So today's little chore, forced on basically the entire internet, was changing my eBay password. eBay put out a notice this morning saying they got broken into sometime between February and March, and that whoever did it walked off with a database of names, addresses, phone numbers, birth dates, and encrypted passwords for something like 145 million active users. They're being careful to say financial info (your actual card numbers, PayPal stuff) wasn't stored in that database and wasn't touched, which is something, I guess. But "we lost basically your entire home address and a hashed password" isn't exactly nothing either.
I found out around 11am when a coworker forwarded me the eBay email with the subject line "we cant believe we have to send this" (not an actual quote, but that's the energy). So there went twenty minutes of my lunch break, digging through eBay's password reset flow, which is somehow still clunky in 2014. You'd think a company this size could make "change your password" a two-click thing. Instead I got bounced to a page that made me answer a security question I set up probably in 2007, something about my first pet, and I genuinely could not remember if I'd answered honestly or just typed "Rex" because it seemed like a normal pet name to have.
The part that actually annoyed me was realizing my old eBay password was one I'd reused on at least two other sites. I'm not proud of that. I know better, I've read the same lectures everyone else has about unique passwords for everything, and I still did the lazy thing because eBay is one of those accounts you set up once and mostly forget exists until you need to buy something oddly specific. In my case that was a replacement power supply for an old NES a couple years back, and, this is the tangent, a genuinely cursed purchase before that of a "vintage" Power Glove that arrived smelling like a basement and didn't actually fit my hand. Eleven dollars, non-refundable, one of those eBay purchases you make at midnight and regret by breakfast.
Anyway. New password is set, it's unique to eBay now, and I wrote it down on paper like an animal because I still haven't gotten around to setting up a proper password manager, even though I keep telling myself I will. LastPass has been sitting in a browser tab I haven't closed for probably three weeks now. That's a me problem, not an eBay problem.
What bugs me more than the breach itself, honestly, is how long it apparently sat undiscovered. Months between the actual break-in and today's notice is a long window for a company that size to not notice something was wrong. I don't think anyone expects eBay to be bulletproof, but there's a difference between "we got hit and caught it fast" and "we got hit and found out well after the fact." The second one just doesn't inspire much confidence, no matter how the press release is worded.
Small unrelated thing from yesterday that I wanted to mention: Microsoft did their Surface Pro 3 event in New York, and Panos Panay was up there doing his usual very-earnest presentation style, comparing it to a MacBook Air the entire time. Bigger screen than the old Surface Pro, thinner, starts at 799 dollars for the base model, and it comes with that kickstand that apparently now opens to any angle instead of the two fixed positions the older ones had. I watched some of the livestream while eating breakfast and I'll admit I'm sort of tempted, not enough to actually buy one, but enough that I read the full spec sheet twice. The Type Cover is still sold separately, which feels like it's always going to be the case with these things, and always bugs me a little, since it's not exactly optional if you want to use it like a laptop.
Between that and the eBay thing, it's been a reminder-heavy week for two totally different reasons: one company reminding me their hardware is nice, the other reminding me my password hygiene is embarrassing. I know which lesson I'll actually apply.