Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

171–180 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#171

Earlier quoted context omitted.

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…

> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…

PCI-DSS is a joke, just look at all the zero days that have gone on before today, Comodo the CA hacked, DigiNotar to name a few, the recent zero day in Windows hilighted by none other than the NSA back in Jan. The public have ADHD attention spans, so who cares as long as the money keeps rolling in hey? Do you think your politicians, law enforcement, big businesses or Banksters give a toss? Criminals rule the world and its been going on for thousands of years with people believing in things like Religion and Royalty!

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#172

Earlier quoted context omitted.

> If we want to be cynical, of course there was a self-serving reason they created the standards It's not cynical, it is literally the reason PCI exists. > Five different programs had been started by card companies... The intentions of each were roughly similar: to create an additional level of protection for card issuers - https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec...

Protection from fraud . Fraud costs the credit card industry money. It makes people less likely to trust/use them, which then costs them business. You said - "avoid actually being regulated and are a way to shift liability" This is like saying a store put razors in a locked case to avoid being regulated. Or they simply don't want their stuff stolen? I was being facetious when I said if we want to be cynical, because…

> Or they simply don't want their stuff stolen?

Equating credit card fraud to physical theft is silly. The intermediaries of the credit card industry earn revenue by charging fees to process transactions. When fraud occurs, they're only liable if they were some how responsible. PCI allows the network to shift liability to the periphery and to allow the central network to deny taking responsibility for systemic problems with the infrastructure.

To use your razors analogy, PCI is like Gillette shipping razors lose in a box to CVS and telling the store that it is liable if anyone gets cut or the razors get stolen AND Gillette can fine them if anyone gets cut or razors get stolen. But that's not how it works, in the real world razors come with safety covers in tamper evident sealed plastic clam shells.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#173
If you are receiving your money or reputation from a platform (like HackerOne) then you are going to be underappreciated, undervalued, and treated like an expense that should be minimized.

Here is what responsible disclosure looks like in 2020 from somebody that has self-worth:

> (Message posted to Hacker One, and emailed to any address you can find, and sent in a letter by mail. Yes mail. Also copied in all those ways to investors of the target.)

>

> Dear Sir or Madam:

>

> I have learned about a security issue in PayPal's service. This includes being able to login to user accounts without the credentials the system is expecting. [Be vague about how exactly it works, but explain the impact.]

>

> I am not an employee or contractor of PayPal and I will publish this on my blog at https://privacylog.blogspot.com to build on my reputation for finding and improving the security of internet systems.

>

> This post will publish on 2020-03-09, which is two weeks from today.

>

> If you are committed to fix this issue before public disclosure, I will be happy to work with you. You can contact me at ...

---

Key points:

- The discussion is about my reputation and values. - I am not demanding any payment (not sure if that is legal). - Set a firm publish date. - This asks them to make a commitment to fix and frames the discussion going forward.

And if they do not get back to you, then when you publish you explain it just like you see in newspapers: "the vendor failed to respond and act on this report when I contacted them by email, social media and paper mail with two weeks' notice".

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#174

Earlier quoted context omitted.

They were created for sincere reasons, and with best intentions. In the real world best intentions always conflict with the motivations of individual players. It just isn't reasonable that PayPal would be cut off. That was always a toothless threat, at least for larger players. As an aside, PayPal is a marvel to me because it is effectively lost in time. Using their tools and interface is like stepping back to 1995,…

> They were created for sincere reasons, and with best intentions. No? They were created by the industry to avoid actually being regulated and are a way to shift liability. That doesn't mean they aren't also beneficial, but that's more a side effect than the intention.

[deleted]

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#175

Earlier quoted context omitted.

There is genuine disagreement about whether email qualifies as a second factor. As it is often just protected by a username and password the argument is that it's the same "something you know" factor as a password, or just an obfuscation of the same factor. I will say, that if cybernews have done what they say that they've done, and PayPal are claiming that it's not a concern, then PayPal are clearly in the wrong, an…

it's not just email, its phone also. i recently recently logged inco company paypal from out of country and paypal complained it wants to confirm account via email, fine i confirmed. and then it said it also needs to conform the via phone. ie a call. so it is a form of 2fa. can i also complain how is 2fa a pain if multiple persons use that account. you cannot enable it if they allow only one user per account. there a…

I haven't looked at PayPal specifically, but if it's a standard authenticator app can you not both set it up via the QR code when you enable it while everybody is present?

However, obviously the real answer is to add multiple users to the same paypal account, which apparently you can do with a PayPal Business account.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#176

Earlier quoted context omitted.

I keep thinking we need some sort of new license for open source that limits which entities can use the software based on their net worth or the networth of their shareholders. That way large companies like Google can automatically fund these long tail of projects without burdening casual hackers or startups with unnecessary costs.

> I keep thinking we need some sort of new license for open source that limits which entities can use the software based on their net worth or the networth of their shareholders. That might be a new license, but it is by definition not open source. And, no, companies like Google won't “automatically” buy commercial software with that style of license; from their perspective it's worse than regular commercial software…

Hey, try not insulting people that are trying to have a reasonable conversation.

> EDIT: How about instead a “new” license that, if you feel the software isn't maintained adequately for the needs of your organization, allows you to hire whoever you want to maintain it to your requirements, instead of impotently raging that other people aren't supporting it?

It makes sense for the people that are getting the most profit from a piece of software to be the ones paying for basic maintenance/cleanup/improvements.

If you want customizations or new features, that's when it makes the most sense to 100% self-fund.

> it has all the downsides of traditional commercial software plus gives a competitive advantage to upstart competitors

On average, I'd expect it to still be a lot cheaper than commercial closed-source software.

And what exactly do you mean by competitive advantage here?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#177
post #83

Earlier quoted context omitted.

Sorry, but you don't understand what you are looking at. All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not. And the "scans" the PCI-DSS standards refers to are standard pen-test and external vulnerability scans, usually conducted by an accounting company who will ce…

> All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not. Please read the page again. They specifically say you can achieve compliance certification with HackerOne.

The page only says that they do external security scans that other companies who do the actual certification recognize as valid scans. They certify no one themselves.

Further, that has absolutely nothing to do with anyone reporting vulnerabilities through HackerOne. That is not a scan by the definition of PCI-DSS, the SOC2 trust services criteria, or any other security framework you care to name.

Just give it up. You're wrong.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#178

PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…

Former QSA here....and that external scanning vendor (one in each quarter) and two required Pen Tests per year had not be HackerOne carrying them out. Automatic conflict of interest. HackerOne has a vested interest in a clean scan and making Paypal look good.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#179
post #139

I have not used Paypal since I had to file a dispute over an item I bought on ebay via Paypal. As a response they snail-mailed me a bunch of screenshots of an internal web-app with a bunch of info for someone else, SSN, CC number, address, etc. Everything I would need to do something bad. I called them and they did not seem to care so I called the guy (I had his number of course) but he never answered or responded to…

What does CYA mean? Haven't seen this acronym before.

[deleted]
Post reply on HN