Live data from Hacker News

Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

forbes.com

41–50 of 84 posts

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#41

Earlier quoted context omitted.

You're talking about blurring the difference between journalism and opinion.

Journalism is opinion. It's the opinion of the journalist: is this information worth writing about? It's the opinion of the editor: is this part worth changing? It's the opinion of the publisher: is this piece worth publishing?

Maybe I'm just getting old, but this sounds like the lyrics to a bad 80's punk rock song.

https://en.wikipedia.org/wiki/Right_of_reply

> The right of reply or right of correction generally means the right to defend oneself against public criticism in the same venue where it was published. In some countries, such as Brazil, it is a legal or even constitutional right. In other countries, it is not a legal right as such, but a right which certain media outlets and publications choose to grant to people who have been severely criticised by them, as a matter of editorial policy.

You might not like it but it is a thing.

And if they choose to defend themselves with a load of PR doublespeak BS, well, that's also news, eh?

If the reporter adds "...which is obviously bullshit." at the end that's the difference between journalism and a SNL sketch. ( https://www.youtube.com/watch?v=i9qblOghuKk )

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#42

Earlier quoted context omitted.

You're talking about blurring the difference between journalism and opinion.

No, the journalist could easily find independent evidence that suggests the corporate statement is bullshit. It should be challenged and ridiculed. That is the journalist's duty, and they failed. Their job is not to be a copy and paste machine for company press releases.

I agree with your first and third sentences, but not your second.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#43
post #7
post #4

Earlier quoted context omitted.

The two stories are unrelated, though the reporter cites the former. From the vulnerabilities disclosed in that report, it seems pretty unlikely that yesterday's stories caused a rash of thefts; they were all pretty low-severity. Note that here, Paypal paid a substantial bounty a year ago.

From the article: “We reported this in February 2019 to PayPal via HackerOne,” they say. “After an initial rejection and several discussions, PayPal paid a bug bounty of $4,400.” The pair have not heard from PayPal, they say, since April 2019. But this week “tried and could still use the virtual credit card for online payments.” That means, they told me, “the bug has not been fixed.” To reiterate the OP, what is the…

At best, PayPal has a critical flaw [...]

This seems curiously confident given that just about every single one of your many comments on the other story was inaccurate or a misinterpretation.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#44
post #4
post #3

Even yesterday there was this thread https://news.ycombinator.com/item?id=22403565 PayPal needs to seriously reevaluate how they want to approach the vulnerabilities. Why have a bounty program if you are going to act hostile towards the white hat community or even ignore their reports?

The two stories are unrelated, though the reporter cites the former. From the vulnerabilities disclosed in that report, it seems pretty unlikely that yesterday's stories caused a rash of thefts; they were all pretty low-severity. Note that here, Paypal paid a substantial bounty a year ago.

> Note that here, Paypal paid a substantial bounty a year ago.

$4400 is not a substantial bounty for a bug of this severity, compared to the value on the black market. Like, the article even cites that attackers have extracted over $1000 from some individuals, multiply by thousands of users.

The black market value of this exploit is certainly into the hundreds of thousands.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#45
post #43
post #7

Earlier quoted context omitted.

From the article: “We reported this in February 2019 to PayPal via HackerOne,” they say. “After an initial rejection and several discussions, PayPal paid a bug bounty of $4,400.” The pair have not heard from PayPal, they say, since April 2019. But this week “tried and could still use the virtual credit card for online payments.” That means, they told me, “the bug has not been fixed.” To reiterate the OP, what is the…

At best, PayPal has a critical flaw [...] This seems curiously confident given that just about every single one of your many comments on the other story was inaccurate or a misinterpretation.

> This seems curiously confident given that just about every single one of your many comments on the other story was inaccurate or a misinterpretation.

So you don’t think that sending a bug bounty reward a year ago to a security researcher who exposed a flaw, that is still being exploited to take money from people, is a critical flaw in the program?

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#46
post #44
post #4

Earlier quoted context omitted.

The two stories are unrelated, though the reporter cites the former. From the vulnerabilities disclosed in that report, it seems pretty unlikely that yesterday's stories caused a rash of thefts; they were all pretty low-severity. Note that here, Paypal paid a substantial bounty a year ago.

> Note that here, Paypal paid a substantial bounty a year ago. $4400 is not a substantial bounty for a bug of this severity, compared to the value on the black market. Like, the article even cites that attackers have extracted over $1000 from some individuals, multiply by thousands of users. The black market value of this exploit is certainly into the hundreds of thousands.

You'll excuse me if I don't take this very seriously given that on previous threads people have --- not making this up --- made cases for logout CSRFs having high value on the black market. After all: the competitors to the vulnerable service could have used logout CSRFs to drive customers away!

Vulnerabilities are worth money in markets when they fit into pre-existing business/operational models. That's why clientside RCE in popular clients is valuable: multiple competing buyers have whole operational frameworks where new RCEs are drop-in compatible. Nobody speculatively builds new business models around the prospect of a random serverside vulnerability.

Maybe a vulnerability like this has value --- we don't know what it is, or how much interaction is required, or how quickly it could have been killed --- if it directly produces cash every time it's applied. But that's still a maybe for a serverside vulnerability with a half-life of epsilon.

Meanwhile: $4400 is a strong bounty for a serverside logic vulnerability. Serious vulnerabilities like stored XSS have bounty values in the hundreds of dollars despite the fact that people on HN seem to think they're worth 6 figures on some hypothetical black market.

I have no opinion about how Paypal handled this vulnerability after paying up for it; I'm exclusively interested in how this story intersects with yesterday's Paypal thread, which was a shitshow.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#47
post #46
post #44

Earlier quoted context omitted.

> Note that here, Paypal paid a substantial bounty a year ago. $4400 is not a substantial bounty for a bug of this severity, compared to the value on the black market. Like, the article even cites that attackers have extracted over $1000 from some individuals, multiply by thousands of users. The black market value of this exploit is certainly into the hundreds of thousands.

You'll excuse me if I don't take this very seriously given that on previous threads people have --- not making this up --- made cases for logout CSRFs having high value on the black market. After all: the competitors to the vulnerable service could have used logout CSRFs to drive customers away! Vulnerabilities are worth money in markets when they fit into pre-existing business/operational models. That's why clientsi…

The business model already exists: order videogame consoles or luxury purses or some other high-value good that is easily fungible with cash (Craigslist) and then either porch pirate the package when it arrives, or if you're brazen enough just order it right to yourself.

This is something that is routinely done already with credit card fraud. This is how thieves "cash out" the cards they steal with skimmers at gas pumps and stores.

The angle here is that they no longer need to steal your digits with a skimmer, they can just use your contactless payment wallet, because Paypal didn't lock them down properly. Or so the researchers allege (they don't give the exact details of the vuln for obvious reasons).

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#48
post #47
post #46

Earlier quoted context omitted.

You'll excuse me if I don't take this very seriously given that on previous threads people have --- not making this up --- made cases for logout CSRFs having high value on the black market. After all: the competitors to the vulnerable service could have used logout CSRFs to drive customers away! Vulnerabilities are worth money in markets when they fit into pre-existing business/operational models. That's why clientsi…

The business model already exists: order videogame consoles or luxury purses or some other high-value good that is easily fungible with cash (Craigslist) and then either porch pirate the package when it arrives, or if you're brazen enough just order it right to yourself. This is something that is routinely done already with credit card fraud. This is how thieves "cash out" the cards they steal with skimmers at gas pu…

That's like saying the existing business model is "crime". What I'm talking about is all the support code and processes that go into operationalizing a vulnerability. Again: it depends on what the vulnerability is, and we don't know, but if it's an elaborate serverside vulnerability that requires user interaction specific to this vulnerability, I'm comfortable out on the limb that says nobody is bidding against anyone to buy this on any black market.

You're also only responding to a fraction of my argument. Even for clientside RCE, alternate market buyers don't pay full freight in a lump sum: they tranche payments because they know vendors will eventually kill the vulnerability and nobody is sure how long that will take. Here, you have a vulnerability where you'd more or less have to get paid royalties from direct fraud, because, again, Paypal can presumably kill the bug instantly.

If you have more specific details on the vulnerability that will enable you to make a clearer case for how this could drop into a system of repeated profitable attacks, provide them. I'm interested in hearing them.

Otherwise, my default response to people saying "this bounty is too cheap because the black market would pay 10x for it" is "yeah, sure, and for logout CSRFs too".

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#49
post #43

Earlier quoted context omitted.

At best, PayPal has a critical flaw [...] This seems curiously confident given that just about every single one of your many comments on the other story was inaccurate or a misinterpretation.

> This seems curiously confident given that just about every single one of your many comments on the other story was inaccurate or a misinterpretation. So you don’t think that sending a bug bounty reward a year ago to a security researcher who exposed a flaw, that is still being exploited to take money from people, is a critical flaw in the program?

Do I think it's possible PayPal had an incomplete fix or had a regression or an organizational screwup of some kind? Absolutely, that is possible.

Do I think your 'motivated googling' approach to analyzing either story is likely to produce worthwhile insight? Not really. We've already seen it be remarkably inaccurate.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#50
post #25

> “We reported this in February 2019 to PayPal via HackerOne,” they say. “After an initial rejection and several discussions, PayPal paid a bug bounty of $4,400.” The pair have not heard from PayPal, they say, since April 2019. But this week “tried and could still use the virtual credit card for online payments.” That means, they told me, “the bug has not been fixed.” > But in terms of the Fenske and Mayer disclosure…

As for paypal's security policy, note that they have a maximum password length of 24 characters, and routinely send people e-mails with a big 'log-in' link. These are both bad practice. The password length limit reduces the quality of passwords, and suggests plain-text storage of passwords. The sending of log-in links makes people much easier to phish, since people are used to clicking on a link in e-mail and then en…

Recently, I received an E-Mail which looked a lot like a phishing attempt. It contained a link to sign in to "paypal.com", but when hovering over the link, it was revealed to be something like "https://epl.paypal-communication.com/T/ve3648d90e0f976ec10e4.... Really stupid idea to make users believe that "https://random.paypal-suffix.com" might be legit. I wonder why domains like "paypal-comunication.com" are not registered for nefarious purposes yet.
Post reply on HN