Blog: Open letter to eBayThis is a (pending) story which happened recently with the German eBay customer service. Dear eBay, the way you present the login window under certain circumstances is bad practise, I often get long URLs (this one is 320 chars) like https://signin.ebay.de/ws/eBayISAPI.dll?SignIn&co_partnerId=2&pUserId=&siteid=77&pageType=1883&pa1=&i1=&bshowgif=&UsingSSL=0&ru=http%3A%2F%2Fmy.ebay.de%2Fws%2FeBayISAPI.dll%3FMyeBay&pp=&pa2=&errmsg=&runame=&ruparams=&ruproduct=&sid=&favoritenav=&confirm=&ebxPageType=&existingEmail=&isCheckout=&migrateVisitor=1&fromwl= There are two points to this. First Usability: A normal user is supossed to see a clearly recognisable URL in the location bar in the browser. In the age of phising it is always demanded from him/her to check whether he/she is connected to the right site. He/She cannot do that if the URL is 320 chars long. You just overstrain normal users here. Secondly Security: Even I as a person working more than ten years in professional IT security always get confused whether this is the site I really want to deliver my credentials to. E.g. a "@"-sign — not neccessarily ASCII encoded — somewhere in the non-visible part of location bar of my browser would render the visible first — i.e. leading — part as a userinfo component [1,2,3]. This is known as a semantic attack since more than six years and also used by phishers since then. The leading "https" doesn't give this long URL not neccessarily/obviously something like a blessing. Please let me know if and when you intend to fix this. (Dirk Wetter, 12/12/2007) [1]: Richard Siedzik @ GIAC: http://www.giac.org/certified_professionals/practicals/gsec/0650.php [2]: Bruce Schneier: http://www.schneier.com/crypto-gram-0102.html#7 [3]: RFC 3986, paragraph 7.6, RFC 1738, paragraph 3.1
