cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

A Privacy Issue

I have discovered a privacy issue when logging into my eBay account. After entering my username, even without inputting the password, my name becomes visible, like 'Welcome, XXX.' Since usernames and store names are public, this reveals the real name of the store owner to anyone. Using this method, I learned that the owner of LoopMobileAU is Walter, jogr_580404's owner is Antony, and auzlandugg's owner is Xinhua. I believe this is a significant privacy concern.

Message 1 of 9
latest reply
8 REPLIES 8

A Privacy Issue

Are these 'stores/people' someone you have purchased from? But, knowing who owns/runs a business is NOT a privacy thing; it is actually just the opposite and a law was passed to now NOT allow people to 'hide' behind xyz when doing business online. 

Message 2 of 9
latest reply

A Privacy Issue

If those are real sellers names then aren't you providing a public forum with those eBay members names and violating their privacy? 
And if what you say is true then you would know what my name is right? 

Message 3 of 9
latest reply

A Privacy Issue

Are those users folks that have signed in to their accounts on the same computer you are using to see those welcome messages?

 

Your first name should only be visible to you, or to someone using the exact same device and browser you have used to sign in to eBay without erasing cookies in that browser.

 

If you try that using a different browser, or a private or incognito browser window, or another device that that user has not signed into before, you should not see that welcome message displayed until you have signed in completely including using the correct password for that account.

 

 

Message 4 of 9
latest reply

A Privacy Issue

@sungdn  is correct -- there is a flaw. I stand corrected. I am able to recreate the issue with random usernames.

 

Apparently there is a security flaw -- if you enter the username and proceed to the page where the password can be entered, the first name of the user account does appear there even before the password has been entered -- and not as the result cookies or past history on that particular computer.

 

devon@ebay 

 

First names of registered users are discoverable by entering the username into the sign-in page and proceeding to the password page without entering the password. This is dangerous because eBay relies on providing the user's name as proof that a message is actually coming from eBay, and others should not be able to connect a username to a first name outside of a transaction.

Message 5 of 9
latest reply

A Privacy Issue

 Ebay needs to fix this right now. devon@ebay kyle@ebay elizabeth@ebay 

Message 6 of 9
latest reply

A Privacy Issue

devon@ebay kyle@ebay elizabeth@ebay 

Bumping this issue

Message 7 of 9
latest reply

A Privacy Issue


@sungdn wrote:

I have discovered a privacy issue when logging into my eBay account. After entering my username, even without inputting the password, my name becomes visible, like 'Welcome, XXX.' Since usernames and store names are public, this reveals the real name of the store owner to anyone. Using this method, I learned that the owner of LoopMobileAU is Walter, jogr_580404's owner is Antony, and auzlandugg's owner is Xinhua. I believe this is a significant privacy concern.


Hey @sungdn and @refreshingdrink ! Thank you for sharing this and the Product team wanted to share that they are rolling out a fix that should be completed by the end of the day. 

Devon,
eBay
Message 8 of 9
latest reply

A Privacy Issue

This explains how some fake payment invoices are able to have a correct name on them.

 

ebay really dropped the security ball on this one.

Message 9 of 9
latest reply