Live data from Hacker News

PayPal Denies Providing Payment Information to Twitter Username Hacker

thenextweb.com

41–50 of 131 posts

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#41
post #21

Earlier quoted context omitted.

In a hearsay battle between Paypal and a thief, why is the burden on PayPal to prove its innocence?

To my knowledge they don't know who the thief is. The thief allegedly got the last 4 digits of the CC by posing as an employee.[0] If true, it would mean paypal gave out financial information to an unknown third-party, which would be a breach of a bunch of laws, terms, internal policies etc. The burden to prove innocence in this situation would definitely fall on paypal. Excerpts from the original article[0]: >I call…

I dislike paypal as much as anyone, but since when does anyone have to prove innocence?

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#42

Earlier quoted context omitted.

I'm waiting for the day that Godaddy buys Twitter and then is acquired by PayPal. At this point the nexus of evil will be mainly concentrated around one company. It would make a good acquisition target for EMC.

Did I miss something - why are Twitter evil now?

I'm guessing "Sponsored Tweets", but I would call them "pretty annoying" and not "evil".

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#43
post #27

What's interesting is in the original "i got hacked" post[0]. The email from the hacker says that he called paypal and posed as an employee. That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call. So if the hacker told…

- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee.

- The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is even possible, it's gross negligence.

- Call centers typically record all calls regardless of origin; it's not like a human being manually hits a record button on a case-by-case basis.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#44

Fuck PayPal, like you ever gave a shit about your customers. Do us all a favor and KILL yourselves

Take a timeout, come back in 20 and reread your post. Is it really worth it to get so angry and malicious? And protip, if you're going to get this angry, don't post it. It makes you look nuts, and does nothing to anyone about how they might feel about PayPal.

I didn't see the original post, but this is an extremely thoughtful reply to anyone who is angry and acting illogically. Well done.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#45
post #27

What's interesting is in the original "i got hacked" post[0]. The email from the hacker says that he called paypal and posed as an employee. That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call. So if the hacker told…

When I worked at a large bank many years ago, internal calls were verified to be bank employees. It was low tech, but when a bank employee called and asked about a customer we had them verify they were a bank employee by telling them to look up, and tell us what was on a certain page and line of an internal bank book. If their answer matched what we were looking at as well then the conversation continued. The books were changed/printed often.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#46
post #27

What's interesting is in the original "i got hacked" post[0]. The email from the hacker says that he called paypal and posed as an employee. That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call. So if the hacker told…

[deleted]

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#47
post #21

Earlier quoted context omitted.

To my knowledge they don't know who the thief is. The thief allegedly got the last 4 digits of the CC by posing as an employee.[0] If true, it would mean paypal gave out financial information to an unknown third-party, which would be a breach of a bunch of laws, terms, internal policies etc. The burden to prove innocence in this situation would definitely fall on paypal. Excerpts from the original article[0]: >I call…

I dislike paypal as much as anyone, but since when does anyone have to prove innocence?

When you are a financial company.

edit: financial companies, or any company when dealing with a financial or privacy breach usually needs to prove their innocence when they are attributed to allegedly causing financial loss (to varied extents depending on the situation).

This is an expectation from society in general. It may not seem fair or be legally required, but that's just the way it is.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#48
http://thenextweb.com/insider/2014/01/30/godaddy-accepts-par...

"Our review of the situation reveals that the hacker was already in possession of a large portion of the customer information needed to access the account at the time he contacted GoDaddy. The hacker then socially engineered an employee to provide the remaining information needed to access the customer account. The customer has since regained full access to his GoDaddy account, and we are working with industry partners to help restore services from other providers. We are making necessary changes to employee training to ensure we continue to provide industry-leading security to our customers and stay ahead of evolving hacker techniques."

It's likely the attacker obtained credit card info from GoDaddy rather than PayPal.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#49
post #6

Earlier quoted context omitted.

Exactly - as the article points out, without released voice recordings (if they exist, which is not a given), they can't prove that they didn't. Haven't similar things happened before with paypal though?

In a hearsay battle between Paypal and a thief, why is the burden on PayPal to prove its innocence?

I would tend to agree with you, but paypal was emphatic that they _did not_ (emphasis theirs) release anything. There is a difference between not finding evidence and saying as such, "We could find no evidence that that one of our employees failed to follow correct and established procedures". If they had said that, I would be more inclined to let them go. I believe that they placed the burden of proof on themselves by coming out with such a firm statement.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#50
post #42

Earlier quoted context omitted.

Did I miss something - why are Twitter evil now?

I'm guessing "Sponsored Tweets", but I would call them "pretty annoying" and not "evil".

They mean the same thing on the Internet. Same as "mildly interesting" and "epic".
Post reply on HN