Live data from Hacker News

PayPal Denies Providing Payment Information to Twitter Username Hacker

thenextweb.com

71–80 of 131 posts

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#71
post #69

PayPal is lying or playing dumb and here's why: Ask them if the customer service agents can see the last four or if they have to enter them first before the customer's records come up. They can see the last four right away. Call paypal and ask them which card you have on file, you cannot remember. The agent can give you last four to identify it.

> Call paypal and ask them which card you have on file, you cannot remember.

Exactly. I've done this before when services ask me for my full credit card number or expiration date (to verify), and I ask them for the last four digits (to remind me which card I used).

What PayPal did may be bad, but what GoDaddy did (use the last six digits) to verify is even worse.

If you know the last four digits, you have a better than 1% chance of guessing the previous two, since they are not uniformly distributed: http://en.wikipedia.org/wiki/Luhn_algorithm

(There are actually even more restrictions than the Luhn algorithm on credit card numbers, but I won't go into them here. Suffice to say, there's a reason than the attacker says he was able to guess it in a single try - he was lucky, but not that lucky).

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#72
post #70

Earlier quoted context omitted.

- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee. - The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is eve…

Re: recording... Why does the message when you call say something like '...may be recorded...' where "may" sounds like it's synonymous with "might"? I know why they have to have the message but I was just curious if there was a reason for the apparently odd wording.

The wording is specifically because they want to pretend that only a small share of calls are recorded for quality review and that it is very unlikely that your particular call will be recorded.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#73
post #21

Earlier quoted context omitted.

To my knowledge they don't know who the thief is. The thief allegedly got the last 4 digits of the CC by posing as an employee.[0] If true, it would mean paypal gave out financial information to an unknown third-party, which would be a breach of a bunch of laws, terms, internal policies etc. The burden to prove innocence in this situation would definitely fall on paypal. Excerpts from the original article[0]: >I call…

I dislike paypal as much as anyone, but since when does anyone have to prove innocence?

Since there is apparent evidence against their innocence?

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#74
post #21

Earlier quoted context omitted.

To my knowledge they don't know who the thief is. The thief allegedly got the last 4 digits of the CC by posing as an employee.[0] If true, it would mean paypal gave out financial information to an unknown third-party, which would be a breach of a bunch of laws, terms, internal policies etc. The burden to prove innocence in this situation would definitely fall on paypal. Excerpts from the original article[0]: >I call…

I dislike paypal as much as anyone, but since when does anyone have to prove innocence?

Since ever? For example anti-harassment law...

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#75
post #21

Earlier quoted context omitted.

To my knowledge they don't know who the thief is. The thief allegedly got the last 4 digits of the CC by posing as an employee.[0] If true, it would mean paypal gave out financial information to an unknown third-party, which would be a breach of a bunch of laws, terms, internal policies etc. The burden to prove innocence in this situation would definitely fall on paypal. Excerpts from the original article[0]: >I call…

I dislike paypal as much as anyone, but since when does anyone have to prove innocence?

when there is a believable story about them getting socially hacked & they have a sea of clients they are trying not to lose...

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#76
post #30

Earlier quoted context omitted.

We aren't convicting them here - this isn't a court. It's just pointing out that, once again, as always: PayPal Not only did they screw up; but they also can't man up, tell the truth and be transparent - as usual. Shit happens. Slamming us with a denial that shit happened is implying that you aren't going to do anything about it; admitting it is a clear statement that you are not proud of it and will work to make sur…

In other words you're prejudiced and see no reason to logically validate your preconceptions? Great, that's what we need. More people commenting who have all the answers. What if PayPal were telling the truth, how exactly would that situation look different than the one we are in? Good thing PayPal's always wrong though!

It's more like extrapolation from a known set of data points. PayPal has a certain history. You can look up what's gone down in the past, and based on that, the accusations fall right in line with the sorts of things PayPal has historically done. At this point it seems far more likely that PayPal did in fact do what it's accused of than that it didn't.

If PayPal is in fact telling the truth (and that's a big if), then the question becomes where did the hacker get the last 4 of the CC from? GoDaddy has confirmed the hacker had a large amount of info, including presumably the last 4 of the CC when he called them, so somewhere in this whole thing someone gave that data away.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#77

Earlier quoted context omitted.

The argument was, he was deflecting attention away from him towards others - which, as this thread for the parent poster shows, worked.

My argument is, this attention wouldn't even be here had he just kept quiet. I don't think he was clever enough to have foresight that a) this would get this much attention, and b) he would need to deflect said attention by fabricating an elaborate hoax. The guy was simply wanting to brag about what he did in the excitement of him actually pulling it off. I think this is much more believable than him fabricating this…

One issue to be thought of is if he tells how he hacked the accounts, it would become difficult for him to hack some other accounts in the future. But I have found out that he has a habit of giving out advice to people. I have done some searching and found out (hopefully) who he is.

A simple google search for the email swiped@live.com revealed this link http://mydomaintest.com/index.php?query=getgamesfree.net with owner douglas

A password reset on that account shows the following accounts listed. do * * * @gmail.com do * * * @aim.com

A password reset on aim.com for user name douglas(just guessing) also revealed the email d * * * *8@froze.org

Searching for the name douglas parmele and 5167, brenda gave a result http://welfare.im/dox/index.php?name=communist

There is a reference of froze.us in the dox.

Here you get his hackerforums.net profile http://www.hackforums.net/member.php?action=profile&uid=1399...

search for his posts and you see most of them are selling novelty twitter and other accounts

http://www.hackforums.net/search.php?action=results&sid=953a...

Here he gives out advice on securing accounts. http://www.hackforums.net/showthread.php?tid=3610513

You have to have an account on hackforums.net to view those links.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#78
post #47

Earlier quoted context omitted.

When you are a financial company. edit: financial companies, or any company when dealing with a financial or privacy breach usually needs to prove their innocence when they are attributed to allegedly causing financial loss (to varied extents depending on the situation). This is an expectation from society in general. It may not seem fair or be legally required, but that's just the way it is.

You need a course in elementary logic. Specifically, on the burden of proof. Also, everything you wrote in this comment here seems to be a complete fabrication.

I work for a bank and it's absolutely on us to show that our transactions and treatment of financial information is verifiable. We have to be able to demonstrate due diligence, there is no assumption of innocence when the auditors come knocking on the door, whatever 'elementary logic' may say.

Thats why I completely believe the posters here claiming this wouldn't be possible in a banks call centre. What I don't know is whether PayPal operates at the same standard.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#79

Earlier quoted context omitted.

When I worked at a large bank many years ago, internal calls were verified to be bank employees. It was low tech, but when a bank employee called and asked about a customer we had them verify they were a bank employee by telling them to look up, and tell us what was on a certain page and line of an internal bank book. If their answer matched what we were looking at as well then the conversation continued. The books w…

That's just like early days video game anti-piracy measure. What is the third word on the second paragraph of page 42 of the Dungeon Master's manual? Etc.

The Pragmatic Programmer website uses this system to allow you to prove that you bought a hard-copy of a book, so they can offer you a discounted ebook.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#80
post #6

Earlier quoted context omitted.

Exactly - as the article points out, without released voice recordings (if they exist, which is not a given), they can't prove that they didn't. Haven't similar things happened before with paypal though?

In a hearsay battle between Paypal and a thief, why is the burden on PayPal to prove its innocence?

Because 1) they likely have the actual recording on file 2) they are the service company that wants to convince us to continue using them.
Post reply on HN