Live data from Hacker News

PayPal 2FA Bypass

henryhoggard.co.uk

41–50 of 148 posts

Re: PayPal 2FA Bypass

#41
post #4

The simplicity of this exploit demonstrates something profound. The most dangerous things in life are not hidden deep in the weeds. Rather, they stare us in the face in the most obvious spots. It isn't the unknown that presents the biggest threat. It is the known that we never gave a second look.

The cardinal rule of security is: you never, ever, trust anything the client sends.

This bypass is a perfect example. Although author doesn't mention which interception proxy he used, I'm 99% sure it was Burp. Replaying modified content is trivial.

Re: PayPal 2FA Bypass

#42

Ouch! Also, PayPal really needs to stop using SMS for 2fa. I expect more from a payment processor that is linked to my bank account.

Agreed, NIST stopped recommending SMS 2FA a few months back (https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo...)

I really wish they had Google authenticator or Yubikey support.

Re: PayPal 2FA Bypass

#43

Ouch! Also, PayPal really needs to stop using SMS for 2fa. I expect more from a payment processor that is linked to my bank account.

What exactly is wrong with offering SMS 2FA? I don't have a smartphone, but I have a great little prepaid phone. Why should I get no features just because they are not necessarily as good as it gets ? Also, as far as I'm aware, all of the major "attacks" on SMS 2FA are just the fact that a smartphone can be compromised in many ways. I have much less attack surface: an attacker would need to reprogram my undocumented exotic architecture phone with a bug in a parser which is probably too small to contain bugs of that nature. The other way is SMS MITM, which on some networks is demonstrated feasible, but requires basically setting up an SDR near the victim, a lot more complicated.

With my prepaid provider, customer service is shoddy but would need considerably more to do a number port than just the number.

By removing SMS 2FA you gain nothing, and I lose my only viable second factor.

Re: PayPal 2FA Bypass

#44

Ouch! Also, PayPal really needs to stop using SMS for 2fa. I expect more from a payment processor that is linked to my bank account.

What exactly is wrong with offering SMS 2FA? I don't have a smartphone, but I have a great little prepaid phone. Why should I get no features just because they are not necessarily as good as it gets ? Also, as far as I'm aware, all of the major "attacks" on SMS 2FA are just the fact that a smartphone can be compromised in many ways. I have much less attack surface: an attacker would need to reprogram my undocumented…

[deleted]

Re: PayPal 2FA Bypass

#45

Earlier quoted context omitted.

When I went to setup my online account for my old bank, I entered a randomly generated 16 digit key and got an error; "Maximum password length limited to 6 characters...only alpha-numeric" I called to inform them that their account creation was broken, because obviously that was a bug. They told me that sometimes people have a hard time remembering their password, so they "need to balance between ease of use and secu…

Heh, both my banks (Banco do Brasil and Santander) are worse. 6 characters, numbers only! "For my safety" they recommend not using my birthday - how thoughtful.

It's the personal identifier (Kinda like social security number I guess? You write it on every contract you sign basically) and a 4-digit pin here in Spain. Stupidly insecure.

Re: PayPal 2FA Bypass

#46

Ouch! Also, PayPal really needs to stop using SMS for 2fa. I expect more from a payment processor that is linked to my bank account.

What exactly is wrong with offering SMS 2FA? I don't have a smartphone, but I have a great little prepaid phone. Why should I get no features just because they are not necessarily as good as it gets ? Also, as far as I'm aware, all of the major "attacks" on SMS 2FA are just the fact that a smartphone can be compromised in many ways. I have much less attack surface: an attacker would need to reprogram my undocumented…

From my limited reading on the issue. SMS in US is unsafe. Not sure if the same can be said in other places like EU or Japan.

Re: PayPal 2FA Bypass

#47

Ouch! Also, PayPal really needs to stop using SMS for 2fa. I expect more from a payment processor that is linked to my bank account.

What exactly is wrong with offering SMS 2FA? I don't have a smartphone, but I have a great little prepaid phone. Why should I get no features just because they are not necessarily as good as it gets ? Also, as far as I'm aware, all of the major "attacks" on SMS 2FA are just the fact that a smartphone can be compromised in many ways. I have much less attack surface: an attacker would need to reprogram my undocumented…

All the major 2FA attacks I have read about involved social engineering of the phone provider's customer service to number port. The thing is, since it is not a software system but depends on humans, attackers can keep trying until they get a CS rep they can manipulate.

Ex

* https://www.wired.com/2016/06/deray-twitter-hack-2-factor-is...

* https://www.hackread.com/gmail-id-hacked-google-two-factor-a...

Re: PayPal 2FA Bypass

#48

Earlier quoted context omitted.

heart disease vs. terrorism. it seems to be an unfortunate emergent behavior of groups of humans.

I noticed that if it's a fire that kills many people it's only a one day news; while if it's a bomb that kills one everybody's afraid.

It's not the number of casualties that scares people, but rather the nature of the threat.

Fires have existed for several millennia. Our ancestors who built and lived in the very first settlements suffered from their homes/stores occasionally burning down. We know what types of conditions increase risk of fires and we know how to minimize those risks and put the fires out when they occur.

Bombs on the other hand are unpredictable. They also cause their damage instantly and there is no way to minimize or prevent it. You can escape from a burning building, or if stuck, wrap a piece of wet cloth around your mouth to minimize the amount of smoke you breathe while you wait for rescue. You can't outrun an explosion.

That's why people are a lot more scared of bombs than they are of fires (or car accidents, for that matter, which kill many more people than both fires and bombs combined).

Re: PayPal 2FA Bypass

#50

Earlier quoted context omitted.

What exactly is wrong with offering SMS 2FA? I don't have a smartphone, but I have a great little prepaid phone. Why should I get no features just because they are not necessarily as good as it gets ? Also, as far as I'm aware, all of the major "attacks" on SMS 2FA are just the fact that a smartphone can be compromised in many ways. I have much less attack surface: an attacker would need to reprogram my undocumented…

All the major 2FA attacks I have read about involved social engineering of the phone provider's customer service to number port. The thing is, since it is not a software system but depends on humans, attackers can keep trying until they get a CS rep they can manipulate. Ex * https://www.wired.com/2016/06/deray-twitter-hack-2-factor-is... * https://www.hackread.com/gmail-id-hacked-google-two-factor-a...

> All the major 2FA attacks I have read about involved social engineering of the phone provider's customer service to number port.

SS7 attacks don't.

[1] http://www.forbes.com/sites/thomasbrewster/2016/06/01/whatsa...

... hackers can bypass the encryption protections by exploiting SS7 to create duplicate accounts that receive all the messages intended for the target phone.

This is done by tricking the telecoms networks into believing the hacker’s phone has the same number as the target’s. That means they can set up a new WhatsApp or Telegram account with the same number and will receive the supposedly secret code that confirms they are a “legitimate” user. From there, they can impersonate their target, sending and receiving new calls and texts.

Post reply on HN