Live data from Hacker News

Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

forbes.com

1–10 of 84 posts

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#3
Even yesterday there was this thread https://news.ycombinator.com/item?id=22403565

PayPal needs to seriously reevaluate how they want to approach the vulnerabilities. Why have a bounty program if you are going to act hostile towards the white hat community or even ignore their reports?

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#4
post #3

Even yesterday there was this thread https://news.ycombinator.com/item?id=22403565 PayPal needs to seriously reevaluate how they want to approach the vulnerabilities. Why have a bounty program if you are going to act hostile towards the white hat community or even ignore their reports?

The two stories are unrelated, though the reporter cites the former. From the vulnerabilities disclosed in that report, it seems pretty unlikely that yesterday's stories caused a rash of thefts; they were all pretty low-severity.

Note that here, Paypal paid a substantial bounty a year ago.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#7
post #4
post #3

Even yesterday there was this thread https://news.ycombinator.com/item?id=22403565 PayPal needs to seriously reevaluate how they want to approach the vulnerabilities. Why have a bounty program if you are going to act hostile towards the white hat community or even ignore their reports?

The two stories are unrelated, though the reporter cites the former. From the vulnerabilities disclosed in that report, it seems pretty unlikely that yesterday's stories caused a rash of thefts; they were all pretty low-severity. Note that here, Paypal paid a substantial bounty a year ago.

From the article:

“We reported this in February 2019 to PayPal via HackerOne,” they say. “After an initial rejection and several discussions, PayPal paid a bug bounty of $4,400.” The pair have not heard from PayPal, they say, since April 2019. But this week “tried and could still use the virtual credit card for online payments.” That means, they told me, “the bug has not been fixed.”

To reiterate the OP, what is the point of a bug bounty program that ignores or fails to address reported issues?

> The two stories are unrelated

They are related in the sense that both stories show a failure to respond to reported issues.

> Note that here, Paypal paid a substantial bounty a year ago.

They paid but didn’t fix the issue? This is not taking account security serious at all.

At best, PayPal has a critical flaw in their bug bounty program.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#8
> “We reported this in February 2019 to PayPal via HackerOne,” they say. “After an initial rejection and several discussions, PayPal paid a bug bounty of $4,400.” The pair have not heard from PayPal, they say, since April 2019. But this week “tried and could still use the virtual credit card for online payments.” That means, they told me, “the bug has not been fixed.”

> But in terms of the Fenske and Mayer disclosure, the researchers told me that this is not fixed, even after PayPal’s “mitigation” statement.

If Paypal has known about it for a year and it still isn't fixed, then it means that either 1. Paypal didn't understand the bug report and "fixed" something else 2. Paypal understood the bug report, didn't fix it, and is trying to save face. Either one of those sounds pretty bad for their security policy...

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#10
> PayPal told me that “the security of customer accounts is a top priority for the company.”

I wish journalists would ridicule this corporate bullshit lingo instead of just relaying it. I'm fairly certain that anyone that ever had contact with PayPal's (or Amazon's, or probably any other large corporation's) customer service with issues regarding security can attest that it's absolutely not one of their top priorities.

They haven't even bothered to make their official emails not look like phishing attempts. They don't care about security.

Post reply on HN