum of convenience <--> security you're happy. LastPass is plenty good enough for me, others prefer to be a bit further up the security end of things, others prefer to be closer to convenience ("my password is 'password' everywhere I go so I can never forget"). EDIT: A bit more on LastPass in this article. Edited May 21, 2014 by sonofsanta
jinnantonnixx Posted May 21, 2014 Posted May 21, 2014 Damn. I'm up to 'password7' already. 'password8' here we come. Where will it end? 1
Garacesh Posted May 21, 2014 Posted May 21, 2014 The passwords aren't stored externally - only an encrypted dump of them, with the decryption key stored on the device. They tell you repeatedly not to lose your master password, because if you do, you're stuffed - they've no way of getting to them. Still, no system is perfect short of memorising a unique password for every site, so whichever route you go (LastPass/KeePass) it's fundamentally weaker than that - as ever with security, you have to choose where on the spectrum of convenience <--> security you're happy. LastPass is plenty good enough for me, others prefer to be a bit further up the security end of things, others prefer to be closer to convenience ("my password is 'password' everywhere I go so I can never forget"). Very true, but Keepass works the same way, the database has a 'Master Password' which acts as the decryption key for the database. Difference is, the Keepass database is stored on my machine whereas LastPass is stored on the web. Sure, that's not infallible and it would be possible for a miscreant to access my machine and take my passwords, but chances are if that happened it would be a 'happy accident' as a result of other malware, rather than a targeted attack for specifically my credentials. Think how many people will be trying to crack into the LastPass databases..? Considerably more, I'd hypothesise.
sonofsanta Posted May 21, 2014 Posted May 21, 2014 Very true, but Keepass works the same way, the database has a 'Master Password' which acts as the decryption key for the database. Difference is, the Keepass database is stored on my machine whereas LastPass is stored on the web. Sure, that's not infallible and it would be possible for a miscreant to access my machine and take my passwords, but chances are if that happened it would be a 'happy accident' as a result of other malware, rather than a targeted attack for specifically my credentials. Think how many people will be trying to crack into the LastPass databases..? Considerably more, I'd hypothesise. Ah, that's where we differ - I have much more faith that LastPass know what they're doing in terms of security than I have faith in myself
Garacesh Posted May 21, 2014 Posted May 21, 2014 (edited) Ah, that's where we differ - I have much more faith that LastPass know what they're doing in terms of security than I have faith in myself Touché I guess I just see an online service as a bigger point of failure than my personal machine. Lots more people will be attacking LP than my PC, there's always 'disgruntled employees', spear phishing, physical device compromise, or even the physical servers being taken (which admittedly could happen to my machine, but is less likely, as LastPass would have much more 'value' due to the thousands of passwords it holds, rather than my 20 or so that are unique to me and might not really offer much use, besides eBay, PayPal and my bank, I guess.) Edited May 21, 2014 by Garacesh 1
Bananas Posted May 21, 2014 Posted May 21, 2014 "However, the database did not contain financial information or other confidential personal information." No, only my full name, date of birth and full home address. There's nothing can be done with that Another appropriate time to point out how marvellous https://lastpass.com/ is. How does that stop them getting your password when they compromise the database containing the customer data though? I've used Roboform for years because it does password management along with filling forms etc too, brilliant bit of kit
Edu-IT Posted May 21, 2014 Posted May 21, 2014 If users have rubbish password on their email, which they've used to register for LastPass, can they reset the password, go to the email address, click through to LastPass and get in to everything? Genuine question having not used LP.
unixman_again Posted May 21, 2014 Posted May 21, 2014 Damn. I'm up to 'password7' already. 'password8' here we come. Where will it end? You'll need to capitalise the P to conform to the usual password requirements of upper case, lower case and number or symbol. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now