Live data from Hacker News

Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

forbes.com

81–84 of 84 posts

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#81
post #80

Earlier quoted context omitted.

Can you show me a larger payment-focused company that's been revealed to be storing passwords in plaintext within the past 5 years? Not saying there's not a ton of incompetence, but that's a very specific level of incompetence.

Why does it have to be payment focused? There's tons of big tech companies that have done this. Enjoy: https://github.com/plaintextoffenders/plaintextoffenders/blo... It's not difficult to find them

I'm just saying a company like Paypal which is both massive and dealing with something extremely sensitive (money) isn't going to make such a ridiculous mistake. I'm definitely no fan of theirs; I'm just saying it's silly for the initial poster to speculate the password length restriction is there because they're storing them in plaintext.

Plaintext password storage definitely still is common, unfortunately, but you're not going to see it at a place like Paypal or Bank of America or Stripe in 2020. Or even 2010.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#82
post #80

Earlier quoted context omitted.

Why does it have to be payment focused? There's tons of big tech companies that have done this. Enjoy: https://github.com/plaintextoffenders/plaintextoffenders/blo... It's not difficult to find them

I'm just saying a company like Paypal which is both massive and dealing with something extremely sensitive (money) isn't going to make such a ridiculous mistake. I'm definitely no fan of theirs; I'm just saying it's silly for the initial poster to speculate the password length restriction is there because they're storing them in plaintext. Plaintext password storage definitely still is common, unfortunately, but you'…

Yeah you're in for a surprise in the future.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#83
post #82

Earlier quoted context omitted.

I'm just saying a company like Paypal which is both massive and dealing with something extremely sensitive (money) isn't going to make such a ridiculous mistake. I'm definitely no fan of theirs; I'm just saying it's silly for the initial poster to speculate the password length restriction is there because they're storing them in plaintext. Plaintext password storage definitely still is common, unfortunately, but you'…

Yeah you're in for a surprise in the future.

I work in the infosec industry, so I've definitely seen some crazy and incompetent shit. But I still don't think Paypal or Stripe would store plaintext credentials.

Re: Critical PayPal Security Hack: Multiple Thefts Now Reported–Check Your Settings

#84

Earlier quoted context omitted.

Every single login asks for TOTP, and sessions expire very quickly. Even the mobile app asks every time, even if you use some saved/authorized login method like fingerprint login. For someone who uses PayPal for most online payments this can be extremely tedious.

None of this is relevant to the question asked. I understand it’s all correct, but it fails to answer the question of quantity over time presented.

In my previous comment:

> For someone who uses PayPal for most online payments this can be extremely tedious.

To rephrase that: the quantity can range from "almost every online payment" to "every online payment". If, like many people, you try to use PayPal for most payments to avoid credit card info leakage, that means you need to answer a TOTP challenge on every payment.

Post reply on HN