Live data from Hacker News

PayPal 2FA Bypass

henryhoggard.co.uk

31–40 of 148 posts

Re: PayPal 2FA Bypass

#31

Earlier quoted context omitted.

17 days is fast, relatively speaking. Security questions are hardly really that great of 2FA protection anyways.

Good to know. And ya, a security question to bypass a phone 2SV is a joke. Almost entirely defeats the purpose.

Just to be clear, it bypasses any of their 2FA codes, not just SMS-based codes. The security questions bypass "feature" also appears on my account for which I use a VeriSign 2FA dongle.

Re: PayPal 2FA Bypass

#32
If I were to guess this flaw was a result of monkey-patching to support 2FA that didn't quite consider different scenarios.

I've come across a few authentication bypass vulns that seem similar.

Re: PayPal 2FA Bypass

#33
post #4

The simplicity of this exploit demonstrates something profound. The most dangerous things in life are not hidden deep in the weeds. Rather, they stare us in the face in the most obvious spots. It isn't the unknown that presents the biggest threat. It is the known that we never gave a second look.

heart disease vs. terrorism. it seems to be an unfortunate emergent behavior of groups of humans.

I noticed that if it's a fire that kills many people it's only a one day news; while if it's a bomb that kills one everybody's afraid.

Re: PayPal 2FA Bypass

#34
post #22

I'm happy to see that the article doesn't have any BS that I have to ignore. It's a simple page that only tells the 'required' story. As a reader, I want more people to cut the crap about 'blah blah blah' and get to the subject.

That only works if you can assume your audience has the necessary context.

That being said, I've often thought Hacker News should have a nice crowd sourced tldr summary at the top of all the comments.

Re: PayPal 2FA Bypass

#36

Does anybody know how to activate 2FA for PayPal? In the security section I don't even have that option.

I don't remember exactly where it is in settings, but it's not called 2fa or something obvious it's called something like PayPal Security Key

Re: PayPal 2FA Bypass

#37

I've seen equally as ridiculous web bugs, computing prices browser side in javascript, credit card numbers encoded in REST API endpoints, financial websites not supporting 2FA at all or mixing http requests into the sites. We're solidly in the dark ages of web security still.

When I went to setup my online account for my old bank, I entered a randomly generated 16 digit key and got an error; "Maximum password length limited to 6 characters...only alpha-numeric" I called to inform them that their account creation was broken, because obviously that was a bug. They told me that sometimes people have a hard time remembering their password, so they "need to balance between ease of use and secu…

Heh, both my banks (Banco do Brasil and Santander) are worse. 6 characters, numbers only! "For my safety" they recommend not using my birthday - how thoughtful.

Re: PayPal 2FA Bypass

#39
post #22

I'm happy to see that the article doesn't have any BS that I have to ignore. It's a simple page that only tells the 'required' story. As a reader, I want more people to cut the crap about 'blah blah blah' and get to the subject.

Well, here the succinctness is a part of the story. It emphasises just how basic this bypass is.

For what it's worth, I thought the "I was in a hotel..." story was superfluous and probably not true.

Post reply on HN