Live data from Hacker News

PayPal 2FA Bypass

henryhoggard.co.uk

131–140 of 148 posts

Re: PayPal 2FA Bypass

#131

Earlier quoted context omitted.

I always fill all social engineering-vulnerable questions with nonsense, especially when it is a banking site. I like when they let you set the question yourself so you can put something like "Why would a secure financial institution allow such a horrible security hole in it's system?" To which the answer is Tyrolese4Tokyo_Beulah!Papuan.

I fill them with nonsense words unrelated to the question. Mother's maiden name? Fire truck. First car? Air conditioner. If I have to call a company they always ask me why. The explanation is anyone who has me as a Facebook friend can figure out who my first girlfriend was, my maternal grandmother's first name, my mother's maiden name, where I was born, my first car, etc. And if every company has the same data, a dat…

Same here. But recently, United airlines changed their system to only allow selecting from a list (your favorite dog breed ? Choose 1 of 8. Your favorite movie genre? Choose one of 12). I picked a random set and wrote it in my password stash.

Seriously bad security practices.

Re: PayPal 2FA Bypass

#132

Earlier quoted context omitted.

> If you can't - just generate a random password as the answer. "I_ty/:QWuCllV?'6ILs`O12kl;d0-`1" is an excellent name for your first dog / high school. Just don't forget to use a password manager to store these. Be wary of social engineering attacks though. - I'd also need you to provide me an answer to your security question. What was your first dog's name? - Oh, you know, it's a long string of random characters I…

I always fill all social engineering-vulnerable questions with nonsense, especially when it is a banking site. I like when they let you set the question yourself so you can put something like "Why would a secure financial institution allow such a horrible security hole in it's system?" To which the answer is Tyrolese4Tokyo_Beulah!Papuan.

And the answer is "because, by and large, it works just fine". Yes, people fall afoul of these kinds of questions, but the general public cannot handle proper security hygeine - and educating them takes so much effort on both sides, that your customers will just go elsewhere. Proper security procedures would also lock a great many more people out of their own accounts than would be lost to fraud. Can't satisfy security questions? Well, take the morning off work on Monday morning and bring in several forms of identification...

It's why ATM PIN codes are so short - it's easier for the bank to just reimburse losses in case of fraud than to properly/strictly control security access.

Any time I see someone talk about how dumb general banking security procedures are, it tells me that they've spent no time in tech support for the general public :)

Re: PayPal 2FA Bypass

#133
post #56

Mistakes were made, and there are definitely lessons to be learned, but if we want to improve the state of security, we really need to change the way we react to these types of bugs. If a service has an outage and a company posts a postmortem, we all think: "wow! that was an interesting bug, lets learn from this". We shouldn't be treating security issues differently. People who make security mistakes aren't idiots. T…

> They aren't negligent

What would actually qualify as negligence in your view of the world!? This is as bad as it gets, this isn't an ordinary mistake.

Re: PayPal 2FA Bypass

#134

Earlier quoted context omitted.

What exactly is wrong with offering SMS 2FA? I don't have a smartphone, but I have a great little prepaid phone. Why should I get no features just because they are not necessarily as good as it gets ? Also, as far as I'm aware, all of the major "attacks" on SMS 2FA are just the fact that a smartphone can be compromised in many ways. I have much less attack surface: an attacker would need to reprogram my undocumented…

There is a TOTP/Google Auth 2FA application for J2ME, which will run on many feature phones: http://totpme.sourceforge.net/ In addition, 2FA systems are not limited to devices the consumer already has -- Paypal could easily send you a device that generates a one-time password, or that uses a challenge-response protocol to do so.

Yeah, I'll need to upgrade to a J2ME compatible phone when they kill GSM here anyway, so I guess that will be an option. Thanks for the char * * uri;

Re: PayPal 2FA Bypass

#135
post #56

Mistakes were made, and there are definitely lessons to be learned, but if we want to improve the state of security, we really need to change the way we react to these types of bugs. If a service has an outage and a company posts a postmortem, we all think: "wow! that was an interesting bug, lets learn from this". We shouldn't be treating security issues differently. People who make security mistakes aren't idiots. T…

All great points and true! The problem is PayPal hasn't been a great company to so many people their practices are abysmal. I've had my company account frozen more then once and it was a terrible experience and it's happened to lots of people. This is a company that makes a lot of mistakes and has bad judgement. They don't deserve my understanding. They haven't earned it. Other companies have.

But otherwise you are right. Less scrutiny more understanding so companies will be open and honest when they screw up.

Re: PayPal 2FA Bypass

#136
post #56

Mistakes were made, and there are definitely lessons to be learned, but if we want to improve the state of security, we really need to change the way we react to these types of bugs. If a service has an outage and a company posts a postmortem, we all think: "wow! that was an interesting bug, lets learn from this". We shouldn't be treating security issues differently. People who make security mistakes aren't idiots. T…

I fill them with nonsense words unrelated to the question. Mother's maiden name? Fire truck. First car? Air conditioner.

If I have to call a company they always ask me why. The explanation is anyone who has me as a Facebook friend can figure out who my first girlfriend was, my maternal grandmother's first name, my mother's maiden name, where I was born, my first car, etc. And if every company has the same data, a data breach at one makes the entire system fall apart.http://www.passwordmanagers.net/resources/Recovery-Mode-with... Recovery Mode with Itunes

Re: PayPal 2FA Bypass

#137
post #105

Sounds like a lot of work! Paypal will just turn off two-factor themselves if you ask nicely via an unverified twitter DM. http://imgur.com/a/Tu1AN https://www.reddit.com/r/SocialEngineering/comments/3kgw3s/p...

PayPal's 2FA broke on me when it started locking my account every time I attempted to use it, because I'd previously made it send too many SMSes (poor signal). I was thankful that support let me disable it, but it was worrying they didn't try to verify that I actually controlled my device first.

It's weird, don't all services that enable 2FA give you reset codes? Shouldn't they ask you to use those, or at least give them one if anything so they can help you disable your account? Kind of odd.

Re: PayPal 2FA Bypass

#138

Am I the only one who found it odd that the author had internet access, but there was no phone signal? Maybe it's because I'm Kenyan, where phone penetration is much higher than internet penetration, and where internet access over GSM has the biggest share of the internet access pie chart.

The author mentioned being in a hotel, so I assume he was using their wifi.

Re: PayPal 2FA Bypass

#139
post #75

Earlier quoted context omitted.

I'm guessing it's five characters so people don't just use their four digit PIN. I don't have any explanation for why they would limit it to five characters though, or why it has to be alphanumeric. That said, Comdirect seems to offer regular passwords or six digit PINs and Bank of Scotland (in Germany) seems to also offer regular passwords. But there are plenty of other offenders. For example my energy provider E-wi…

The justification is a rootkit which intercepts copy-paste but not the password field

Sure, except then it would intercept the copy, not the paste. And it basically trades clipboard vulnerabilities for keylogging vulnerabilities.

A more realistic exploit is a Flash banner on another tab intercepting the password in the clipboard. This is why offline password managers automatically expire the clipboard though.

The danger of discouraging complex or long passwords is far greater than either of these two attacks, both of which rely on the user's system already being compromised.

Re: PayPal 2FA Bypass

#140
post #42

Earlier quoted context omitted.

Agreed, NIST stopped recommending SMS 2FA a few months back ( https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo... ) I really wish they had Google authenticator or Yubikey support.

They have both. I have a "Symantec VIP" co-branded Yubikey that I've used with PayPal for years along with an authenticator app on my phone as a fallback.

I have both a yubikey and an auth app but can't seem to find a way to use them with paypal. Do you have some kind of special account or is that a feature bound to a certain market?
Post reply on HN