Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

91–100 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#91

From PayPal's response to a 2FA bypass: > If the attacker has the victim's password, they would already be able to gain access to the account via web UI too. As such, the account is already compromised. As such, there does not appear to be any security implications as a direct result of this behavior. Seriously? This means PayPal's 2FA is just security theater. I'd rather they didn't offer it at all in this case, at…

From reading a different article, the terminology seems to be a bone of contention here. This ’2FA' is an email message PayPal send when they detect a new login location. They do not call it 2FA and they do offer actual 2FA that cybernews have not bypassed.

It's very obviously a distinction without a difference though. Like the authors say, this is a amazing opportunity for black-market paypal account buyers. It's the only line of defense that thousands of people have between black hats and their bank account. In any case, I'd definitely call this 2-factor authentication - the only difference is the trigger (every login vs suspicious logins). It just so happens that they have different code for each of those two cases, and these bounty hunters have discovered a bug in one of them.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#92

Earlier quoted context omitted.

GDPR only charges big fines to big players.

https://www.gdpreu.org/compliance/fines-and-penalties/ > Up to €10 million, or 2% of the worldwide annual revenue of the prior financial year, whichever is higher I'm no lawyer, but this doesn't sound like it's just for the bigger players, at the minimum you'd be looking at some fines. At minimum you'd be paying 10 million if you incur that amount of fines. I guess it could be argued the 2% is geared towards hurting…

At minimum you would be looking at "nothing". Between that and 2%/10 million there are many possibilities. Requiring to answer questions, warnings, requiring some changes etc. And even once it gets to the fine territory, getting things from the max end is not something that would always happen. Out of documented 208 cases (https://www.enforcementtracker.com/), there have been 6 fines that exceeded 10 million and another 4 that exceeded 1 million. Median seems to be around 10 000.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#93

Earlier quoted context omitted.

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

Their "In-Scope Vulnerabilities" explicitly includes XSS exploits, though, which they also closed as Not Applicable (after patching the issue). Tangentially, as a (former?) PayPal user, it's wild to see that they consider vulnerabilities involving stolen credentials as a non-issue. Why do they offer 2FA at all, then? e: After taking another look at that massive Out-of-Scope list, I'm having a hard time imagining a bu…

I can't really evaluate #5, but their screenshot undermines them -- it shows a chat session between the victim and "PayPal Virtual Agent", with the virtual agent offering some canned text.

If that's all you can do, then this is a self-XSS, which is excluded.

#6 is much more clear; that one's very obviously a self-XSS.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#94
post #73

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

I worked as a contractor for a company that's a household name in the US. I am now convinced that HackerOne only exists for CISOs to say "look, I'm doing something" during the 2-3 years they stay at a company. The cybersecurity team had a backlog of roughly 30 critical issues discovered internally before starting HackerOne. We were unable to fix those issues, or the ones reported to us, because we had no visibility i…

Ohh your very right. The sales team is very focused on "selling" to the CISO (rightly so I suppose). I was part of a team that got the big sales pitch.

Little technical details, high on "let us handle this for you, we know hackers / Well throw a big Defcon party for anyone you want."

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#95
post #83

Earlier quoted context omitted.

HackerOne states they are a PCI-DSS auditor approved organization [1]. [1] https://www.hackerone.com/product/challenge

Sorry, but you don't understand what you are looking at. All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not. And the "scans" the PCI-DSS standards refers to are standard pen-test and external vulnerability scans, usually conducted by an accounting company who will ce…

> All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not.

Please read the page again. They specifically say you can achieve compliance certification with HackerOne.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#96

Earlier quoted context omitted.

reading both, looks to me like this is pretty much 2fa. isn't 2fa defined as a "second factor" beyond user:pass? isn't that what this bypass is about?

There is genuine disagreement about whether email qualifies as a second factor. As it is often just protected by a username and password the argument is that it's the same "something you know" factor as a password, or just an obfuscation of the same factor. I will say, that if cybernews have done what they say that they've done, and PayPal are claiming that it's not a concern, then PayPal are clearly in the wrong, an…

In the forbes article cited above, the author says that cybernews showed it to him:

"CyberNews claims—and the company showed me a demonstration—that it can successfully login to an account using basic credentials on a new computer. "

So for now, I'd say they did what they're claiming

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#97

Earlier quoted context omitted.

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…

> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…

Why does the regulatory body get to approve who and what can scan implementations of their security scheme? It seems like the ideal auditor and scanning software, in PCI DSS's eyes, would be the one that just barely checks the boxes for minimum security requirements. Poking too hard at their security scheme would reveal how lackluster it is but they still need someone to poke at it to prove compliance. Being able to ignore anyone or anything that isn't on the approved list seems like willful negligence.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#98

Earlier quoted context omitted.

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…

> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…

> Actually this makes a pretty good case for this regulation being a joke.

PCI-DSS is not government regulation, but an industry created and enforced standard. Compliance is not mandated by federal law and only a couple of states have laws that reference it. For example, Nevada requires compliance while Washington doesn't require compliance but does remove liability for breaches for compliant businesses.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#99
post #71

Earlier quoted context omitted.

no shit PCI-DSS is a farce it's just there to make people that don't know anything about technology feel better

It's certainly very effective at providing said people with a false sense of security. It's also another buzzword they can utilize to waste people's time during meetings.

exactly, it is simply marketing (/ politics) really

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#100
post #84

Earlier quoted context omitted.

Upvoted, but not sure it's a tragedy. Much like that quote about democracy, it's a bad system, except the others are worse. Would be nice to have something better tho.

> the others are worse I think we need more experimentation with solutions to the (open-source) public goods problem before we can say that the others are worse. Ditto with experimentation on variants of democracy. Significantly harder to experiment with that than with open source funding though.

Open source is pretty successful if you include the plethora of knowledge it provides to new developers. It is difficult to quantify and it is symptomatic that there is litte prestige in commiting to any open source project.

I don't really get the democracy comment.

Post reply on HN