Live data from Hacker News

PayPal Denies Providing Payment Information to Twitter Username Hacker

thenextweb.com

51–60 of 131 posts

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#51
post #27

What's interesting is in the original "i got hacked" post[0]. The email from the hacker says that he called paypal and posed as an employee. That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call. So if the hacker told…

When I worked at a large bank many years ago, internal calls were verified to be bank employees. It was low tech, but when a bank employee called and asked about a customer we had them verify they were a bank employee by telling them to look up, and tell us what was on a certain page and line of an internal bank book. If their answer matched what we were looking at as well then the conversation continued. The books w…

That's just like early days video game anti-piracy measure.

What is the third word on the second paragraph of page 42 of the Dungeon Master's manual? Etc.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#52
post #26

Earlier quoted context omitted.

Who's going to cover the lawyer costs? I'd love to see a 'no win no fee' company prepared to take on paypal

It's done all the time with class actions.

This line of reasoning doesn't make a whole lot of sense. As a member of several class action lawsuits over the past 20+ years, I bet I've made out like a bandit - no less than $2.50 distributed over maybe 5-7 CALs. Sweet! The lawyers, however, probably made $500,000,000 with those 5-7 lawsuits.

So while there's a financial want from the lawyers' perspective, why would I want to go that route?

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#53
All the hacker claims to have obtained from PayPal is the last four digits of the credit card number. Perhaps this failed attempt they mention was them asking the hacker to provide the complete credit card number ending in XXXX as a form of verification?

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#54

In my opinion, the hacker who hijacked this guy's Twitter account didn't have had ANY interest in explaining how he got to it, besides creating a hoax to confuse and divert attention. Just think about it, in just one email he puts the blame on both GoDaddy, for doing phone validation over unsecure criteria (like credit card numbers), and PayPal (for giving out the last digits of the card number to a complete stranger…

> didn't have had ANY interest in explaining how he got to it, besides creating a hoax to confuse and divert attention. Would the story have gone viral, though, had he just said, "I'm not going to say anything about how I did it."? The story would have just been another "I got hacked" story. If the hacker were really clever enough to fabricate such an elaborate hoax, I think he would have been clever enough to realiz…

The argument was, he was deflecting attention away from him towards others - which, as this thread for the parent poster shows, worked.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#55
post #27

What's interesting is in the original "i got hacked" post[0]. The email from the hacker says that he called paypal and posed as an employee. That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call. So if the hacker told…

The email from the hacker says that he called paypal and posed as an employee.

I took that to mean the hacker posed as an employee of Naoki Hiroshima. I wonder which it was.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#56
post #47

Earlier quoted context omitted.

I dislike paypal as much as anyone, but since when does anyone have to prove innocence?

When you are a financial company. edit: financial companies, or any company when dealing with a financial or privacy breach usually needs to prove their innocence when they are attributed to allegedly causing financial loss (to varied extents depending on the situation). This is an expectation from society in general. It may not seem fair or be legally required, but that's just the way it is.

You need a course in elementary logic. Specifically, on the burden of proof. Also, everything you wrote in this comment here seems to be a complete fabrication.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#57
post #31

I didn't expect them to come forth and accept it. If it's an employee mistake, and not a standard broken process, they can erase the tracks.

If it's possible for employees to be able to make such a mistake, that's a standard broken process. It should not be possible for them to reveal the last four no matter how badly someone wants them to and how clever their social engineering skills. It shouldn't be possible from a technical perspective, not from a "we told employees not to do this" perspective.

If you display 4 digits to the user for CC validation, as basically everyone does, then there will always be someone who can read those 4 digits and give them to someone else.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#58
post #30

Earlier quoted context omitted.

that's not a reason to convict without evidence. if paypal is so shit why is everyone using them. vote with your feet

We aren't convicting them here - this isn't a court. It's just pointing out that, once again, as always: PayPal Not only did they screw up; but they also can't man up, tell the truth and be transparent - as usual. Shit happens. Slamming us with a denial that shit happened is implying that you aren't going to do anything about it; admitting it is a clear statement that you are not proud of it and will work to make sur…

In other words you're prejudiced and see no reason to logically validate your preconceptions?

Great, that's what we need. More people commenting who have all the answers. What if PayPal were telling the truth, how exactly would that situation look different than the one we are in? Good thing PayPal's always wrong though!

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#59
Paypal's value lies in it's network and it's trustworthiness. There is no way in a million years they would divulge a f*-up of this magnitude unless there's was cold hard proof.

But I think there is pretty convincing proof, and I think if anything, this makes them less trustworthy than if they had come out and accepted partial wrong doing.

The "hacker" had no incentive to lie; the ace was in his hand.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#60

Earlier quoted context omitted.

> didn't have had ANY interest in explaining how he got to it, besides creating a hoax to confuse and divert attention. Would the story have gone viral, though, had he just said, "I'm not going to say anything about how I did it."? The story would have just been another "I got hacked" story. If the hacker were really clever enough to fabricate such an elaborate hoax, I think he would have been clever enough to realiz…

The argument was, he was deflecting attention away from him towards others - which, as this thread for the parent poster shows, worked.

My argument is, this attention wouldn't even be here had he just kept quiet.

I don't think he was clever enough to have foresight that a) this would get this much attention, and b) he would need to deflect said attention by fabricating an elaborate hoax.

The guy was simply wanting to brag about what he did in the excitement of him actually pulling it off. I think this is much more believable than him fabricating this story.

Post reply on HN