Members
  • Total Members: 14176
  • Latest: toxxxa
Stats
  • Total Posts: 42943
  • Total Topics: 16142
  • Online Today: 4292
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)









Author Topic: eBay hacked, 145 million "encrypted" user account passwords stolen!  (Read 2325 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7528
  • KARMA: 322
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum


Confusion reigns over whether or not the 145 million "encrypted" user account passwords swiped from eBay can be practically cracked by crooks.

A day has passed since the online tat bazaar admitted its customer database was hacked back in February, and the method of encryption is still not known: http://www.ebayinc.com/in_the_news/story/ebay-inc-ask-ebay-users-change-passwords
We do what wasn't encrypted: millions of people's names, home addresses, dates of birth, phone numbers and email addresses, which were stored in the ransacked database alongside the passwords.

Spokeswoman Amanda Miller broke radio silence to say eBay.com ran passwords through some sort of mystery one-way encryption, aka hashing: http://uk.reuters.com/article/2014/05/21/us-ebay-password-idUKBREA4K0B420140521

She insisted the website used "sophisticated, proprietary hashing and salting technology to protect the passwords". Users have been told to change their login credentials as a precaution.

Computer security experts have criticised the web souk for its handling of the almighty blunder, and want more technical details from the website.

"The use of proprietary algorithms is not only extremely unlikely, but also ill advised: there's no wider scrutiny of effectiveness," Rik Ferguson, veep of security research at Trend Micro, told The Register: http://countermeasures.trendmicro.eu/oy-vey-ebay-five-questions-for-you

"eBay used proprietary implementations of an algorithm? Perhaps – but not proprietary algorithms. So take that [eBay] quote with a pinch of salt, no pun intended."

eBay admitted on Wednesday that miscreants broke into its confidential database about two months ago after somehow infiltrating its corporate network, possibly by obtaining access to staff-level accounts. While the passwords were "encrypted", the millions of personal records lifted were now – leading some to question why this information wasn't stored in an encrypted form: http://bhconsulting.ie/securitywatch/?p=2180

Financial details, such as credit card numbers, were not exposed – eBay claims – but the leaked data is a treasure trove for identity thieves.

The internet auction house has not responded to our request to identify the hashing function used. The official @AskeBay Twitter profile did tell one user that it stores "encrypted passwords that have been hashed and salted": https://twitter.com/AskeBay/status/469338371886546944

eBay customers should be wary of convincing phishing emails and other messages that include their leaked personal information to look legit – and be wary of emails posing as password-reset requests. These malicious missives redirect users to websites that masquerade as eBay.com and harvest victims' usernames and passwords.

El Reg has heard crims have already started phishing for marks' logins along these lines.

(ElReg)

Bootnote

Passwords should be hashed, rather than encrypted in a reversible manner, as explained in the above video by infosec blogger Javvad Malik: http://youtu.be//FYfMZx2hy_8

Samker's Computer Forum - SCforum.info


devnullius

  • SCF VIP Member
  • *****
  • Posts: 3614
  • KARMA: 157
  • Gender: Female
    • SCForum.info
I'm really really really disappointed at ebay  >:(
More information about bitcoin, altcoin & crypto in general? GO TO  j.gs/7385484/btc

Cuisvis hominis est errare, nullius nisi insipientis in errore persevare... So why not get the real SCForum employees to help YOUR troubled computer!!! SCF Remote PC Assist http://goo.gl/n1ONa9

Samker's Computer Forum - SCforum.info


 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising