Re: ebay sends passwords in the clear

From: Andrew Bennett (abennettat_private)
Date: Sun Feb 20 2000 - 02:00:04 PST

  • Next message: Michal Krzysztofowicz: "Sun Internet Mail Server"

    At 11:03 AM 2/16/00 -0800, rfrommat_private:
    >I've been trying to get ebay to do something about this for a month and a
    >half, to no avail.  See http://avocado.dhs.org/ebpd/ for details, including an
    >ebay password sniffer.
    
    I noticed that ebay has a link on their Sign In feature page to sign in via
    SSL.  It's not the most obvious link.  An easy way to get there:
    
    - when prompted for your id/password, below the box, click the Sign In link
    - when prompted again for your id/password, below the box, click the 'here'
    link
    
    Of course, take note of the cookie that they will place on your
    computer.  You'll have to close your browser, or it will expire in 40
    minutes of inactivity, whichever comes first, according to the web page.
    
    Couple this with the 'my ebay' preferences as to what activities you want
    your password remembered, one might only have to enter their password once,
    during the SSL session where the cookie gets set.
    
    
    Andrew
    --
       Andrew Bennett
       abennettat_private
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:36:15 PDT