Earlier quoted context omitted.
If it's possible for employees to be able to make such a mistake, that's a standard broken process. It should not be possible for them to reveal the last four no matter how badly someone wants them to and how clever their social engineering skills. It shouldn't be possible from a technical perspective, not from a "we told employees not to do this" perspective.
If you display 4 digits to the user for CC validation, as basically everyone does, then there will always be someone who can read those 4 digits and give them to someone else.
PayPal Denies Providing Payment Information to Twitter Username Hacker
61–70 of 131 posts
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#62Earlier quoted context omitted.
If you display 4 digits to the user for CC validation, as basically everyone does, then there will always be someone who can read those 4 digits and give them to someone else.
You don't need to display them to the user. The user can ask for them from the customer. The user types in the 4 digits the customer provides. The computer compares the two strings. The user need never see the real stored digits.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#63Earlier quoted context omitted.
The argument was, he was deflecting attention away from him towards others - which, as this thread for the parent poster shows, worked.
My argument is, this attention wouldn't even be here had he just kept quiet. I don't think he was clever enough to have foresight that a) this would get this much attention, and b) he would need to deflect said attention by fabricating an elaborate hoax. The guy was simply wanting to brag about what he did in the excitement of him actually pulling it off. I think this is much more believable than him fabricating this…
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#64Earlier quoted context omitted.
It's done all the time with class actions.
This line of reasoning doesn't make a whole lot of sense. As a member of several class action lawsuits over the past 20+ years, I bet I've made out like a bandit - no less than $2.50 distributed over maybe 5-7 CALs. Sweet! The lawyers, however, probably made $500,000,000 with those 5-7 lawsuits. So while there's a financial want from the lawyers' perspective, why would I want to go that route?
Sounds like a lot of other scams.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#65Earlier quoted context omitted.
Exactly - as the article points out, without released voice recordings (if they exist, which is not a given), they can't prove that they didn't. Haven't similar things happened before with paypal though?
In a hearsay battle between Paypal and a thief, why is the burden on PayPal to prove its innocence?
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#66Earlier quoted context omitted.
When you are a financial company. edit: financial companies, or any company when dealing with a financial or privacy breach usually needs to prove their innocence when they are attributed to allegedly causing financial loss (to varied extents depending on the situation). This is an expectation from society in general. It may not seem fair or be legally required, but that's just the way it is.
You need a course in elementary logic. Specifically, on the burden of proof. Also, everything you wrote in this comment here seems to be a complete fabrication.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#67Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#68Earlier quoted context omitted.
My argument is, this attention wouldn't even be here had he just kept quiet. I don't think he was clever enough to have foresight that a) this would get this much attention, and b) he would need to deflect said attention by fabricating an elaborate hoax. The guy was simply wanting to brag about what he did in the excitement of him actually pulling it off. I think this is much more believable than him fabricating this…
After all the prison sentences lately, I'm not sure he wants to brag about himself.
Not being snarky, that's a real question. I don't know the minds and rationale of hackers.
I generally get the impression hackers honestly feel they're invincible, until they get caught. Maybe that's a misperception though.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#69Ask them if the customer service agents can see the last four or if they have to enter them first before the customer's records come up.
They can see the last four right away.
Call paypal and ask them which card you have on file, you cannot remember. The agent can give you last four to identify it.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#70What's interesting is in the original "i got hacked" post[0]. The email from the hacker says that he called paypal and posed as an employee. That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call. So if the hacker told…
- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee. - The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is eve…
Why does the message when you call say something like '...may be recorded...' where "may" sounds like it's synonymous with "might"?
I know why they have to have the message but I was just curious if there was a reason for the apparently odd wording.