As I understood the article, the brute force attack used a generic password and then combined it with harvested Ebay usernames, then submitted these to Ebay's database to see if it got a valid response. The login attempts would only try each account a limited number of times with a limited amount of passwords, lest Ebay's software notify administrators of a massive amount of erroneous logins.
What that means in non-technical speak is that as long as you use a fairly complex password, then this particular technique will not work on you. An example, gleaned from one of my past passwords:
G05t33!eRs
Might seem hard to remember, until you realize it spells out Go Steelers...
The main danger to online account info is, always has been, and most likely always will be, key loggers, and other malware that tracks key strokes. A secondary danger is phishing, the practice of setting up a fake web page that looks exactly like a real commercial web page, and then inducing the user to input their real password into this fake site.
I think the majority of people get their account info stolen by doing one of the following things:
1. Logging onto a commercial web site from a public computer. I would NEVER use a computer at an internet cafe, if I had ANY other choice. Even if you log onto Yahoo ONLY, if a person gets your public email info, they can usually gain access to other sites hrough it.
2. Go to sites that offer free (illegal) music, software, etc.. If only you knew how many people's computers I have had to rebuild because they used Napster or another "free" site. Usually, these softwares were advertisement driven, and would load spyware on your computer in order to gain market information for sale to third party sites.. The spyware that had a valid use in the software often opened ports that would allow a hacker access to your system.
3. Going to joke sites, funny film sites, etc.. That were not well known "players" in the industry.. The smaller an online company is, the more likely they cannot afford a good network secrity guy to clean any bad stuff off their web servers.
4. Opening any and all links in emails sent to them. I mean seriously... How silly can you be?
Russ