PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…
no shit PCI-DSS is a farce it's just there to make people that don't know anything about technology feel better
“We found PayPal vulnerabilities and PayPal punished us for it”
71–80 of 337 posts
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#72I find it so fascinating because it is a kind of manifestation of what is clearly a kind of mentality of abused people, the kind of people who usually others see as being trapped in a kind of inability to internalize the abuse being perpetrated against them, and therefore rationalize, excuse, ignore, etc. to simply push away and hide and suppress the clear abuses happening to them. It's just as sad as it is interesting to me because of the inherent illogical puzzle it represents, a puzzle that clearly has not yet been solved or for which there exists no easy and clean solution. How do you get someone out of an abusive relationship, be it a personal relationship or something like a formalized cult?
We are all abused by PayPal and other tech companies on a constant basis, yet all we do is lament the treatment, while simply just continuing on in the abusive relationship. Someone should tell PayPal, etc. "no, you are not allowed to abuse us anymore. We have human rights and your lies, deceit, abuse, manipulation, gaslighting, monopolization, etc are not going to be tolerated anymore." But I guess our other abusers in Congress get too much money and free meals out of it to change that.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#73HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…
The cybersecurity team had a backlog of roughly 30 critical issues discovered internally before starting HackerOne. We were unable to fix those issues, or the ones reported to us, because we had no visibility into source code, there were 12 different development teams, most of them outsourced, and all the project managers were interested in was covering their ass.
The HackerOne deployment was invite-only, but the few hackers in it did fantastic work. I kept being told to find excuses to reduce the amount we'd pay for the critical issues they'd find and we'd fail to fix. At least we triaged faster than Paypal.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#74Earlier quoted context omitted.
GDPR only charges big fines to big players.
https://www.gdpreu.org/compliance/fines-and-penalties/ > Up to €10 million, or 2% of the worldwide annual revenue of the prior financial year, whichever is higher I'm no lawyer, but this doesn't sound like it's just for the bigger players, at the minimum you'd be looking at some fines. At minimum you'd be paying 10 million if you incur that amount of fines. I guess it could be argued the 2% is geared towards hurting…
[0] https://gdpr-info.eu/art-83-gdpr/ Art. 83(4)
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#75Earlier quoted context omitted.
I've raised a chargeback with the issuing bank, which should hopefully make PayPal sit up and put a bit more effort into sorting this out. Or just close your account and ban you.
Possibly, a blog post will follow if that happens. PayPal has aways been a firewall around my creditcard number and I've never linked any other current account for pulling funds as, having worked in the payments industry, I know what a shit show it can be and that (in most cases, especially like this) the creditcard issuer will stand with the cardholder and not the merchant. Now i'm using other methods to pay for mos…
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#76Earlier quoted context omitted.
HackerOne states they are a PCI-DSS auditor approved organization [1]. [1] https://www.hackerone.com/product/challenge
> HackerOne states they are a PCI-DSS auditor approved organization Not anywhere on the page you linked. And a "PCI-DSS auditor approved organization" is not a "PCI-DSS approved scanning vendor" which if they were you could just quote the certificate number instead of link to HackerOne. ---- EDIT: I guess you are referring to this: > Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certif…
Read the page carefully - it specifically states they are an auditor approved org.
Quote from page: “Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.[1].”
Secondly, PayPal works with HackerOne officially [2] and within the CVSS standards as they clearly state on their HackerOne page, which is complying with PCI DSS.
[1] https://www.hackerone.com/product/challenge
[2] https://hackerone.com/paypal
Edit: Archived incase:
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#77Earlier quoted context omitted.
> but disclosing bugs publically is an addition to your resume Request disclosure on hackerone then. Idk, breaking the law to get a job doesn't seem ok to me.
The screenshot in #2 does show the H1 Staff screwing up -- @cybernews requests disclosure and gets a response saying "you may request disclosure if you would like this reviewed, using the drop down menu" (which @cybernews has already done). @cybernews' behavior in that thread isn't ideal, but they're more in the right than in the wrong on that one, judging by the screenshot.
At least Paypal was notified before the public disclosure!
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#78Earlier quoted context omitted.
GDPR max fine is (iirc) 4% of revenue. So if you are a small fish you will be paying less then the big fish. Also the fines are for wilful failure to comply, if you accidentally broke GDPR then your first offence is going to be more a slap on the wrist then an instant 4%.
Except it says "whichever" is higher, so if they decided to fine you 10 million or 2% of revenue, and your 2% is much lower than 10 million, guess which one you're paying... > Up to €10 million, or 2% of the worldwide annual revenue of the prior financial year, whichever is higher See: https://www.gdpreu.org/compliance/fines-and-penalties/
Fining a small mom and pop site 20 mill (20mil/4% is the highest fine depending on the case) is not proportionate, not effective because I would like to see them actually collect on that and I would say such a fine to a mom and pop would be dissuasive of doing business at all which is not that the ICO in the U.K. would want. Speaking of the ICO, their big fine (fucking auto correct) to BA for shockingly bad security earned them a 1.5% fine instead of the max 4% because they worked with the ICO (but the ICO still found they failing in a duty of care to protect data) and have been pushing the fine down the road ever since it was issued, atm the earliest ICO will actually fine BA is next month and it’s been almost a year since they filed their "intent to fine".
So while they can throw around heavy fines. It’s not like they run every mom and pop site out of the country.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#79Earlier quoted context omitted.
The market for a freelance security researcher out there is hard, no doubt, but disclosing bugs publically is an addition to your resume, akin to any other professional development you do. It demonstrates you can do the work and it shows the skills you have. Suing someone for disclosing an actual bug is a long term losing proposition for any company in a competitive industry.
> but disclosing bugs publically is an addition to your resume Request disclosure on hackerone then. Idk, breaking the law to get a job doesn't seem ok to me.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#80PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…
> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…
Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather than simply demonstrating aptitude directly.