It's been mentioned in news coverage on the EBAY hack, and not from the itself. It's also been reported that none of an account holder's personal info was encrypted except for the password itself. But I'm also beginning to think it's a good idea to tailor unique security answers specifically to a website. In case of a breach, those answers couldn't be used to hack another account by resetting a "lost" password?