With eBay's response to date, there is very little information that allows users to better evaluate a service in which they have invested trust. Questions of trust and safety are natural for people to raise in a variety of everyday circumstances. For example, when people get on a plane or take medicine its natural for them to be concerned about the safety. In eBay's case, eBay is a market place and a financial services company so it's reasonable to ask for high standards and to question what their security practices are like.
One would also think that eBay would have a strong interest in developing trust between themselves and their customers, but there is little evidence of that recognition. Specifically, the going corporate standard for a major security breach among eBay's corporate peers is (a) full and (b) immediate disclosure.
By (a) full, note, that eBay has come our with a very murky statement about exactly what happened. There is nothing more substantial than "you should change your password but we don't think there is any danger". Well, was there general database access? Did attackers had access to production servers? All of them? Is there any impartial 3rd party audit that stands behind eBays security statements? Further, as part of a full disclose, it's good procedure to disclose how passwords were stored if they expect to establish trust. They have had 2 weeks at least to prepare their statements and they can't do better than the useless "passwords were encrypted"?. There are really only two possibilities here:
(1) passwords were combined with a random salt and then hashed or
(2) they were morons.
And right now given their public statement it looks like (2).
By (b) immediate, note, its not unreasonable to expect that a certain percentage of eBay's users use the same username / password for both their eBay and their PayPal accounts. So for a couple of weeks now eBay has been aware of a potential financial danger to their customers and they have been sitting on the problem. Fail.
Security breaches happen to everyone. There is no faulting eBay there. The fault is with all aspects of their response. They have had a major security breach and they have not responded with a proportional disclosure. And that implies that security isn't their largest company problem.
There is fundamental concept in economics called comparative advantage, which implies that everyone can provide value to society making both themselves and everyone else better off in the process. So theory would imply that it is not a big problem.
Leaving theory and moving to the real world, Note that in the past agricultural jobs were the focal point of the economy and people were very worried about new plant technologies and large scale production. They worried - 'What are people going to do when we don't need farmers?' For the past 30 years or so the economy has been losing manufacturing jobs to low cost countries and automation. All during that process and even today people have asked, what people are going to do when all the 'good' manufacturing jobs are gone? In both cases the jobs are gone and never coming back and it also hasn't been a problem.
So just like the ordinary people that didn't become farmers and the ordinary people who didn't become assembly line workers are, today, contributing to society; theory and practice suggest that ordinary people that don't become technologists will also, in the future, be contributing to society.
The password hash has always been computed on the first n < 16 characters of the plain text password. What I suspect is going on now though, is that Hotmail is transitioning to accepting arbitrarily sized, plain text passwords. Before Hotmail can change the code though, they need to get the current users used to entering the <= 16 characters of their 'actual' plain text password. If they just change the code, everyone who has a > 16 character password will find they cant log in. and chaos will ensue.
HP has been cutting their workforce for a long time, at least since the Hurd days. Back then I suspect cuts were made based just on the numbers. Some people were expensive and I saw a lot of very capable people get let go. Eventually it became hard to find capable people and now, many years later, I suspect continued cuts wont matter. The good engineers that would have made their next generation of products were disposed of and wont go back. The good engineers of the future aren't being drawn to careers at HP. And the current management is getting theirs, while there is still momentum in the system. HP's time is past.
I see this as just publicity piece for Seattle. The cities, here and abroad, that advertise themselves as the next Silicon Valley are a dime a dozen. They’re looking to create buzz and interest among possible investors. The primary information for investors here -- those people, who want to make Seattle the next Silicon Valley, lack imagination.
One would also think that eBay would have a strong interest in developing trust between themselves and their customers, but there is little evidence of that recognition. Specifically, the going corporate standard for a major security breach among eBay's corporate peers is (a) full and (b) immediate disclosure.
By (a) full, note, that eBay has come our with a very murky statement about exactly what happened. There is nothing more substantial than "you should change your password but we don't think there is any danger". Well, was there general database access? Did attackers had access to production servers? All of them? Is there any impartial 3rd party audit that stands behind eBays security statements? Further, as part of a full disclose, it's good procedure to disclose how passwords were stored if they expect to establish trust. They have had 2 weeks at least to prepare their statements and they can't do better than the useless "passwords were encrypted"?. There are really only two possibilities here: (1) passwords were combined with a random salt and then hashed or (2) they were morons. And right now given their public statement it looks like (2).
By (b) immediate, note, its not unreasonable to expect that a certain percentage of eBay's users use the same username / password for both their eBay and their PayPal accounts. So for a couple of weeks now eBay has been aware of a potential financial danger to their customers and they have been sitting on the problem. Fail.
Security breaches happen to everyone. There is no faulting eBay there. The fault is with all aspects of their response. They have had a major security breach and they have not responded with a proportional disclosure. And that implies that security isn't their largest company problem.