Live data from Hacker News

Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

forbes.com

21–30 of 84 posts

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#21
post #19

> PayPal told me that “the security of customer accounts is a top priority for the company.” I wish journalists would ridicule this corporate bullshit lingo instead of just relaying it. I'm fairly certain that anyone that ever had contact with PayPal's (or Amazon's, or probably any other large corporation's) customer service with issues regarding security can attest that it's absolutely not one of their top prioritie…

It's called the "right of reply". It's courtesy to reach out to a company and include their response without critique about whether it's "corporate bullshit".

I agree that reaching out to whomever's being criticised is a courtesy and, sometimes, even legally required. But I don't think it's right to not critique. When a company blatantly uses doublespeak, that should absolutely be critiqued.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#22
post #13

So NFC reading of embedded card details is always on, regardless of whether you are in "payments" mode or have the app open? Is that a PayPal flaw, or is it an Android/NFC/Google Payments flaw?

That's an EMV [1] standard and there is a lot more info you can get [2] from your card. There are plenty of apps you can use to read your card [3].

[1] https://en.wikipedia.org/wiki/EMV

[2] https://www.eftlab.com/knowledge-base/145-emv-nfc-tags/

[3] https://play.google.com/store/apps/details?id=com.github.dev...

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#24
post #19

Earlier quoted context omitted.

It's called the "right of reply". It's courtesy to reach out to a company and include their response without critique about whether it's "corporate bullshit".

I agree that reaching out to whomever's being criticised is a courtesy and, sometimes, even legally required. But I don't think it's right to not critique. When a company blatantly uses doublespeak, that should absolutely be critiqued.

You're talking about blurring the difference between journalism and opinion.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#25

> “We reported this in February 2019 to PayPal via HackerOne,” they say. “After an initial rejection and several discussions, PayPal paid a bug bounty of $4,400.” The pair have not heard from PayPal, they say, since April 2019. But this week “tried and could still use the virtual credit card for online payments.” That means, they told me, “the bug has not been fixed.” > But in terms of the Fenske and Mayer disclosure…

As for paypal's security policy, note that they have a maximum password length of 24 characters, and routinely send people e-mails with a big 'log-in' link.

These are both bad practice. The password length limit reduces the quality of passwords, and suggests plain-text storage of passwords. The sending of log-in links makes people much easier to phish, since people are used to clicking on a link in e-mail and then entering their credentials on the site.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#26
Just as a PSA, it wasn't until I looked at one of these articles in the last few days about PayPal that a screenshot showing how to enable 2FA demonstrated that TOTP-based authenticator apps are now allowed. For the longest time, PayPal was only allowing 2FA SMS after they chucked their old physical security keys.

Anyone who's been stuck on SMS may wish to login and switch over to TOTP.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#27

Earlier quoted context omitted.

I agree that reaching out to whomever's being criticised is a courtesy and, sometimes, even legally required. But I don't think it's right to not critique. When a company blatantly uses doublespeak, that should absolutely be critiqued.

You're talking about blurring the difference between journalism and opinion.

No, the journalist could easily find independent evidence that suggests the corporate statement is bullshit.

It should be challenged and ridiculed. That is the journalist's duty, and they failed.

Their job is not to be a copy and paste machine for company press releases.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#28

Just as a PSA, it wasn't until I looked at one of these articles in the last few days about PayPal that a screenshot showing how to enable 2FA demonstrated that TOTP-based authenticator apps are now allowed. For the longest time, PayPal was only allowing 2FA SMS after they chucked their old physical security keys. Anyone who's been stuck on SMS may wish to login and switch over to TOTP.

I tried when they introduced that and gave up on it again: There is no way to mark a device as trusted, and I'm certainly not opening my 2FA app for every single login/payment.

Also, this is 2020, where is WebAuthN? That would at least make the constant 2FA a bit more bearable.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#29
post #25

> “We reported this in February 2019 to PayPal via HackerOne,” they say. “After an initial rejection and several discussions, PayPal paid a bug bounty of $4,400.” The pair have not heard from PayPal, they say, since April 2019. But this week “tried and could still use the virtual credit card for online payments.” That means, they told me, “the bug has not been fixed.” > But in terms of the Fenske and Mayer disclosure…

As for paypal's security policy, note that they have a maximum password length of 24 characters, and routinely send people e-mails with a big 'log-in' link. These are both bad practice. The password length limit reduces the quality of passwords, and suggests plain-text storage of passwords. The sending of log-in links makes people much easier to phish, since people are used to clicking on a link in e-mail and then en…

I’ve been telling friends and family, for at least 10 years, maybe more, the only safe way to go to PayPal, is to type the address into the browser yourself, starting with HTTPS.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#30
post #16

As a power user of Google Pay in conjunction with PayPal (in Germany) should I be worried now and remove - as recommended - my PayPal account from Google Pay? A lot of people around me also use it the same way as I do and no one heard of any such incident yet. Well, now that I told them, of course everyone heard of it at least ... What are those "multiple reports"? I see the source is golem.de (don't get me started o…

> Also the article states that Google Pay provides a virtual credit card when used with PayPal. How? All I saw up until now was virtual debit cards. Naming confusion, I think. To some people (mostly Americans), credit and debit cards are the same thing - just plastic payment cards. Some Europeans think Visa/Mastercard can only be credit cards (they can be either credit or debit). To me, the difference is that credit…

For added confusion, credit and debit cards have different processing networks, with the debit networks having much lower fees. And in the US at least, virtually all debit cards can also be processed as credit if the store doesn't accept debit directly (eg online payments). And while in Europe all cards have PINs, in the US only debit cards have PINs, and running then as credit allows you to bypass the PIN requirement.
Post reply on HN