> PayPal told me that “the security of customer accounts is a top priority for the company.” I wish journalists would ridicule this corporate bullshit lingo instead of just relaying it. I'm fairly certain that anyone that ever had contact with PayPal's (or Amazon's, or probably any other large corporation's) customer service with issues regarding security can attest that it's absolutely not one of their top prioritie…
It's called the "right of reply". It's courtesy to reach out to a company and include their response without critique about whether it's "corporate bullshit".
Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
21–30 of 84 posts
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#22So NFC reading of embedded card details is always on, regardless of whether you are in "payments" mode or have the app open? Is that a PayPal flaw, or is it an Android/NFC/Google Payments flaw?
[1] https://en.wikipedia.org/wiki/EMV
[2] https://www.eftlab.com/knowledge-base/145-emv-nfc-tags/
[3] https://play.google.com/store/apps/details?id=com.github.dev...
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#23Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#24Earlier quoted context omitted.
It's called the "right of reply". It's courtesy to reach out to a company and include their response without critique about whether it's "corporate bullshit".
I agree that reaching out to whomever's being criticised is a courtesy and, sometimes, even legally required. But I don't think it's right to not critique. When a company blatantly uses doublespeak, that should absolutely be critiqued.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#25> “We reported this in February 2019 to PayPal via HackerOne,” they say. “After an initial rejection and several discussions, PayPal paid a bug bounty of $4,400.” The pair have not heard from PayPal, they say, since April 2019. But this week “tried and could still use the virtual credit card for online payments.” That means, they told me, “the bug has not been fixed.” > But in terms of the Fenske and Mayer disclosure…
These are both bad practice. The password length limit reduces the quality of passwords, and suggests plain-text storage of passwords. The sending of log-in links makes people much easier to phish, since people are used to clicking on a link in e-mail and then entering their credentials on the site.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#26Anyone who's been stuck on SMS may wish to login and switch over to TOTP.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#27Earlier quoted context omitted.
I agree that reaching out to whomever's being criticised is a courtesy and, sometimes, even legally required. But I don't think it's right to not critique. When a company blatantly uses doublespeak, that should absolutely be critiqued.
You're talking about blurring the difference between journalism and opinion.
It should be challenged and ridiculed. That is the journalist's duty, and they failed.
Their job is not to be a copy and paste machine for company press releases.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#28Just as a PSA, it wasn't until I looked at one of these articles in the last few days about PayPal that a screenshot showing how to enable 2FA demonstrated that TOTP-based authenticator apps are now allowed. For the longest time, PayPal was only allowing 2FA SMS after they chucked their old physical security keys. Anyone who's been stuck on SMS may wish to login and switch over to TOTP.
Also, this is 2020, where is WebAuthN? That would at least make the constant 2FA a bit more bearable.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#29> “We reported this in February 2019 to PayPal via HackerOne,” they say. “After an initial rejection and several discussions, PayPal paid a bug bounty of $4,400.” The pair have not heard from PayPal, they say, since April 2019. But this week “tried and could still use the virtual credit card for online payments.” That means, they told me, “the bug has not been fixed.” > But in terms of the Fenske and Mayer disclosure…
As for paypal's security policy, note that they have a maximum password length of 24 characters, and routinely send people e-mails with a big 'log-in' link. These are both bad practice. The password length limit reduces the quality of passwords, and suggests plain-text storage of passwords. The sending of log-in links makes people much easier to phish, since people are used to clicking on a link in e-mail and then en…
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#30As a power user of Google Pay in conjunction with PayPal (in Germany) should I be worried now and remove - as recommended - my PayPal account from Google Pay? A lot of people around me also use it the same way as I do and no one heard of any such incident yet. Well, now that I told them, of course everyone heard of it at least ... What are those "multiple reports"? I see the source is golem.de (don't get me started o…
> Also the article states that Google Pay provides a virtual credit card when used with PayPal. How? All I saw up until now was virtual debit cards. Naming confusion, I think. To some people (mostly Americans), credit and debit cards are the same thing - just plastic payment cards. Some Europeans think Visa/Mastercard can only be credit cards (they can be either credit or debit). To me, the difference is that credit…