Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

11–20 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#11

>When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level. This happened even when the issue was eventually patched, although we received no bounty, credit, or even a thanks. Instead, we got our Reputation scores (which start out at 100) negatively impacted, leaving us worse off than if we’d reported not…

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

but this is it:

"This happened even when the issue was eventually patched..." which, based on that, I understand their gripe here

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#13
From PayPal's response to a 2FA bypass:

> If the attacker has the victim's password, they would already be able to gain access to the account via web UI too. As such, the account is already compromised. As such, there does not appear to be any security implications as a direct result of this behavior.

Seriously? This means PayPal's 2FA is just security theater. I'd rather they didn't offer it at all in this case, at least then I'd know how insecure my account really was.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#14
PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed.

According to this image [2], they did not respond or refute within 30 days.

If PayPal’s PCI-DSS compliance certification isn’t revoked then PCI-DSS is a farce.

[1] https://www.itgovernance.co.uk/blog/a-guide-to-the-pci-dsss-...

[2] https://cybernews.com/wp-content/uploads/2020/02/paypal-2fa-...

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#15
post #7

> They deemed this issue a Duplicate, and we lost another 5 points. A dupe costs points?! On bugcrowd you GET points for dupes...

The points associated with a duplicate report depend on the status of the report you get duped to. I assume in this case the original report was Not Applicable.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#16
post #7

> They deemed this issue a Duplicate, and we lost another 5 points. A dupe costs points?! On bugcrowd you GET points for dupes...

The points associated with a duplicate report depend on the status of the report you get duped to. I assume in this case the original report was Not Applicable.

Oh so an N/A dupe? That sounds plausable.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#17
post #9

I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

> I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne. Sadly you can't feed your children from media drama. Maybe, in the long run, but it's more likely to get sued.

The market for a freelance security researcher out there is hard, no doubt, but disclosing bugs publically is an addition to your resume, akin to any other professional development you do. It demonstrates you can do the work and it shows the skills you have.

Suing someone for disclosing an actual bug is a long term losing proposition for any company in a competitive industry.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#18

>When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level. This happened even when the issue was eventually patched, although we received no bounty, credit, or even a thanks. Instead, we got our Reputation scores (which start out at 100) negatively impacted, leaving us worse off than if we’d reported not…

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

with the acquired information, the researcher has a few options:

- bulk acquire stolen credentials, bypass 2FA, bypass the security checks when sending money, and accumulate wealth

- sell above process to anyone that has an internet-connected device, the desire to accumulate wealth, and willingness to commit fraud (which I would guess is a non-trivial % of the world's population)

- disclose the vulnerabilities to paypal through any available channels

The fact that they went with the latter AND were punished for it doesn't shock you? Jesus.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#19

PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…

> then PCI-DSS is a farce.

Take a wild guess on what you think will happen.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#20
This doesn't surprise me. I'm currently trying to get a refund out of PayPal after what looks like a massive flaw in their refund process. I paid for something on eBay and it appears to have been a compromised account. The original auction, feedback history, etc, looked legit. The flow was this:

1) I pay for a product on eBay using PayPal, using my creditcard (direct from card, not from any existing PayPal balance).

2) Seller marks item as shipped but then 5mins later issues an e-check refund (rather than a refund on my creditcard).

3) Seller cancels and deletes the original item on eBay so i can no longer raise a dispute there.

4) The e-check refund continues to bounce as clearly the compromised paypal account can't pull those funds from the other source.

5) The refund being in limbo means my dispute with PayPal gets closed as "a refund was previously issue" (which did, and will continue to, bounce).

The important part is 2 - since I paid for this on my card the refund should have gone direct to my card. However, since I paid for this on my creditcard I've raised a chargeback with the issuing bank, which should hopefully make PayPal sit up and put a bit more effort into sorting this out.

Post reply on HN