Live data from Hacker News

PayPal.com XSS Vulnerability

seclists.org

51–60 of 79 posts

Re: PayPal.com XSS Vulnerability

#51
On a sidenote, does anyone have a good setup for browsing securely to avoid issues like this? I ran with JS restricted to a whitelist for a while, but many random websites that I have to use require it these days.

Can you use something like Ghostery to allow any site to do its own JS but not external JS, besides whitelisted sites/externals?

Re: PayPal.com XSS Vulnerability

#52
post #51

On a sidenote, does anyone have a good setup for browsing securely to avoid issues like this? I ran with JS restricted to a whitelist for a while, but many random websites that I have to use require it these days. Can you use something like Ghostery to allow any site to do its own JS but not external JS, besides whitelisted sites/externals?

> Can you use something like Ghostery to allow any site to do its own JS but not external JS, besides whitelisted sites/externals?

That's exactly what noscript does. Use the option "Temporarily allow top-level sites by default->Base 2nd level Domains".

Re: PayPal.com XSS Vulnerability

#53

Earlier quoted context omitted.

The Federal Labor Standards Act has provisions about anyone under the age of 18 working for companies whose revenue is greater than $500,000. It sucks to be a kid for a lot of reasons. This kid just blamed Paypal for one of our country's many idiotic federal laws. This choice should be considered a career limiting decision by any hiring manager.

This choice should be considered a career limiting decision by any hiring manager. Are you saying that you're holding a 17 year old student in Germany responsible for not understanding US labor laws?

I find the meaning and knowledge of laws to be inaccessible overall as a 18+ citizen. I'm not American, but who for instance knew that there were "provisions" under the Federal Labor Standards Act?

Re: PayPal.com XSS Vulnerability

#55

Earlier quoted context omitted.

If the feds were to audit the situation you are describing, I would wager they'd come after Google. Google has a lot more freedom and track record for asking forgiveness instead of permission than Paypal (i.e. wifi sniffing in google cars). They are not a payment processing company. This stuff is complicated. Never attribute to malice that which is adequately explained by stupidity.

Why's that? Minors can receive compensation for work they perform.

Also, would it even be applicable to minors working from outside the U.S?

Re: PayPal.com XSS Vulnerability

#56
post #20

Is there any legitimate reason to discriminate because of age?

The Federal Labor Standards Act has provisions about anyone under the age of 18 working for companies whose revenue is greater than $500,000. It sucks to be a kid for a lot of reasons. This kid just blamed Paypal for one of our country's many idiotic federal laws. This choice should be considered a career limiting decision by any hiring manager.

The Fair Labor Standards Act places no limitations on the work of 16 and 17 year olds in non-hazardous jobs, and in any case does not concern itself with non-employment relationships like the one Paypal would have had with this 17-year-old.

There is a reason that you read about minors running their own businesses all the time. The laws are targeted at employment that is exploitative or interferes with a child's education. Not at things like this.

Re: PayPal.com XSS Vulnerability

#57
post #52
post #51

On a sidenote, does anyone have a good setup for browsing securely to avoid issues like this? I ran with JS restricted to a whitelist for a while, but many random websites that I have to use require it these days. Can you use something like Ghostery to allow any site to do its own JS but not external JS, besides whitelisted sites/externals?

> Can you use something like Ghostery to allow any site to do its own JS but not external JS, besides whitelisted sites/externals? That's exactly what noscript does. Use the option "Temporarily allow top-level sites by default->Base 2nd level Domains".

Thanks! This looks like exactly the behavior I want.

Re: PayPal.com XSS Vulnerability

#58
post #47

Earlier quoted context omitted.

Wait, it's considered "working for" when there's no employment relationship of any kind?

I doubt it has to do with labor laws, specifically. Payment is paid through a verified Paypal account, which you must be 18 years of age to use their services according to their user agreement.

Can't they just post him a cheque?

Re: PayPal.com XSS Vulnerability

#59
post #20

Is there any legitimate reason to discriminate because of age?

The Federal Labor Standards Act has provisions about anyone under the age of 18 working for companies whose revenue is greater than $500,000. It sucks to be a kid for a lot of reasons. This kid just blamed Paypal for one of our country's many idiotic federal laws. This choice should be considered a career limiting decision by any hiring manager.

[deleted]

Re: PayPal.com XSS Vulnerability

#60
post #33

Earlier quoted context omitted.

The Federal Labor Standards Act has provisions about anyone under the age of 18 working for companies whose revenue is greater than $500,000. It sucks to be a kid for a lot of reasons. This kid just blamed Paypal for one of our country's many idiotic federal laws. This choice should be considered a career limiting decision by any hiring manager.

They didn't have to pay him. Still very poorly handled. Should've gone something like: 1. "Hey, that's awesome that you found that, thanks!" 2. "For very good reasons (a), (b) and (c) we can't actually pay you, that really sucks :(" 3. "But hey we like your style, so how about we fly you over for an internship when you've finished school / investigate if Germany has different rules / look at scholorship options and a…

I totally agree, and they have the ability to give him the money. All they would have to do is ask for a parent to represent him.
Post reply on HN