Blog: Open letter to eBay

This is a (pending) story which happened recently with the German eBay customer service.

Dear eBay,

the way you present the login window under certain circumstances is bad practise, I often get long URLs (this one is 320 chars) like


There are two points to this.

First Usability: A normal user is supossed to see a clearly recognisable URL in the location bar in the browser. In the age of phising it is always demanded from him/her to check whether he/she is connected to the right site. He/She cannot do that if the URL is 320 chars long. You just overstrain normal users here.

Secondly Security: Even I as a person working more than ten years in professional IT security always get confused whether this is the site I really want to deliver my credentials to. E.g. a "@"-sign — not neccessarily ASCII encoded — somewhere in the non-visible part of location bar of my browser would render the visible first — i.e. leading — part as a userinfo component [1,2,3]. This is known as a semantic attack since more than six years and also used by phishers since then. The leading "https" doesn't give this long URL not neccessarily/obviously something like a blessing.

Please let me know if and when you intend to fix this. (Dirk Wetter, 12/12/2007)

First Reply (12/13/2007): The first answer was typically due to past experience I had with German eBay customer service: It looks like the person replying had not understand the content of the request. With copy-and-pasted paragraphs I was told to write this e-mail from a valid eBay-registered e-mail address.
 I replied that security problems should not be a matter whether one has an eBay account or not. Please escalate to management.

Second Reply (12/14/2007): What came now stunned me. First I was told to not send my concerns as an attachement since the filter eBay customer service uses strips attachements off. So far so good, but I didn't attach my concern as an attachment, it was inline text. I was wondering now for the second time how cursory eBay's customer service reads e-mails. The attachments in question were a cryptographic signature and a vcard.
  Secondly: I got two e-mails asking for feedback on the quality of the reply. More precisely: The e-mails were multipart, first part was barely readable text/plain-encoded (this is exactly how a plain-text mailreader displays it, IDs modified):

The second part was text/html encoded including remote pictures.
 So again, this is where usabilty and privacy and security of eBay could do much better.

