Live data from Hacker News

PayPal Denies Providing Payment Information to Twitter Username Hacker

thenextweb.com

21–30 of 131 posts

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#21
post #6

Earlier quoted context omitted.

Exactly - as the article points out, without released voice recordings (if they exist, which is not a given), they can't prove that they didn't. Haven't similar things happened before with paypal though?

In a hearsay battle between Paypal and a thief, why is the burden on PayPal to prove its innocence?

To my knowledge they don't know who the thief is.

The thief allegedly got the last 4 digits of the CC by posing as an employee.[0]

If true, it would mean paypal gave out financial information to an unknown third-party, which would be a breach of a bunch of laws, terms, internal policies etc.

The burden to prove innocence in this situation would definitely fall on paypal.

Excerpts from the original article[0]:

>I called paypal and used some very simple engineering tactics to obtain the last four of your card (avoid this by calling paypal and asking the agent to add a note to your account to not release any details via phone)

>Yes paypal told me them over the phone (I was acting as an employee) and godaddy let me “guess” for the first two digits of the card

[0] https://medium.com/p/24eb09e026dd

[1] https://news.ycombinator.com/item?id=7141532

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#22
post #9

Earlier quoted context omitted.

Godaddy.

I'm waiting for the day that Godaddy buys Twitter and then is acquired by PayPal. At this point the nexus of evil will be mainly concentrated around one company. It would make a good acquisition target for EMC.

And then they would rename it to "Umbrella corporation"

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#23

I am more interested in Twitter's response to all of this.

While I think the right thing of Twitter would be to give the account back, they didn't really do anything wrong (if the story is to be believed). Hiroshima simply changed the account name, and let the hacker know it was available.

Not sure Twitter could have done anything to prevent this from happening.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#24

In my opinion, the hacker who hijacked this guy's Twitter account didn't have had ANY interest in explaining how he got to it, besides creating a hoax to confuse and divert attention. Just think about it, in just one email he puts the blame on both GoDaddy, for doing phone validation over unsecure criteria (like credit card numbers), and PayPal (for giving out the last digits of the card number to a complete stranger…

I could be wrong, but wasn't there a story a while back where someone explained how they could hack into any apple ID account with a similar process? Didn't linode's servers get hacked and the hacker explained the whole process?

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#25
post #12

Earlier quoted context omitted.

In a hearsay battle between Paypal and a thief, why is the burden on PayPal to prove its innocence?

Because Paypal has a history of being full of shit.

@1angryhacker - they're the only game in town for a lot of people, notably ebay sellers and users. More tech-savvy sellers know to diversify or to use other payment gateways (amazon, google, etc) but paypal has a huge userbase of average internet users.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#27
What's interesting is in the original "i got hacked" post[0]. The email from the hacker says that he called paypal and posed as an employee.

That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call.

So if the hacker told them he was Jack from xyz department, who would know the difference, better still, would they log the call at all?

The alleged breach could in this situation be quite easy.

[0] https://medium.com/p/24eb09e026dd

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#28
post #26

I'd be reporting them to the authorities. Then I'd sue them, and get the recording in discovery.

Who's going to cover the lawyer costs? I'd love to see a 'no win no fee' company prepared to take on paypal

It's done all the time with class actions.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#29

Fuck PayPal, like you ever gave a shit about your customers. Do us all a favor and KILL yourselves

Take a timeout, come back in 20 and reread your post. Is it really worth it to get so angry and malicious? And protip, if you're going to get this angry, don't post it. It makes you look nuts, and does nothing to anyone about how they might feel about PayPal.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#30
post #12

Earlier quoted context omitted.

Because Paypal has a history of being full of shit.

that's not a reason to convict without evidence. if paypal is so shit why is everyone using them. vote with your feet

We aren't convicting them here - this isn't a court. It's just pointing out that, once again, as always:

PayPal

Not only did they screw up; but they also can't man up, tell the truth and be transparent - as usual. Shit happens. Slamming us with a denial that shit happened is implying that you aren't going to do anything about it; admitting it is a clear statement that you are not proud of it and will work to make sure it never happens again.

It's come to the point where if someone said that PayPal are responsible for climate change; I would be inclined to believe them. No matter how much they denied it.

Post reply on HN