ebay, WTF?
Scooby Regular
iTrader: (6)
Joined: Sep 2004
Posts: 14,661
Likes: 5
From: On a small Island near France
Things like this make me laugh....... working in IT - users/customers never want to change their passwords, keep the same password for everything and sometimes make them way too simple........... they are then the first to moan when their accounts get hacked.
Ebay notified you to do something. Don't worry so much about why this, why that, just do what they ask, your account is secure again and move on in life
Ebay notified you to do something. Don't worry so much about why this, why that, just do what they ask, your account is secure again and move on in life

Just don't suggest his actions are turd like .. he doesn't appear to like that
Had exactly the same with my Facebook on Thursday. I just changed my password slightly and signed back in.
Simple.
If it happens again I'll just change back to my old password.
Simple.
If it happens again I'll just change back to my old password.
Scooby Regular
iTrader: (6)
Joined: Sep 2004
Posts: 14,661
Likes: 5
From: On a small Island near France
Lots of people do that too .. it's crazy, why risk it? if someone has your password, chances are it's part of a big list and will likely be used for bruteforce on multiple sites. Changing it back puts you at risk. Add a number, a full-stop, add a capital, unless someone is targeting you specifically they'll just move on when it fails.
Lots of people do that too .. it's crazy, why risk it? if someone has your password, chances are it's part of a big list and will likely be used for bruteforce on multiple sites. Changing it back puts you at risk. Add a number, a full-stop, add a capital, unless someone is targeting you specifically they'll just move on when it fails.
Scooby Regular
iTrader: (6)
Joined: Sep 2004
Posts: 14,661
Likes: 5
From: On a small Island near France
I'd be over the moon if a company was that proactive with my details.
Scooby Regular
iTrader: (6)
Joined: Sep 2004
Posts: 14,661
Likes: 5
From: On a small Island near France
No, there is a paid subscription for IT security professionals that gives you details on recently posted Hacks, etc. If you follow the bread crumb you can normally find the lists online.
So we ran the usernames and passwords on said list (from a forum I think) against our LDAPs, those that authenticated where changed and the customers informed. Of course we didn't have the passwords to tell them the new ones, so they had to perform an action to recover accounts.
Difficult to share the reasoning as we don't want to highlight any potential hacker wannabes to this kind of data.
Thread
Thread Starter
Forum
Replies
Last Post
scoober101
General Technical
4
May 6, 2016 11:21 AM







