Live data from Hacker News

PayPal and zero-dollar invoice spam

troyhunt.com

71–77 of 77 posts

Re: PayPal and zero-dollar invoice spam

#71
post #60

[deleted]

Which banks are offering throwaway credit card numbers? And where do you see wide scale deployment 3Dsecure for online checkouts? Certainly not in the US. And what online payments processors are offering less than PayPal's 2.9% + $0.30? Seems pretty standard across the industry.

Citi bank will give a throwaway credit card number if you have one of their credit cards. I use it all the time, you can even set a date/limit on it if you want

Re: PayPal and zero-dollar invoice spam

#72
post #69
post #68

For a PayPal employee to post here and say he made a team aware and they are working on this it's utterly laughable. There was a post here on hn over two years ago for the same issue which was top post and generated a lot of news. https://news.ycombinator.com/item?id=6526481 It is obviously very well known to them for years but they continue to do it

Obviously well known? Guy at PayPal sees post, tells a technical person about it, said person forgets about it. Suddenly PayPal doesn't know about it anymore. Or a person wants to work on fixing this but a manager says no, because there are other priorities. Or a person starts working on this, quits, and it gets lost among the things they were working on. It's so easy for things to get lost in a company, even with al…

Isn't this what support case systems and bug tracking software was meant to do - to track non-closed issues?

Re: PayPal and zero-dollar invoice spam

#73

Earlier quoted context omitted.

Holding onto funds is how you mitigate risk as a bank or money transmitter.

Do you think they're running loads of security tests all the while or something? I'd imagine a majority (if not all) of the checks are done up front- especially given it's 2015. Pretty sure they get a nice bump on their balance sheet for cash "in-transit" - and keeping the timeframe to 3-5 business days only magnifies that effect.

It's not about balance sheets, it's about having time to cope with any unexpected problems with the transaction, like fraud.

It's frustrating, and ideally not necessary, but it's essentially a safety net for the middle party.

Re: PayPal and zero-dollar invoice spam

#74
post #9
post #2

Why would you put a clickable link to the spam website on your blog though?

If you're so interested in typing in spam links you might as well search up something like "cheap electronics online" in Google and start clicking around page 10.

Sorry about being a bit rude in this comment. I didn't mean to sound so sarcastic and I didn't mean to refer to you specifically.

Re: PayPal and zero-dollar invoice spam

#75
post #72
post #69

Earlier quoted context omitted.

Obviously well known? Guy at PayPal sees post, tells a technical person about it, said person forgets about it. Suddenly PayPal doesn't know about it anymore. Or a person wants to work on fixing this but a manager says no, because there are other priorities. Or a person starts working on this, quits, and it gets lost among the things they were working on. It's so easy for things to get lost in a company, even with al…

Isn't this what support case systems and bug tracking software was meant to do - to track non-closed issues?

That assumes that the manager doesn't insist that bugs of age get closed simply because long-open bugs make for ugly metrics.

Re: PayPal and zero-dollar invoice spam

#76
post #72
post #69

Earlier quoted context omitted.

Obviously well known? Guy at PayPal sees post, tells a technical person about it, said person forgets about it. Suddenly PayPal doesn't know about it anymore. Or a person wants to work on fixing this but a manager says no, because there are other priorities. Or a person starts working on this, quits, and it gets lost among the things they were working on. It's so easy for things to get lost in a company, even with al…

Isn't this what support case systems and bug tracking software was meant to do - to track non-closed issues?

yeah, I agree, but I think a lot of us work in similar situations, where bug tracking exists, but there's such inundation of bugs that we can lose track of some.

I guess I have sympathy for the PayPal team in this case. They're working on an extremely large product, with a huge user-base. I would imagine it would be very easy for bugs like this to fall through the cracks even with a "process" in place

Re: PayPal and zero-dollar invoice spam

#77

PayPal employee here (and I'm hiring Node.js developers :P ). I actually got two of these messages while I was out for the holiday break. I don't work on the team that handles invoicing; but, I (among others) made them aware of this issue and they are definitely working on a fix. The challenge, of course, is that there are plenty of legitimate reasons for sending $0 invoices and we don't want to artificially make our…

Genuine question: What are the legitimate uses of $0 invoices? The only thing I can think of is a product that usually costs money (and thus has an invoice workflow), but has been marked as free for some promotion.

I sold a product and it was paid for by gift certificate or a special promo. I want to send a $0.00 invoice for the customer to see it and enjoy the feeling (Sweet! Free jerky/flowers/socks). It's great marketing and the customer will remember you the next time they want some jerky/flowers/socks.
Post reply on HN