Live data from Hacker News

Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

forbes.com

71–80 of 84 posts

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#71
post #66

Earlier quoted context omitted.

Or because you don't want to risk users forgetting very long passwords. (Everyone should be using a password manager, but sadly that isn't the case.) That's generally the reason that limit is set.

That certainly flies in the face of most recent recommendation. Recent NIST guidelines say not to do this, and NIST isn't really known for being adventureous. The current best practice is for people to use passphrases rather than complicated passwords. For this, a password length limit of 24 is simply not enough.

I'm no advocate of it; just explaining what's very likely their rationale, as opposed to them storing passwords in plaintext. Plaintext password storage still happens, but you wouldn't see that at a company like Paypal. (Plaintext credentials may be unintentionally present elsewhere, like debug logs, but a company like that isn't going to be so incompetent as to store them in plaintext in the database.)

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#72
post #28

Just as a PSA, it wasn't until I looked at one of these articles in the last few days about PayPal that a screenshot showing how to enable 2FA demonstrated that TOTP-based authenticator apps are now allowed. For the longest time, PayPal was only allowing 2FA SMS after they chucked their old physical security keys. Anyone who's been stuck on SMS may wish to login and switch over to TOTP.

I tried when they introduced that and gave up on it again: There is no way to mark a device as trusted, and I'm certainly not opening my 2FA app for every single login/payment. Also, this is 2020, where is WebAuthN? That would at least make the constant 2FA a bit more bearable.

Bitwarden and probably other password managers will put the OTP in your clipboard after filling your credentials in so you don’t have to open anything to get the TOTP.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#73

Earlier quoted context omitted.

You don't think they should challenge a company's claim, or should they, but not in the same article?

It's not the journalist's duty to ridicule anyone. Jon Stewart's "The Daily Show" was very entertaining, and even somewhat informative, but I think he would be one of the first to say that it wasn't journalism. I don't like corporate bullshit lingo either but when that's what they say as their formal statement to the press then relaying it is the journalistic duty. It's one thing if the company is outright lying, but…

You wouldn't need to take Jon Stewart's approach though. I'd be fine if the ridiculing comes from another party that the journalist gives room to. Ask a consumer advocate what they think of PayPal's statement, or ask an infosec professional.

Letting the PR speech stand by itself without large red arrows pointing at the absurdity gives it way too much power imho.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#74
post #28

Earlier quoted context omitted.

I tried when they introduced that and gave up on it again: There is no way to mark a device as trusted, and I'm certainly not opening my 2FA app for every single login/payment. Also, this is 2020, where is WebAuthN? That would at least make the constant 2FA a bit more bearable.

How many times per year do you pay someone with PayPal?

Every single login asks for TOTP, and sessions expire very quickly. Even the mobile app asks every time, even if you use some saved/authorized login method like fingerprint login.

For someone who uses PayPal for most online payments this can be extremely tedious.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#75
post #13

So NFC reading of embedded card details is always on, regardless of whether you are in "payments" mode or have the app open? Is that a PayPal flaw, or is it an Android/NFC/Google Payments flaw?

> So NFC reading of embedded card details is always on Apple have a similar option BUT they restrict its use to certain payment terminals (for example it is only supposed by TfL in the UK) and can be disabled if you want. Dunno if the data it exposes (in a physical read attack) could be used for other payments. > With Express Transit mode enabled, you don't have to validate with Face ID, Touch ID or your passcode whe…

Express Transit mode is also disabled by default.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#76

Earlier quoted context omitted.

How many times per year do you pay someone with PayPal?

Every single login asks for TOTP, and sessions expire very quickly. Even the mobile app asks every time, even if you use some saved/authorized login method like fingerprint login. For someone who uses PayPal for most online payments this can be extremely tedious.

None of this is relevant to the question asked. I understand it’s all correct, but it fails to answer the question of quantity over time presented.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#77

Earlier quoted context omitted.

It's not the journalist's duty to ridicule anyone. Jon Stewart's "The Daily Show" was very entertaining, and even somewhat informative, but I think he would be one of the first to say that it wasn't journalism. I don't like corporate bullshit lingo either but when that's what they say as their formal statement to the press then relaying it is the journalistic duty. It's one thing if the company is outright lying, but…

You wouldn't need to take Jon Stewart's approach though. I'd be fine if the ridiculing comes from another party that the journalist gives room to. Ask a consumer advocate what they think of PayPal's statement, or ask an infosec professional. Letting the PR speech stand by itself without large red arrows pointing at the absurdity gives it way too much power imho.

I "feel ya" but you've got those options already. In other words, maybe you're actually complaining about people's taste in news media?

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#78
post #66

Earlier quoted context omitted.

That certainly flies in the face of most recent recommendation. Recent NIST guidelines say not to do this, and NIST isn't really known for being adventureous. The current best practice is for people to use passphrases rather than complicated passwords. For this, a password length limit of 24 is simply not enough.

I'm no advocate of it; just explaining what's very likely their rationale, as opposed to them storing passwords in plaintext. Plaintext password storage still happens, but you wouldn't see that at a company like Paypal. (Plaintext credentials may be unintentionally present elsewhere, like debug logs, but a company like that isn't going to be so incompetent as to store them in plaintext in the database.)

We've literally seen larger companies be more incompetent.

There's no reason PayPal is excluded from this.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#79
post #78

Earlier quoted context omitted.

I'm no advocate of it; just explaining what's very likely their rationale, as opposed to them storing passwords in plaintext. Plaintext password storage still happens, but you wouldn't see that at a company like Paypal. (Plaintext credentials may be unintentionally present elsewhere, like debug logs, but a company like that isn't going to be so incompetent as to store them in plaintext in the database.)

We've literally seen larger companies be more incompetent. There's no reason PayPal is excluded from this.

Can you show me a larger payment-focused company that's been revealed to be storing passwords in plaintext within the past 5 years? Not saying there's not a ton of incompetence, but that's a very specific level of incompetence.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#80
post #78

Earlier quoted context omitted.

We've literally seen larger companies be more incompetent. There's no reason PayPal is excluded from this.

Can you show me a larger payment-focused company that's been revealed to be storing passwords in plaintext within the past 5 years? Not saying there's not a ton of incompetence, but that's a very specific level of incompetence.

Why does it have to be payment focused? There's tons of big tech companies that have done this.

Enjoy: https://github.com/plaintextoffenders/plaintextoffenders/blo...

It's not difficult to find them

Post reply on HN