Advertisement
Promo

Online business Toolkit

EBay closes password option to plug hole

Troy Wolverton CNet

Published: 03 Apr 2002 10:56 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

EBay disabled a password function on its site Tuesday to close a "very serious" security hole that could allow hackers access to users' accounts, a spokesman said.

EBay disabled the "Change Your Password" function in an effort to close the vulnerability, eBay spokesman Kevin Pursglove said Tuesday. That feature will remain disabled until eBay can put a fix in place, he said.

"We don't see (the vulnerability) existing in other features," and no customers have complained, Pursglove said. "From what we can tell right now, we have not seen anybody's account compromised in any way."

Greg Shipley, chief technology officer of security consulting firm Neohapsis, blamed the problem on a "design failure" in eBay's authentication system.

"It's just a bad design. It's kind of disappointing coming from a company the size of eBay," Shipley said.

The vulnerability, discovered by a Canadian security expert and brought to eBay's attention late last week, would allow a person who has the user ID of an account to go in through eBay's "Change Your Password" feature, change a user's password and gain access to the account.

Pursglove said people who potentially exploited the vulnerability would not have been able to see credit card numbers.

"What they can see is the credit card transaction history of a user," Pursglove said, calling the problem "very serious." The credit card numbers, he said, are behind a separate firewall.

While eBay has disabled access to that security hole, the company is still working on a fix for an earlier problem involving so-called dictionary attacks. These attacks utilize a bot, or an automated program, to find passwords for known eBay user IDs by combing though a list of common passwords and a dictionary of words.

EBay has said that the number of accounts compromised by dictionary attacks has been no more than the "low triple digits." The company has also said that less than one one-hundredth of 1 percent of its listings end in confirmed cases of fraud.

"We're working on it right now," Pursglove said, adding that changes to the login procedure would be in place in four to six weeks. "We think it will make it harder for these (attacks) to work."

Security experts have criticised the company's log-in system, saying that because it generally transmits passwords and account information in plain text, it is vulnerable to "packet sniffers," programs that can monitor the transmission of data between computers.

EBay has also repeatedly warned members in recent months about another, more low-tech scam: fraudulent e-mail messages that purport to come from the company but link to bogus Web sites that ask for their passwords or other account information.


For everything Internet-related, from the latest legal and policy-related news, to domain name updates, see ZDNet UK's Internet News Section.

Have your say instantly, and see what others have said. Go to the Telecoms forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
26 out of 61 people found this useful


Company/Topic Alerts

Create a new alert from the list below:



Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters