09-22-2024 08:33 PM
I have discovered a privacy issue when logging into my eBay account. After entering my username, even without inputting the password, my name becomes visible, like 'Welcome, XXX.' Since usernames and store names are public, this reveals the real name of the store owner to anyone. Using this method, I learned that the owner of LoopMobileAU is Walter, jogr_580404's owner is Antony, and auzlandugg's owner is Xinhua. I believe this is a significant privacy concern.
09-22-2024 08:44 PM
Are these 'stores/people' someone you have purchased from? But, knowing who owns/runs a business is NOT a privacy thing; it is actually just the opposite and a law was passed to now NOT allow people to 'hide' behind xyz when doing business online.
09-22-2024 08:45 PM
If those are real sellers names then aren't you providing a public forum with those eBay members names and violating their privacy?
And if what you say is true then you would know what my name is right?
09-22-2024 08:55 PM
Are those users folks that have signed in to their accounts on the same computer you are using to see those welcome messages?
Your first name should only be visible to you, or to someone using the exact same device and browser you have used to sign in to eBay without erasing cookies in that browser.
If you try that using a different browser, or a private or incognito browser window, or another device that that user has not signed into before, you should not see that welcome message displayed until you have signed in completely including using the correct password for that account.
09-22-2024 09:28 PM - edited 09-22-2024 09:32 PM
@sungdn is correct -- there is a flaw. I stand corrected. I am able to recreate the issue with random usernames.
Apparently there is a security flaw -- if you enter the username and proceed to the page where the password can be entered, the first name of the user account does appear there even before the password has been entered -- and not as the result cookies or past history on that particular computer.
First names of registered users are discoverable by entering the username into the sign-in page and proceeding to the password page without entering the password. This is dangerous because eBay relies on providing the user's name as proof that a message is actually coming from eBay, and others should not be able to connect a username to a first name outside of a transaction.
09-22-2024 11:22 PM
Ebay needs to fix this right now. devon@ebay kyle@ebay elizabeth@ebay
09-24-2024 02:27 PM
devon@ebay kyle@ebay elizabeth@ebay
Bumping this issue
09-27-2024 08:30 AM - edited 09-27-2024 09:16 AM
@sungdn wrote:
I have discovered a privacy issue when logging into my eBay account. After entering my username, even without inputting the password, my name becomes visible, like 'Welcome, XXX.' Since usernames and store names are public, this reveals the real name of the store owner to anyone. Using this method, I learned that the owner of LoopMobileAU is Walter, jogr_580404's owner is Antony, and auzlandugg's owner is Xinhua. I believe this is a significant privacy concern.
Hey @sungdn and @refreshingdrink ! Thank you for sharing this and the Product team wanted to share that they are rolling out a fix that should be completed by the end of the day.
09-27-2024 09:20 AM - edited 09-27-2024 09:21 AM
This explains how some fake payment invoices are able to have a correct name on them.
ebay really dropped the security ball on this one.