Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

131–140 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#131
Unfortunately, for many companies, bug bounty programs have been the best invention in silencing security research and CVEs. They promise the world, beat you down on severity / payouts, sometimes just claim duplicate or known issue with no way to verify, and then block public disclosure. Very frustrating.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#132

I have not used Paypal since I had to file a dispute over an item I bought on ebay via Paypal. As a response they snail-mailed me a bunch of screenshots of an internal web-app with a bunch of info for someone else, SSN, CC number, address, etc. Everything I would need to do something bad. I called them and they did not seem to care so I called the guy (I had his number of course) but he never answered or responded to…

My experience with PayPal, from dev support to account managers, has been an absolute shit show. They were simply the first to their market and it's hard to kick them out.

It was difficult at first, this happened quite some time ago, but these days it seems there are lots of non-paypal options.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#133
post #66

Earlier quoted context omitted.

I've raised a chargeback with the issuing bank, which should hopefully make PayPal sit up and put a bit more effort into sorting this out. Or just close your account and ban you.

Possibly, a blog post will follow if that happens. PayPal has aways been a firewall around my creditcard number and I've never linked any other current account for pulling funds as, having worked in the payments industry, I know what a shit show it can be and that (in most cases, especially like this) the creditcard issuer will stand with the cardholder and not the merchant. Now i'm using other methods to pay for mos…

Try Privacy.com for a better creditcard firewall

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#134

PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…

PCI-DSS does not have Bug Bounty requirements. That's referring to ASV scans which have to be run quarterly by a specific list of vendors and then there's a dispute/remediation process.

Their response is dogshit but not for this reason.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#135

Earlier quoted context omitted.

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…

> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…

It's not a regulation. It's a contractual obligation between the merchant and the PCI counsel (which is made up by VISA/Mastercard/the backing banks/etc). It was put in place to avoid regulation.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#136

Earlier quoted context omitted.

> All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not. Please read the page again. They specifically say you can achieve compliance certification with HackerOne.

You achieve that compliance by paying HackerOne, as a company, to perform a compliance scan. This does not mean any swinging dick that reports a vulnerability through HackerOne is causing PayPal to fall out of compliance. These scans are planned well in advance and are part of a normal audit cycle. (edit: typo) On top of that, there's not really any legal issues for being non-compliant, as has been pointed out elsewh…

As someone who deals with PCI-DSS compliance in fintech land on a daily basis this thread is showing me there are a lot of people who like to crow on about stuff they don't know a thing about.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#137
post #97

Earlier quoted context omitted.

> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…

Why does the regulatory body get to approve who and what can scan implementations of their security scheme? It seems like the ideal auditor and scanning software, in PCI DSS's eyes, would be the one that just barely checks the boxes for minimum security requirements. Poking too hard at their security scheme would reveal how lackluster it is but they still need someone to poke at it to prove compliance. Being able to…

Because when you make the rules you get to make the rules?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#138
post #9

I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

> I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne. Sadly you can't feed your children from media drama. Maybe, in the long run, but it's more likely to get sued.

> Sadly you can't feed your children from media drama.

By the way, if the problem is "how do I reliably get money from bug bounties" (as opposed to "I found a cool bug, what do I do with it") --

I strongly recommend finding a product with some kind of barrier to entry. Most researchers on these platforms are very low-effort. A gigantic, complicated product, like Workday, or even better a gigantic, complicated product that requires payment (!), like Slack for Enterprise, will usually not be getting very many reports. That product is hard to understand. But that means that -- once you've put in the effort to understand the product -- there's a lot more low-hanging fruit, and the company is likely to treat researchers better because of the lower report volume.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#139

I have not used Paypal since I had to file a dispute over an item I bought on ebay via Paypal. As a response they snail-mailed me a bunch of screenshots of an internal web-app with a bunch of info for someone else, SSN, CC number, address, etc. Everything I would need to do something bad. I called them and they did not seem to care so I called the guy (I had his number of course) but he never answered or responded to…

What does CYA mean? Haven't seen this acronym before.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#140
post #39

Earlier quoted context omitted.

It's all that PayPal deserves of they get a pass for PCI-DSS non-compliance.

I'm sure that'll be a great comfort to the victims of whoever those flaws are sold to.

Who would you like to be upset with in a case where the black market is more efficient than HackerOne?

If the legitimate channels are not working then the system is broken and you should blame PayPal and HackerOne. Be pissed at PayPal for not making it easier to report real issues. Be pissed at PayPal for not finding the issues themselves.

Post reply on HN