Ina Steiner EcommerceBytes Blog
News and insight focusing on ecommerce.
by Ina Steiner, Editor of EcommerceBytes.com
Sun Dec 10 2017 16:24:07

eBay Privacy Breach Exposes Customer Names on Google

By: Ina Steiner

Sponsored Link

In what appears to be a major breach of customer privacy, eBay is exposing customers' real first and last names, as well as the items they've purchased, publicly on Google. 

While the idea that your real name is exposed in a product review you left for a benign product like clothing or books is disturbing enough, Google is also displaying eBay customer names for sensitive purchases such as medical diagnostic tests - including pregnancy, drug, and HIV home testing kits.

A reader who provided EcommerceBytes with the news tip told us, "As both an eBay seller as well as being a buyer who has left product reviews for item that I have purchased on eBay, this new revelation is very disturbing to me. Furthermore what really scared me is the fact that with very little effort on my part I was able to match the reviewers actual name with their anonymous eBay user ID, by opening both the eBay product page and the Google Shopping product page in separate windows and placing them side by side."

For every search we conducted, from cookbooks to medical test kits, all of the reviews on Google Shopping Product Pages that were provided by eBay.com displayed actual customer names and the date they left the review, while reviews from other online retailers, such as Target.com and Walmart.com displayed user IDs.

It's not likely that someone who purchased a medical diagnostic test on eBay name would be thrilled that their review might be read by family members, partners or employers. One buyer was clearly concerned about the privacy of his purchase, noting in his review of a test kit he'd purchased on eBay that he was pleased it had come in discrete packaging.

EcommerceBytes was also able to do some matching of real names and user names of product reviews on Google Shopping and on eBay; once we had the eBay user name, we could see what other reviews they left. If they also used their eBay account to sell items, we could see their location (usually city, state, and country).

It appears there is a flaw in the feed eBay provides to Google, and this not the first time that eBay has been accused of compromising users' privacy. In 2014, NYU researchers discovered that they could aggregate eBay buyers' purchases, and characterized it as a security breach - and that was when they had only the user names, not the actual names of buyers.

As part of the 2014 study, the researchers conducted a survey to gauge buyer expectations around privacy on the marketplace, they found nearly 39% preferred to make a sensitive or private purchase on eBay, "noting that they believed the site was a more discrete vendor than a physical store."

"Additionally, 38 percent of those surveyed believed that their purchase histories were visible to no one except them," the NYU researchers wrote. 

We can't overstate how troubling this breach of privacy is, and of all the developments that have caused users to be concerned about privacy over the years, this tops the list right next to eBay's massive data breach of 2014 when it forced 145 million users to change their passwords. 

We reached out to eBay and Google prior to publishing, a Google spokesperson said he would look into the matter. eBay as not yet responded.

Update (Mon Dec 11 2017 10:03:27): Google Masks Customer Names after Alerted to eBay Privacy Breach (link)

Update (Mon Dec 11 2017 19:46:04): Google Says eBay Is Working to Resolve Privacy Flaw (link)

Comments (32) | Leave Comment | Permalink
Readers Comments

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

This user has validated their user name. by: toolguy

Mon Dec 11 14:16:36 2017

You had a name not an eBay ID!

How would you know what city they were in?

eBay doesn't show ID's of buyers. . .

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

by: Whatever This user has validated their user name.

Mon Dec 11 14:48:38 2017

What's the big deal? China and Russia already know every stinking thing about everyone anyway - our privacy was lost years ago. They probably know what size grannie panties I wear

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

This user has validated their user name. by: LasVagueness

Mon Dec 11 19:44:37 2017

I'm surprised more readers are not up in arms over this egregious breach of privacy. I am currently on hold with eBay having been transferred FOUR times. Employees are having a hard time figuring out what department handles this kind of issue.

Ina, PLEASE let your loyal readers know if you find out how to remove reviews on your end.

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

This user has validated their user name. by: LasVagueness

Mon Dec 11 20:04:00 2017

The last employee I spoke with fully grasped the issue and pledged to pass this info along to get the breach resolved, however, he was not able to see the breach.

Are there any volunteers that can show us on this site an example so eBay can follow up on their end?  

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

This user has validated their user name. by: LasVagueness

Mon Dec 11 20:10:44 2017

Here is how to remove your reviews:

1) Hover your mouse over "Hi, your name" in the upper left-hand corner of eBay.

2) Click your eBay user ID

3) Near the bottom of the page will be your reviews. Click delete on all your reviews.

You're safe from Google's prying eyes.  

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

This user has validated their user name. by: Marie

Tue Dec 12 02:30:54 2017

@ LasVagueness

THANK YOU for that VERY useful information !!

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

by: Twiganne This user has validated their user name.

Tue Dec 12 10:42:00 2017

Please follow twitter feed #crookedvenues

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

This user has validated their user name. by: IDKwhoIare

Tue Dec 12 14:47:50 2017

I am surprised Google cared to do anything.  In order to leave a review on Google you have to provide your first & last name...no IDs allowed.  I do not review on Google specifically because of that requirement.

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

This user has validated their user name. by: LasVagueness

Tue Dec 12 15:52:13 2017

@Marie  You're the one I get most of my eBay tips from...glad I could finally reciprocate.  

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

by: Snapped This user has validated their user name.

Wed Dec 13 02:40:15 2017

That 'post comment' button - on any forum or venue - should be more accurately labeled as something akin to 'show the world'.  In fact, any act to 'share' anything 'on-line' is, and once posted shall forever be, accessible to someone, somewhere, sometime, not originally intended.  And were one truly concerned about 'privacy', a good suggestion to help retain it is to not post anything publicly about that private purchase.  

Regardless of any 'promise' for data protection made, internet anonymity has evolved to become a 21st C. oxymoron.  Beware any claims to the contrary, especially if made by, or via, eBay.  They've proven themselves a bit unreliable when it comes to appropriately managing any kind of data AND fulfilling promises of any kind of protection.  

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

This user has validated their user name. by: toolguy

Wed Dec 13 10:02:29 2017

@snapped

I'm not worried about ebay, it's Facebook & Google who I worry about!

Since I'm in the job market I've closed my Facebook account, but there is nothing I can do about Google. . .They know more about me then I know about myself!

Perminate Link for eBay Privacy Breach Exposes Customer Names on Google   eBay Privacy Breach Exposes Customer Names on Google

by: CNYC This user has validated their user name.

Wed Dec 13 20:54:14 2017

I am so sick and tired of the constant eBay F ups.  Their search sucks too.  I really tried to continue to support that site because there are a lot of really great long time sellers, but the site itself it a nightmare

Click to view more comments
1 2 


Login is required to post comments.
To sign in to leave a comment using your AB Verify User Name, fill in the form below. If you have not yet signed up for AB Verify, or if you'd like more information, go to the Registration Page
.

Login for AB Verify
Be sure and use your email address and password to log in.

 
Email:
Password:
 
 Forgot Your Password?
 Even though you are signed in with the AuctionBytes Blog, you will have to sign in to the EcommerceBytes blog. But you can sign in with your existing AB Verify info.