Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

41–50 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#41

Earlier quoted context omitted.

> then PCI-DSS is a farce. Take a wild guess on what you think will happen.

All these regulations are bs. Designed to keep small players out.

To be fair they are probably not designed specifically for that, the issue is big players are much more likely to have more political leverage.

Or is that one much like GDPR? Crazy fines that only big players can afford, in such a case, that was poorly designed.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#42
HackerOne appears to be completely broken and I wouldn't recommend it to anyone.

Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud.

I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2 months to merge my patch. Maybe they're volunteers, so I can't blame them. Reported it to the bug bounty [1] which promises high rewards on January 20th and apart from triaging it, there has been radio silence since despite having invoked HackerOne mediation. I have more Squid memory bugs and I'd rather rm -rf them than go through this process again.

HackerOne used to be decent but this appears to be a structural problem now [2].

[1] https://hackerone.com/ibb-squid-cache [2] https://twitter.com/DevinStokes/status/1228014268567547905

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#43

PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed.

Quote from your source:

> If your scan fails, you must schedule a rescan within 30 days to prove that the critical, high-risk or medium-risk vulnerabilities have been patched.

Scan in this sentence refers to "a PCI DSS external scan".

The list of approved vendors that can conduct PCI DSS external scans can be found here: https://www.pcisecuritystandards.org/assessors_and_solutions...

Please find cybernews' certificate number there and quote it for us, I have looked and can't find it.

I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong.

And even if they were an approved scanning vendor, from what little I know about PCI-DSS, these scans are part of larger process - so even if they were an approved scanning vendor the scan failure would still have had to be part of the larger process for this 30 day limit to apply.

I could go on and on about how much I hate PayPal and random other things, but just because I don't like something does not quite justify making false claims about it.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#44

Earlier quoted context omitted.

All these regulations are bs. Designed to keep small players out.

To be fair they are probably not designed specifically for that, the issue is big players are much more likely to have more political leverage. Or is that one much like GDPR? Crazy fines that only big players can afford, in such a case, that was poorly designed.

GDPR only charges big fines to big players.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#45

Earlier quoted context omitted.

> then PCI-DSS is a farce. Take a wild guess on what you think will happen.

All these regulations are bs. Designed to keep small players out.

They were created for sincere reasons, and with best intentions. In the real world best intentions always conflict with the motivations of individual players.

It just isn't reasonable that PayPal would be cut off. That was always a toothless threat, at least for larger players.

As an aside, PayPal is a marvel to me because it is effectively lost in time. Using their tools and interface is like stepping back to 1995, and it seems -- from an outsider perspective -- that it must be some duct-taped quagmire that is barely holding on.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#46

Earlier quoted context omitted.

Could you link that article? Because the screenshot in this article pretty clearly shows PayPal sending an SMS to the user's phone.

https://www.forbes.com/sites/zakdoffman/2020/02/22/paypal-cr... I should note that I haven't really investigated this so I don't claim to know any truth.

reading both, looks to me like this is pretty much 2fa. isn't 2fa defined as a "second factor" beyond user:pass?

isn't that what this bypass is about?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#47
post #20

This doesn't surprise me. I'm currently trying to get a refund out of PayPal after what looks like a massive flaw in their refund process. I paid for something on eBay and it appears to have been a compromised account. The original auction, feedback history, etc, looked legit. The flow was this: 1) I pay for a product on eBay using PayPal, using my creditcard (direct from card, not from any existing PayPal balance).…

You put in way too much effort. Call your credit card company first. Your credit card company profits from vendor (PayPal) mistakes by charging fees, so they are always happy to help you.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#48

PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…

HackerOne states they are a PCI-DSS auditor approved organization [1].

[1] https://www.hackerone.com/product/challenge

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#49

Earlier quoted context omitted.

> then PCI-DSS is a farce. Take a wild guess on what you think will happen.

All these regulations are bs. Designed to keep small players out.

I guess you're not at all familiar with the self report nature of PCI audits.

The purpose of PCI is to shift liability

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#50

I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

HackerOne, itself, is pretty generous about reported bugs. (As in, you reported an issue in the website hackerone.com.) They have to be, because their existence depends on everyone thinking bug bounty platforms are a good idea -- it's part of their way of encouraging people to hunt for bug bounties in general. Payouts for bugs in other products are determined by those companies, not by H1.

The point of being a branded platform is that you take responsibility for the activity on your platform. Otherwise you are just an email gateway.
Post reply on HN