From PayPal's response to a 2FA bypass: > If the attacker has the victim's password, they would already be able to gain access to the account via web UI too. As such, the account is already compromised. As such, there does not appear to be any security implications as a direct result of this behavior. Seriously? This means PayPal's 2FA is just security theater. I'd rather they didn't offer it at all in this case, at…
From reading a different article, the terminology seems to be a bone of contention here. This ’2FA' is an email message PayPal send when they detect a new login location. They do not call it 2FA and they do offer actual 2FA that cybernews have not bypassed.
“We found PayPal vulnerabilities and PayPal punished us for it”
91–100 of 337 posts
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#92Earlier quoted context omitted.
GDPR only charges big fines to big players.
https://www.gdpreu.org/compliance/fines-and-penalties/ > Up to €10 million, or 2% of the worldwide annual revenue of the prior financial year, whichever is higher I'm no lawyer, but this doesn't sound like it's just for the bigger players, at the minimum you'd be looking at some fines. At minimum you'd be paying 10 million if you incur that amount of fines. I guess it could be argued the 2% is geared towards hurting…
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#93Earlier quoted context omitted.
They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…
Their "In-Scope Vulnerabilities" explicitly includes XSS exploits, though, which they also closed as Not Applicable (after patching the issue). Tangentially, as a (former?) PayPal user, it's wild to see that they consider vulnerabilities involving stolen credentials as a non-issue. Why do they offer 2FA at all, then? e: After taking another look at that massive Out-of-Scope list, I'm having a hard time imagining a bu…
If that's all you can do, then this is a self-XSS, which is excluded.
#6 is much more clear; that one's very obviously a self-XSS.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#94HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…
I worked as a contractor for a company that's a household name in the US. I am now convinced that HackerOne only exists for CISOs to say "look, I'm doing something" during the 2-3 years they stay at a company. The cybersecurity team had a backlog of roughly 30 critical issues discovered internally before starting HackerOne. We were unable to fix those issues, or the ones reported to us, because we had no visibility i…
Little technical details, high on "let us handle this for you, we know hackers / Well throw a big Defcon party for anyone you want."
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#95Earlier quoted context omitted.
HackerOne states they are a PCI-DSS auditor approved organization [1]. [1] https://www.hackerone.com/product/challenge
Sorry, but you don't understand what you are looking at. All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not. And the "scans" the PCI-DSS standards refers to are standard pen-test and external vulnerability scans, usually conducted by an accounting company who will ce…
Please read the page again. They specifically say you can achieve compliance certification with HackerOne.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#96Earlier quoted context omitted.
reading both, looks to me like this is pretty much 2fa. isn't 2fa defined as a "second factor" beyond user:pass? isn't that what this bypass is about?
There is genuine disagreement about whether email qualifies as a second factor. As it is often just protected by a username and password the argument is that it's the same "something you know" factor as a password, or just an obfuscation of the same factor. I will say, that if cybernews have done what they say that they've done, and PayPal are claiming that it's not a concern, then PayPal are clearly in the wrong, an…
"CyberNews claims—and the company showed me a demonstration—that it can successfully login to an account using basic credentials on a new computer. "
So for now, I'd say they did what they're claiming
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#97Earlier quoted context omitted.
> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…
> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#98Earlier quoted context omitted.
> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…
> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…
PCI-DSS is not government regulation, but an industry created and enforced standard. Compliance is not mandated by federal law and only a couple of states have laws that reference it. For example, Nevada requires compliance while Washington doesn't require compliance but does remove liability for breaches for compliant businesses.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#99Earlier quoted context omitted.
no shit PCI-DSS is a farce it's just there to make people that don't know anything about technology feel better
It's certainly very effective at providing said people with a false sense of security. It's also another buzzword they can utilize to waste people's time during meetings.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#100Earlier quoted context omitted.
Upvoted, but not sure it's a tragedy. Much like that quote about democracy, it's a bad system, except the others are worse. Would be nice to have something better tho.
> the others are worse I think we need more experimentation with solutions to the (open-source) public goods problem before we can say that the others are worse. Ditto with experimentation on variants of democracy. Significantly harder to experiment with that than with open source funding though.
I don't really get the democracy comment.