Live data from Hacker News

PayPal 2FA Bypass

henryhoggard.co.uk

21–30 of 148 posts

Re: PayPal 2FA Bypass

#22
I'm happy to see that the article doesn't have any BS that I have to ignore. It's a simple page that only tells the 'required' story. As a reader, I want more people to cut the crap about 'blah blah blah' and get to the subject.

Re: PayPal 2FA Bypass

#23
This is scarily simple. Profit indeed for a black hat. Coupled with a recent post about Gmail on how phone carriers are the weakest link, I just don't feel safe with anything but a dongle based 2fa these days.

Re: PayPal 2FA Bypass

#26
post #23

This is scarily simple. Profit indeed for a black hat. Coupled with a recent post about Gmail on how phone carriers are the weakest link, I just don't feel safe with anything but a dongle based 2fa these days.

Unless the master key is compromised allowing anyone to generate authenticator codes, as I seem to recall happened a few years ago with a major provider.

Re: PayPal 2FA Bypass

#27
This seems like a good time to rant about PayPal 2FA and its poor usability.

Every time I open the PayPal app I have to wait for a text message and type a code across. That should not be necessary! PayPal should count the app as the second factor and only ask for the password. I am happy to us 2FA with Google because I only have to use it when on a new device, or once a month or so in the browser.

Second, support 2FA apps like Authy already. SMS based 2FA is both insecure and unreliable.

Re: PayPal 2FA Bypass

#28
post #23

This is scarily simple. Profit indeed for a black hat. Coupled with a recent post about Gmail on how phone carriers are the weakest link, I just don't feel safe with anything but a dongle based 2fa these days.

That doesn't help in this case. I have a VeriSign 2FA dongle for PayPal and it still offers the same option of logging in with security questions.

Re: PayPal 2FA Bypass

#29

Ouch! Also, PayPal really needs to stop using SMS for 2fa. I expect more from a payment processor that is linked to my bank account.

As I just mentioned elsewhere on this thread, SMS isn't the problem here. I use a VeriSign dongle for PayPal 2FA but PayPal still offers the same option of using security questions instead. I was previously under the reasonable assumption that the security questions form was ar least handled correctly, but apparently not.

Re: PayPal 2FA Bypass

#30
What is the additional phone verification good for if you can bypass it anyhow?

I mean - if you can chose between pw+phone and pw+pw2 ... why bring the phone into play at all?

Post reply on HN