Ebay "Change passwords"

Discussion in 'Off-Topic Discussion' started by Spruce, May 21, 2014.

  1. Spruce

    Spruce Glad to be back .....

    Joined:
    Apr 10, 2009
    Messages:
    8,765
    Gender:
    Male
    Ratings:
    +12,352
    Just been on the news that Ebay has been hacked , everyone been told to change passwords

    I also checked on Ebay and they are also advising to "change passwords" as soon a possible

    Spruce
     
    • Informative Informative x 1
    • pete

      pete Growing a bit of this and a bit of that....

      Joined:
      Jan 9, 2005
      Messages:
      50,489
      Gender:
      Male
      Occupation:
      Retired
      Location:
      Mid Kent
      Ratings:
      +92,082
      its a bit late aint it????
       
      • Agree Agree x 2
      • Scrungee

        Scrungee Well known for it

        Joined:
        Dec 5, 2010
        Messages:
        16,524
        Location:
        Central England on heavy clay soil
        Ratings:
        +28,997
        So that explains why ebayers from Syria have been beating me to all the bargains!
         
        • Funny Funny x 3
        • JWK

          JWK Gardener Staff Member

          Joined:
          Jun 3, 2008
          Messages:
          32,099
          Gender:
          Male
          Location:
          Surrey
          Ratings:
          +48,983
          I think eBay own Paypal so I thought it best to change my Paypal password at the same time.
           
        • Jiffy

          Jiffy The Match is on Fire

          Joined:
          Aug 25, 2011
          Messages:
          11,506
          Occupation:
          Pyro
          Location:
          Retired Next To The Bonfire in UK
          Ratings:
          +32,989
          I can't,i don't have any account :mute:
           
          • Funny Funny x 3
          • Kristen

            Kristen Under gardener

            Joined:
            Jul 22, 2006
            Messages:
            17,534
            Gender:
            Male
            Location:
            Suffolk, UK
            Ratings:
            +12,668
            I can't understand the need to change passwords. They can't, surely, be storing any passwords? Only poxy sites do that ...

            If in doubt, about the security of a site, ask for a "password reminder". If you get an email with your original password then the site has a weak password system, and your password is stored, somewhere, in plain text and is at risk from a hack-attack. It would be easy to say "avoid sites like that" but you probably still want to shop there ... You could have one "regular" password for all such sites (ones which don't store your credit card details) and then separate, different, passwords for all the ones that do (banks, paypal, amazon, etc.) Write the passwords on a piece of paper and stick it to your screen - I am being serious! - there was an article that said that the chance of your house being broken into AND the burglar being interested in your passwords is far less than the supplier's servers being hacked!!

            However, if the password reminder you get is a one-time-use random-letter password then the site is using a secure password system - so called "Salt and Hash". Basically they don't store your password at all, they put your password through some mangling mathematical algorithm and then store the result of that number. So when you login again they mangle the password you typed again, check against the mangled number they stored when you registered, and if they match you are in. If someone steals the mangled numbers file it is impossible to reverse engineer the passwords. (The Salt part is an additional trick to stop two people with the same mangled number actually having the same password, so you cannot guess one and then use that to access everyone else's account who also used "Password1" as their password!

            I'm sure everyone here is either nerdy enough to know what I am talking about, and not need a link to more info ... or is NOT nerdy enough to be interested!!

            Here's the links anyway :)

            http://en.wikipedia.org/wiki/Cryptographic_hash_function
            http://en.wikipedia.org/wiki/Salt_(cryptography)

            Anyway, be weary of any site that sends you your original password in any password-reminder email. Most especially if they actually store your credit card details (e.g. allow you to re-order without re-entering your card details)
             
            • Informative Informative x 2
            • Like Like x 1
            • Kristen

              Kristen Under gardener

              Joined:
              Jul 22, 2006
              Messages:
              17,534
              Gender:
              Male
              Location:
              Suffolk, UK
              Ratings:
              +12,668
              Here we go - today's Telegraph:

              "The database, which was compromised between late February and early March, included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth," said the company"

              Can't see why I need to change my password then.

              Plus ... the hack attack was 3 months ago ... either we needed to know much sooner, or there isn't a thread (I'm sure people are outraged, but their Name, Date of birth, etc. are easy for anyone to get, if they want them badly enough.
               
              • Useful Useful x 2
              • Informative Informative x 1
              • Madahhlia

                Madahhlia Total Gardener

                Joined:
                Mar 19, 2007
                Messages:
                3,678
                Gender:
                Female
                Location:
                Suburban paradise
                Ratings:
                +3,090
                So, shutting the stable door when the horse has emigrated to Mongolia if it so wished?

                I changed mine this morning, think I've forgotten it already.
                 
                • Funny Funny x 1
                • Kristen

                  Kristen Under gardener

                  Joined:
                  Jul 22, 2006
                  Messages:
                  17,534
                  Gender:
                  Male
                  Location:
                  Suffolk, UK
                  Ratings:
                  +12,668
                  I haven't had a password-change-request email. I just can;t see that a) it is needed b) it would make any difference. I don't believe eBay store their passwords in a way that would allow them to be stolen ... so if my Name, DoB, EMail etc. has been stolen changing my password will make no difference ... and all that info is available in public domain to anyone who wants it anyway.

                  Slow news day, or someone angry with eBay for some reason or other ...
                   
                  • Agree Agree x 3
                  • ARMANDII

                    ARMANDII Low Flying Administrator Staff Member

                    Joined:
                    Jan 12, 2019
                    Messages:
                    48,096
                    Gender:
                    Male
                    Ratings:
                    +100,838
                    I've had a password change request from E-Bay. And as usual it was nothing straightforward. You follow the link and leads into the change and then create, and confirm, a new password........so far, so good. Then you have to sign into E-Bay and find that it won't recognise your password that it accepted on the change page:gaah: There followed a page saying that if you were having trouble getting the system to accept a new password for your old account then you should re-register for a new account:wallbanging: Even the system was contrary as it actually recognised the previous change of password and so classed it as a old password which it wouldn't allow.......so that was another new password needed:wallbanging:
                     
                  • Madahhlia

                    Madahhlia Total Gardener

                    Joined:
                    Mar 19, 2007
                    Messages:
                    3,678
                    Gender:
                    Female
                    Location:
                    Suburban paradise
                    Ratings:
                    +3,090
                    Switch the blummin' thing off and go to bed, Our Mandy!
                     
                  • ARMANDII

                    ARMANDII Low Flying Administrator Staff Member

                    Joined:
                    Jan 12, 2019
                    Messages:
                    48,096
                    Gender:
                    Male
                    Ratings:
                    +100,838
                    Well, in the end I actually found myself on the "My E-Bay"page with a new account.......but I'm not sure which "new" password was accepted and worked:hate-shocked::dunno::scratch::heehee:..........but I'll take your advice and I'm off to :snooze:
                     
                  • Scrungee

                    Scrungee Well known for it

                    Joined:
                    Dec 5, 2010
                    Messages:
                    16,524
                    Location:
                    Central England on heavy clay soil
                    Ratings:
                    +28,997
                    What gets me is sites (where you can log in using your email address) insisting your password must be at least something like 20 characters long and contain a mixture of both lower & uppercase characters plus at least one number but if you forget it they simply send a new one to your email account (where the password might be the name of your pet rabbit) and there's loads of emails identifying the sites you deal with and can get new passwords from.
                     
                    • Like Like x 1
                    • Agree Agree x 1
                    • JWK

                      JWK Gardener Staff Member

                      Joined:
                      Jun 3, 2008
                      Messages:
                      32,099
                      Gender:
                      Male
                      Location:
                      Surrey
                      Ratings:
                      +48,983
                      Be very careful about any email with a link in it, especially asking for a password change - it could be phising (where you are taken to a fake site that gleans your information). Quoted from ebay themselves:

                      Same goes for any email from anyone else, don't trust any embedded link, at first sight they may look safe, hover over them and you might see some dodgy Romanian address, the blighters are all out to get us :mad:
                       
                      • Like Like x 1
                      • Agree Agree x 1
                      • JWK

                        JWK Gardener Staff Member

                        Joined:
                        Jun 3, 2008
                        Messages:
                        32,099
                        Gender:
                        Male
                        Location:
                        Surrey
                        Ratings:
                        +48,983
                        @ARMANDII - I am really concerned for you, it sounds like you have been taken to a fake site. Please log on normally to ebay (old account) and take it from there.
                         
                        • Agree Agree x 1
                        Loading...

                        Share This Page

                        1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
                          By continuing to use this site, you are consenting to our use of cookies.
                          Dismiss Notice