Live data from Hacker News

PayPal 2FA Bypass

henryhoggard.co.uk

111–120 of 148 posts

Re: PayPal 2FA Bypass

#111
post #56

Mistakes were made, and there are definitely lessons to be learned, but if we want to improve the state of security, we really need to change the way we react to these types of bugs. If a service has an outage and a company posts a postmortem, we all think: "wow! that was an interesting bug, lets learn from this". We shouldn't be treating security issues differently. People who make security mistakes aren't idiots. T…

I disagree. Your "lets be super nice to everybody" strategy has come to an absurd conclusion. Is there no-one who can be held accountable for competency which they claim, when it comes to computer stuff?

PayPal doesn't write on its websites "We're some enthusiasts with no software or security experience. Let's see how well this works, together!" No, like everyone in this industry, PayPal claims its security experts have your money and financial information super secure. It's one of the first in this space, and has almost two decades of experience.

This wasn't a tricky subtle bug, this was obvious. This should have been caught in code review and tests. PayPal should be afraid of rolling out slick easy-to-use features without code review and tests. It is many years too late for PayPal to be learning the basics.

Re: PayPal 2FA Bypass

#112

Earlier quoted context omitted.

How so? The point of a random-four-words password isn't that it won't be hit by existing brute force software, it's that it's easy to remember but impractical to brute force with any software - with a 60,000 word dictionary there are more than 2^63 possible passwords.

That's true, but the whole point of the strip was that you use words that evoke an easily-memorable scene in your head. That will probably mean you can confine your list to words that most people know, which reduces the search space significantly. "correct", "horse", 'battery" and "staple" are all very common words.

The strip used a 2048 word dictionary. 2^44 is still far too many to brute force

Re: PayPal 2FA Bypass

#113
post #41
post #4

The simplicity of this exploit demonstrates something profound. The most dangerous things in life are not hidden deep in the weeds. Rather, they stare us in the face in the most obvious spots. It isn't the unknown that presents the biggest threat. It is the known that we never gave a second look.

The cardinal rule of security is: you never, ever, trust anything the client sends . This bypass is a perfect example. Although author doesn't mention which interception proxy he used, I'm 99% sure it was Burp. Replaying modified content is trivial.

Fiddler also has this capability

Re: PayPal 2FA Bypass

#114
post #99

Earlier quoted context omitted.

That's why mine answers are "DO NOT ACCEPT THIS ANSWER!!! ". Hopefully the support person will get the hint. :-/

Unfortunately, if they don't or are forced by policy, then you've just told the Internet your security answers. If I were you I'd edit that and reword it without specifics.

Thanks for your care, but there is a part that is random, and the wording is probably a bit different. I don't disclose passwords on the internet. :)

Re: PayPal 2FA Bypass

#115

Earlier quoted context omitted.

at least with one of my banks customer support centres this wouldn't happen, if you stumble for a split second they shut down the call and tell you to go into a branch to verify your identity, this is pretty annoying...

Good, they should be commended for the practice! I wish I could trust that all companies would do that, though. (Anyway, I like the idea of using answers to security questions as hard passwords.)

[deleted]

Re: PayPal 2FA Bypass

#116

Earlier quoted context omitted.

> If you can't - just generate a random password as the answer. "I_ty/:QWuCllV?'6ILs`O12kl;d0-`1" is an excellent name for your first dog / high school. Just don't forget to use a password manager to store these. Be wary of social engineering attacks though. - I'd also need you to provide me an answer to your security question. What was your first dog's name? - Oh, you know, it's a long string of random characters I…

at least with one of my banks customer support centres this wouldn't happen, if you stumble for a split second they shut down the call and tell you to go into a branch to verify your identity, this is pretty annoying...

That's terrible, because it makes using password managers impossible (while on your phone for example, or you simply don't have it open that instant because you didn't know when/if they would ask).

Re: PayPal 2FA Bypass

#117

Earlier quoted context omitted.

It's not the number of casualties that scares people, but rather the nature of the threat. Fires have existed for several millennia. Our ancestors who built and lived in the very first settlements suffered from their homes/stores occasionally burning down. We know what types of conditions increase risk of fires and we know how to minimize those risks and put the fires out when they occur. Bombs on the other hand are…

I think perception of danger = amount of times hearing people die from doing act / amount of times doing act. So flying is much higher than diving: People drive much more than they fly (a few times a year vs twice a day) and hear about air-crashes (9/11, Malaysia Airlines) more than car crashes. It's the brain playing games with us

Availability bias is definitely one aspect, but I think a big part of it is also how easy it is to tell a story that separates oneself from the victims (this often takes the form of victim blaming, but not necessarily). It's easy to tell yourself the story of how heart attacks happen to people with different lifestyles or genetics, or how car crashes happen to drivers who are less attentive, or how violent crime happens to people who live in other neighborhoods. It's a lot harder to tell yourself the story of how you'll avoid the plane with the latent mechanical fault or how you'll never be at a gathering place that would make an attractive terrorist target.

Re: PayPal 2FA Bypass

#118
post #40

This is surreal. Does PayPal outsource their web development to an anonymous script kiddie on 4chan?

I can tell you first hand what they do! They call a company like "Accenture" (which we call "Accidenture" or "HP Consulting" and a GE Capital Porta-building appears with H1-B programmers. They're there for a few months, and then they go away.

Re: PayPal 2FA Bypass

#119
post #75
post #64

Earlier quoted context omitted.

It seems standard practice for German banks to limit online passwords to five alpha-numeric characters. Fortunately, you need a TAN number (generated by a device or from an SMS message) to actually make a transaction. I have no idea why they limit the password length like this.

I'm guessing it's five characters so people don't just use their four digit PIN. I don't have any explanation for why they would limit it to five characters though, or why it has to be alphanumeric. That said, Comdirect seems to offer regular passwords or six digit PINs and Bank of Scotland (in Germany) seems to also offer regular passwords. But there are plenty of other offenders. For example my energy provider E-wi…

The justification is a rootkit which intercepts copy-paste but not the password field

Re: PayPal 2FA Bypass

#120

Earlier quoted context omitted.

> If you can't - just generate a random password as the answer. "I_ty/:QWuCllV?'6ILs`O12kl;d0-`1" is an excellent name for your first dog / high school. Just don't forget to use a password manager to store these. Be wary of social engineering attacks though. - I'd also need you to provide me an answer to your security question. What was your first dog's name? - Oh, you know, it's a long string of random characters I…

I always fill all social engineering-vulnerable questions with nonsense, especially when it is a banking site. I like when they let you set the question yourself so you can put something like "Why would a secure financial institution allow such a horrible security hole in it's system?" To which the answer is Tyrolese4Tokyo_Beulah!Papuan.

Exactly, it's just another opportunity to password protect things.
Post reply on HN