Earlier quoted context omitted.
Or because you don't want to risk users forgetting very long passwords. (Everyone should be using a password manager, but sadly that isn't the case.) That's generally the reason that limit is set.
That certainly flies in the face of most recent recommendation. Recent NIST guidelines say not to do this, and NIST isn't really known for being adventureous. The current best practice is for people to use passphrases rather than complicated passwords. For this, a password length limit of 24 is simply not enough.
Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
71–80 of 84 posts
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#72Just as a PSA, it wasn't until I looked at one of these articles in the last few days about PayPal that a screenshot showing how to enable 2FA demonstrated that TOTP-based authenticator apps are now allowed. For the longest time, PayPal was only allowing 2FA SMS after they chucked their old physical security keys. Anyone who's been stuck on SMS may wish to login and switch over to TOTP.
I tried when they introduced that and gave up on it again: There is no way to mark a device as trusted, and I'm certainly not opening my 2FA app for every single login/payment. Also, this is 2020, where is WebAuthN? That would at least make the constant 2FA a bit more bearable.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#73Earlier quoted context omitted.
You don't think they should challenge a company's claim, or should they, but not in the same article?
It's not the journalist's duty to ridicule anyone. Jon Stewart's "The Daily Show" was very entertaining, and even somewhat informative, but I think he would be one of the first to say that it wasn't journalism. I don't like corporate bullshit lingo either but when that's what they say as their formal statement to the press then relaying it is the journalistic duty. It's one thing if the company is outright lying, but…
Letting the PR speech stand by itself without large red arrows pointing at the absurdity gives it way too much power imho.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#74Earlier quoted context omitted.
I tried when they introduced that and gave up on it again: There is no way to mark a device as trusted, and I'm certainly not opening my 2FA app for every single login/payment. Also, this is 2020, where is WebAuthN? That would at least make the constant 2FA a bit more bearable.
How many times per year do you pay someone with PayPal?
For someone who uses PayPal for most online payments this can be extremely tedious.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#75So NFC reading of embedded card details is always on, regardless of whether you are in "payments" mode or have the app open? Is that a PayPal flaw, or is it an Android/NFC/Google Payments flaw?
> So NFC reading of embedded card details is always on Apple have a similar option BUT they restrict its use to certain payment terminals (for example it is only supposed by TfL in the UK) and can be disabled if you want. Dunno if the data it exposes (in a physical read attack) could be used for other payments. > With Express Transit mode enabled, you don't have to validate with Face ID, Touch ID or your passcode whe…
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#76Earlier quoted context omitted.
How many times per year do you pay someone with PayPal?
Every single login asks for TOTP, and sessions expire very quickly. Even the mobile app asks every time, even if you use some saved/authorized login method like fingerprint login. For someone who uses PayPal for most online payments this can be extremely tedious.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#77Earlier quoted context omitted.
It's not the journalist's duty to ridicule anyone. Jon Stewart's "The Daily Show" was very entertaining, and even somewhat informative, but I think he would be one of the first to say that it wasn't journalism. I don't like corporate bullshit lingo either but when that's what they say as their formal statement to the press then relaying it is the journalistic duty. It's one thing if the company is outright lying, but…
You wouldn't need to take Jon Stewart's approach though. I'd be fine if the ridiculing comes from another party that the journalist gives room to. Ask a consumer advocate what they think of PayPal's statement, or ask an infosec professional. Letting the PR speech stand by itself without large red arrows pointing at the absurdity gives it way too much power imho.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#78Earlier quoted context omitted.
That certainly flies in the face of most recent recommendation. Recent NIST guidelines say not to do this, and NIST isn't really known for being adventureous. The current best practice is for people to use passphrases rather than complicated passwords. For this, a password length limit of 24 is simply not enough.
I'm no advocate of it; just explaining what's very likely their rationale, as opposed to them storing passwords in plaintext. Plaintext password storage still happens, but you wouldn't see that at a company like Paypal. (Plaintext credentials may be unintentionally present elsewhere, like debug logs, but a company like that isn't going to be so incompetent as to store them in plaintext in the database.)
There's no reason PayPal is excluded from this.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#79Earlier quoted context omitted.
I'm no advocate of it; just explaining what's very likely their rationale, as opposed to them storing passwords in plaintext. Plaintext password storage still happens, but you wouldn't see that at a company like Paypal. (Plaintext credentials may be unintentionally present elsewhere, like debug logs, but a company like that isn't going to be so incompetent as to store them in plaintext in the database.)
We've literally seen larger companies be more incompetent. There's no reason PayPal is excluded from this.
Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings
#80Earlier quoted context omitted.
We've literally seen larger companies be more incompetent. There's no reason PayPal is excluded from this.
Can you show me a larger payment-focused company that's been revealed to be storing passwords in plaintext within the past 5 years? Not saying there's not a ton of incompetence, but that's a very specific level of incompetence.
Enjoy: https://github.com/plaintextoffenders/plaintextoffenders/blo...
It's not difficult to find them