Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

61–70 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#61

Earlier quoted context omitted.

To be fair they are probably not designed specifically for that, the issue is big players are much more likely to have more political leverage. Or is that one much like GDPR? Crazy fines that only big players can afford, in such a case, that was poorly designed.

GDPR max fine is (iirc) 4% of revenue. So if you are a small fish you will be paying less then the big fish. Also the fines are for wilful failure to comply, if you accidentally broke GDPR then your first offence is going to be more a slap on the wrist then an instant 4%.

Except it says "whichever" is higher, so if they decided to fine you 10 million or 2% of revenue, and your 2% is much lower than 10 million, guess which one you're paying...

> Up to €10 million, or 2% of the worldwide annual revenue of the prior financial year, whichever is higher

See: https://www.gdpreu.org/compliance/fines-and-penalties/

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#62

Earlier quoted context omitted.

They were created for sincere reasons, and with best intentions. In the real world best intentions always conflict with the motivations of individual players. It just isn't reasonable that PayPal would be cut off. That was always a toothless threat, at least for larger players. As an aside, PayPal is a marvel to me because it is effectively lost in time. Using their tools and interface is like stepping back to 1995,…

> They were created for sincere reasons, and with best intentions. No? They were created by the industry to avoid actually being regulated and are a way to shift liability. That doesn't mean they aren't also beneficial, but that's more a side effect than the intention.

Yes?

If we want to be cynical, of course there was a self-serving reason they created the standards -- because fraud, especially "internet" fraud, was on a massive upswing and it threatened this enormous new market of credit card spending. There is no question it's in their self-interest to improve the general condition of transactions.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#63

Earlier quoted context omitted.

To be fair they are probably not designed specifically for that, the issue is big players are much more likely to have more political leverage. Or is that one much like GDPR? Crazy fines that only big players can afford, in such a case, that was poorly designed.

GDPR only charges big fines to big players.

https://www.gdpreu.org/compliance/fines-and-penalties/

> Up to €10 million, or 2% of the worldwide annual revenue of the prior financial year, whichever is higher

I'm no lawyer, but this doesn't sound like it's just for the bigger players, at the minimum you'd be looking at some fines. At minimum you'd be paying 10 million if you incur that amount of fines. I guess it could be argued the 2% is geared towards hurting the big players.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#64

Earlier quoted context omitted.

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

Yet paypal's policy explictly says authentication bypasses, like the 2FA bypass they showed, are in scope >Authentication or authorization flaws, including insecure direct object references and authentication bypass Reading with the context of the other out-of-scope issues. I think they meant that the ability to buy or steal someones credentials is not a vulnerability in and of itself. >Vulnerabilities involving stol…

> It is a poorly worded and confusing policy. Yet, if I found a 2FA bypass and I read that policy I would conclude that it is in scope and submit the issue.

If you wanted my advice as something of an insider to the platform, I'd say that you should point to the ambiguity there ("One policy says yes, another policy says no?") and ask for an Informational close rather than Not Applicable. (H1 hates it when researchers ask for a specific close status, but it's common and often reasonable.) Closing your report Informational instead of Not Applicable costs the company nothing, so even an argument that isn't very strong on the merits can carry the day.

I wouldn't push for a payout, given the out-of-scope phrasing. If executing a successful attack requires you to possess stolen credentials, they're on solid ground when they tell you the attack is excluded by their policy.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#65
I say it all the time, there are no incentives or rules regarding cybersecurity standards, or companies have no obligations to follow them. The cost and risks of cybersecurity is pretty high, the public are always the first victims and pay the damage.

Cybersecurity always has been a national problem which should be solved by laws.

Insurance companies or banks should at least be encouraged to do more.

Cybersecurity shouldn't be improved with bug bounties.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#66
post #20

This doesn't surprise me. I'm currently trying to get a refund out of PayPal after what looks like a massive flaw in their refund process. I paid for something on eBay and it appears to have been a compromised account. The original auction, feedback history, etc, looked legit. The flow was this: 1) I pay for a product on eBay using PayPal, using my creditcard (direct from card, not from any existing PayPal balance).…

I've raised a chargeback with the issuing bank, which should hopefully make PayPal sit up and put a bit more effort into sorting this out. Or just close your account and ban you.

Possibly, a blog post will follow if that happens. PayPal has aways been a firewall around my creditcard number and I've never linked any other current account for pulling funds as, having worked in the payments industry, I know what a shit show it can be and that (in most cases, especially like this) the creditcard issuer will stand with the cardholder and not the merchant.

Now i'm using other methods to pay for most e-commerce transactions: one time PANs, a distinct debit account that I keep a minimum amount of funds in for this stuff, etc. So PyaPal are no longer seeing anything like the level of use they once did from me. They can ban my account if they want, the issuing bank have already said they will proceed with the chargeback if PayPal don't issue a refund.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#67
post #53

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

Squid is vastly under-equipped to deal with the security hygiene needed for a project this important. That's the tragedy of the open source world : mission critical for everyone, but no actor willing to maintain it properly. It's Heartbleed all over again.

Upvoted, but not sure it's a tragedy. Much like that quote about democracy, it's a bad system, except the others are worse. Would be nice to have something better tho.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#68

Earlier quoted context omitted.

HackerOne, itself, is pretty generous about reported bugs. (As in, you reported an issue in the website hackerone.com.) They have to be, because their existence depends on everyone thinking bug bounty platforms are a good idea -- it's part of their way of encouraging people to hunt for bug bounties in general. Payouts for bugs in other products are determined by those companies, not by H1.

The point of being a branded platform is that you take responsibility for the activity on your platform. Otherwise you are just an email gateway.

It is possible to escalate your dispute with a company to H1 itself. They'll review the report and the company's policy, and they may contact the triager or the company to try to resolve any questions.

I wouldn't do that as a regular thing; you're pretty well guaranteed to piss off everyone on the company's side of things.

I should note that I've personally seen probably in excess of $100,000 paid out through H1; the payouts do happen.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#69

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

I've never liked these rent-seeking bugbounty platforms which are inserting themselves as middle-men and mediators, but then take away the real value that comes from building direct client relationships.

it's ok for people who start out and only want to work on vulns and not bother with "sales" (building long term client relationships). severely limiting though in the long run!

much better to spend time on pitching your service directly and build a name for yourself this way. most customers I had always came back and rewarded me with more work. on those bounty platorms however you're constantly competing with drive-by pen-testers who lower your price and you have no say in the whole negotiation and bargaining phase. your previous reputation also tends to stay locked into these platforms.

a better long term approach is to build connections, set up a ltd (LLC) and make sure you have a good lawyer who can advise you (not just when things go down). ideally build a collective with other like minded (e.g. like a consulting or law practice where you don't always have to share clients but you can if you want to complement each others skills).

this is imo the best way to escape the "scope-prison" and the best way to learn about clients additional (and actual) weak points (points that they haven't themselves even thought about).

does anyone here do it this way or with a similar approach?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#70

Earlier quoted context omitted.

https://www.forbes.com/sites/zakdoffman/2020/02/22/paypal-cr... I should note that I haven't really investigated this so I don't claim to know any truth.

reading both, looks to me like this is pretty much 2fa. isn't 2fa defined as a "second factor" beyond user:pass? isn't that what this bypass is about?

There is genuine disagreement about whether email qualifies as a second factor. As it is often just protected by a username and password the argument is that it's the same "something you know" factor as a password, or just an obfuscation of the same factor.

I will say, that if cybernews have done what they say that they've done, and PayPal are claiming that it's not a concern, then PayPal are clearly in the wrong, and that remains true even if we all agree that this isn't 2FA.

Post reply on HN