Skip to main content

Your questions answered on what to do following the hacking attack on eBay's database

Ebay's announcement that a database holding the personal details of users – potentially all 223 million worldwide – was hacked raises a number of serious questions. It's the biggest reported hack ever in terms of the number of people affected, but does not affect financial data, which is stored separately. Q: Do I need to change my eBaypassword? A:Yes. eBay is recommending this to all users. Q: But I just changed it a few weeks ago when all the Heartbleedstuff was happening. Do I really need to? A:eBay says that it discovered the hack about two weeks ago, and that it happened between "late February and early March". If you haven't changed your password since then, you should. Q: What data was stolen? A:eBays says that the database with users' customer names, encrypted password, email address, physical address, phone number and date of birth was breached. It hasn't said how much of that data was copied. It's best to assume that it all was. Q: Who was behind it? A:eBay hasn't said, and it's unlikely that any group would claim responsibility. But the fact that the hackers targeted eBay and its customer database suggests that they were commercially oriented, rather than an Anonymous-style "hacktivist" group. Q: What could someone do with that data? A:That varies from country to country, but enterprising villains could certainly use it for online identity theft. Q: Was any financial data stolen? A:eBay says not; PayPal, its payment arm, says it was not affected, and that all its information is encrypted. Q: Should I change my PayPal password? A:If you want to be ultra-cautious, yes, but make it different from your eBay one. Q: What's the biggest risk from this hack? A:The most obvious one is "phishing" emails pretending to be from eBay asking you to reset your password, but which direct you to a fake site that will steal your password. The problem is that eBay is going to be sending out lots of emails asking people to change their password. Normally, you can recognise a real eBay email because it contains your username in the subject line – which run-of-the-mill phishing attempts don't have. (Those tend to say something like "eBay user, change your password!" and should always be ignored.) But if hackers have got hold of a database with your email address and username (aka customer name), then they can format an email which will look just like the real thing – but lead you to a fake site that looks like eBay but will capture your login details. To avoid this, don't follow any links in emails that seem to come from eBay. Type the site's address into your browser. Advise your friends (and relatives) about this too: if eBay's username database has leaked to any extent, all those people are very vulnerable to phishing. Q: Do I have to change my "secret question", which is used if I can't remember my password? A:No. eBay says that this was stored separately. Q: What method was used to encrypt the passwords, and how hard will they be to decrypt? A:eBay hasn't yet answered our question on this. Internetcompanies use increasingly sophisticated methods to encrypt passwords; the idea is that your password should be transformed in a one-way process into a string of near-random characters. When you (or someone else) enters a password for the account, it undergoes the same processing, and the resulting strings of characters are compared. If they're the same, the password entry is accepted; if not, it's rejected. Q: Why did eBay wait two weeks before telling everyone of a break-in that happened in February? A:The company hasn't explained the timeline, but security breaches of this type typically take some time first to detect, then to determine their extent, and then to close against further hacks. It's only then that most companies announce they've been affected. Q: Will eBay be introducing two-factor authentication (where you have to enter a code from a mobile device or previously printed list in order to log in from a previously unused device)? A:We have asked, but so far haven't received an answer. The large email suppliers (Google, Microsoft, Yahoo, Apple) all offer "2FA" security, which ensures that even if someone steals your password they can't log in from a new device.

Comments

Popular posts from this blog

MOURNING THE ONLY PRINCIPAL I KNEW

By Dr.Paul Bundi Karau I arrived at Kanyakine High School on 18th February 1999 a small village boy. I had never been to a boarding school, and certainly this is the furthest from home I had ever gone. The boys who were assigned to escort me to Mungania dorm looked at my stunted height and loudly wondered how I would survive in Beast's school.  "Who is Beast?" I asked in bewilderment. "You will know." Musyoki answered curtly. It didn't take me long to know who Beast was. The following day, as the 10 o'clock tea was being served, I heard a commotion, with boys leaving their tea and running helter-skelter towards the classrooms.  I was a fresh mono, so I didn't know what was happening. I ran along the pavement, and came upon a mighty man, who appeared to be adjusting his trousers. He yanked his belt and thrust one whip towards me. I had encountered Beast himself. He was tall, imposing, burly and endowed with a thunderous voice that could re...

Political Tumbocrats

*Political Tumbocrats* A political tumbocrat is a person who hangs around elected leaders to satisfy her/his personal greed. Tumbocrats sees a leader as a demigod whom they worship. The r bootlickers and sycophants of the highest order. Their work is to defend leaders and cheat public that something is happening. A tumbocrat has no values or morals. A tumbocrat is not interested with common good but personal good. A tumbocrat has no vision but appetite for being near high table of power  and feeding on crumbs.   Tumbocrats are greatest obstacles to development in our country. They protect the corrupt and shield the bad governance in so far as they get something to fill their tumbos. They are good and articulate in arguments but they lack the moral authority because they don't value truth. Every political leader is surrounded by tumbocrats. They are the noise makers in social media and around leaders defending them. They peddle lies en create propagandas . They confuse the publ...