Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

7 Facts: eBay Fumbles Password Reset Warning

Online auction site criticized for notification misfire, failing to make password resets mandatory.

expire all users' passwords so they had to be reset. "eBay should programmatically force a reset of all passwords because just asking nicely will be ignored by too many," says TK Keanini, CTO of Lancope, in an emailed statement. "They also should offer a two-factor authentication method as others have done. All of these things help raise the cost to attackers."

The need to force password resets is reinforced by the results of a new survey conducted by antivirus firm Avast. "Only 40% of the respondents who were aware of Heartbleed said they had actually changed their passwords," according to an Avast blog post about the survey, which was released this week. "This number closely matches Pew's Heartbleed report which found that 39% of Internet users have changed their passwords or canceled accounts."

If the Heartbleed password-change rate holds true for eBay's user base, that would mean, of the 145 million people whose encrypted password data was reportedly stolen, 87 million would still be vulnerable to having their accounts compromised if attackers successfully decrypt the stolen passwords.

6. Expect new two-factor authentication options
People who want better eBay site security can tap two-factor authentication, in the form of a PayPal Security Key (as the name implies, it also works for PayPal), which is a credit-card-sized device that generates random, temporary security codes that are used as a second factor together with a password, for authentication.

But the card will cost you a one-time fee of $30. "There's no monthly service fee or additional cost," according to eBay. "Replacement keys are the same price."

Alternately, the PayPal Security Key can be used as a free service via a mobile phone, with the one-time codes being sent via SMS, for example, as sites such as Dropbox and Twitter also do.

Going forward, it's likely that eBay might add mobile apps to its list of two-factor authentication options. In its security advisory, for example, eBay previewed unspecified, new possibilities, saying that "we are looking at other ways to strengthen security on eBay" and noting that "in the coming days and weeks we may be introducing new security features."

7. Breach lesson: Employ password managers, or else
Tapping two-factor authentication, where available -- and when it works well -- is an excellent security step. But the approach still relies on the strength of your password, and no password is ever completely safe.

Accordingly, people should never reuse their passwords. That way, a breach at a site such as eBay (which, although it enjoys an excellent security reputation, was still hacked) won't allow attackers to reuse stolen passwords on other sites. "Each account, especially accounts containing personal information and credit card details, should have its own password," says Ondrej Vlcek, COO at Avast, in an email. "In a situation like this you really don't want your PayPal and eBay accounts to have the same passwords."

Practically speaking, the only way to securely track a large amount of online account details and related access credentials is to use a password manager. While some people worry that storing all of the sensitive information in one location will create a single point of failure, numerous information security experts argue that because password managers can themselves be secured with a complex password, the benefits of being able to maintain unique, strong passwords for every online account you use far outweigh any potential security downsides.

With the rise of mobile devices and synchronization capabilities, furthermore, people can keep secure copies of their passwords on their smartphones, tablets, PCs, or even  on secure websites, for easy retrieval no matter where they are.

Mathew Schwartz served as the InformationWeek information security reporter from 2010 until mid-2014. View Full Bio

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Bprince
50%
50%
Bprince,
User Rank: Ninja
5/30/2014 | 12:32:00 AM
Notification
I find the notification issues raised here troubling. The safest thing to do would be to do a forced reset, and to make the process for changing user passwords as simple as possible.

BP
dan.euritt
50%
50%
dan.euritt,
User Rank: Apprentice
5/25/2014 | 12:51:13 AM
Re: Ebay password change
I changed my Ebay password, but I'm still getting the reminder to change it. I guess that leaving the notice up is the easiest way to reach everyone.
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
5/22/2014 | 1:19:58 PM
Time for Nok Nok Labs?
Not to be flippant, but with Samsung and PayPal turning to Nok Nok Labs, perhaps eBay could follow their lead. Dark Readings has covered Nok Nok Labs many times and I thought this was a nice nutshell: http://www.darkreading.com/risk/nok-nok-labs-delivers-on-vision-for-modern-authentication/d/d-id/1141317?

Their S3 Suite consists of:

-- The NNL(TM) Multifactor Authentication Server (MFAS), which provides a unified, flexible authentication infrastructure that enables user-friendly strong authentication for any device, any authenticator and any application.

-- The NNL(TM) Multifactor Authentication Client (MFAC) Mobile Edition with support for Android and iOS devices, which enables users to authenticate to any application using the existing security capabilities of their mobile devices. Also includes the Mobile App SDK and Authenticator Specific Module (ASM) SDK.

-- The NNL(TM) Multifactor Authentication Client (MFAC) Desktop Edition, with support for Windows 7 and Windows 8, provides user-friendly strong authentication to any application by unleashing the existing security capabilities of billions of desktops and mobile devices.

Call me crazy, but any site dealing with my money had better be securing their infrastructure at a minimum of this level of authentication.
Alison_Diana
50%
50%
Alison_Diana,
User Rank: Moderator
5/22/2014 | 1:19:40 PM
Re: PayPal
Right there with you, Lorna! That was my first question too -- and despite eBay's protestations to the contrary, I'd recommend changing that PayPal password.
Lorna Garey
100%
0%
Lorna Garey,
User Rank: Ninja
5/22/2014 | 11:28:02 AM
PayPal
My immediate thought was, is PayPal affected? I mean, so maybe someone logs in as me and bids on and wins something on eBay. That's bad. Using my PayPal to pay for it?Much, much worse. Nice to hear that "PayPal data is stored separately on a secure network, and all PayPal financial information is encrypted." Would be nicer if that were independently confirmed.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-12512
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting
CVE-2020-12513
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
CVE-2020-12514
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd
CVE-2020-12525
PUBLISHED: 2021-01-22
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
CVE-2020-12511
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.