Live data from Hacker News

PayPal Denies Providing Payment Information to Twitter Username Hacker

thenextweb.com

81–90 of 131 posts

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#81
post #69

PayPal is lying or playing dumb and here's why: Ask them if the customer service agents can see the last four or if they have to enter them first before the customer's records come up. They can see the last four right away. Call paypal and ask them which card you have on file, you cannot remember. The agent can give you last four to identify it.

> Call paypal and ask them which card you have on file, you cannot remember. Exactly. I've done this before when services ask me for my full credit card number or expiration date (to verify), and I ask them for the last four digits (to remind me which card I used). What PayPal did may be bad, but what GoDaddy did (use the last six digits) to verify is even worse. If you know the last four digits, you have a better th…

Someone should just record a video of themselves doing it to their own account and post it online, that would be proof enough I'd think.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#82
post #6

Earlier quoted context omitted.

Exactly - as the article points out, without released voice recordings (if they exist, which is not a given), they can't prove that they didn't. Haven't similar things happened before with paypal though?

In a hearsay battle between Paypal and a thief, why is the burden on PayPal to prove its innocence?

Its partly because PayPal's reputation precedes it. Paypal is a shitty company with often scummy policies. They also have a demonstrated history of employees making horrible decisions.

If PayPal didn't do anything wrong, they would probably be far more eager to provide their customer with assistance. In their initial communication they should have volunteered whether or not there is a recording of any conversation they may have had with the attacker. If there is a recording, they should have immediately volunteered to play it back for the victim in order to give him peace of mind. That's basic customer service.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#83

Earlier quoted context omitted.

You need a course in elementary logic. Specifically, on the burden of proof. Also, everything you wrote in this comment here seems to be a complete fabrication.

The 'burden of proof' is a social/legal concept which has absolutely nothing to do with elementary logic, so maybe you're the one that needs the refresher.

From https://en.wikipedia.org/wiki/Philosophic_burden_of_proof

When debating any issue, there is an implicit burden of proof on the person asserting a claim. The fallacy of an argument from ignorance occurs if, when a claim is challenged, the burden of proof is shifted to be on the challenger.

The burden of proof is a philosophical concept which extends into the legal domain. In fact, it's the only sane way to process assertions made by purportedly rational actors, it's hardly limited to 'social/legal' contexts.

But I'm not sure why you didn't go look this up in Wikipedia before you commented.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#84
post #78

Earlier quoted context omitted.

You need a course in elementary logic. Specifically, on the burden of proof. Also, everything you wrote in this comment here seems to be a complete fabrication.

I work for a bank and it's absolutely on us to show that our transactions and treatment of financial information is verifiable. We have to be able to demonstrate due diligence, there is no assumption of innocence when the auditors come knocking on the door, whatever 'elementary logic' may say. Thats why I completely believe the posters here claiming this wouldn't be possible in a banks call centre. What I don't know…

That's a different question altogether. Banks are required to keep meticulous and auditable transaction records -- nobody is disputing that or even questioning if PayPal does so. Banks are not required to show extend themselves to whatever demands made to them, in order to show that the claims of a random internet person are false.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#85
post #70

Earlier quoted context omitted.

- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee. - The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is eve…

Re: recording... Why does the message when you call say something like '...may be recorded...' where "may" sounds like it's synonymous with "might"? I know why they have to have the message but I was just curious if there was a reason for the apparently odd wording.

They reserve the right not to record the call, in case the stuff hits the fan and a customer insists on getting a recording of the call where everything went wrong.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#86
post #76

Earlier quoted context omitted.

In other words you're prejudiced and see no reason to logically validate your preconceptions? Great, that's what we need. More people commenting who have all the answers. What if PayPal were telling the truth, how exactly would that situation look different than the one we are in? Good thing PayPal's always wrong though!

It's more like extrapolation from a known set of data points. PayPal has a certain history. You can look up what's gone down in the past, and based on that, the accusations fall right in line with the sorts of things PayPal has historically done. At this point it seems far more likely that PayPal did in fact do what it's accused of than that it didn't. If PayPal is in fact telling the truth (and that's a big if), the…

...the question becomes where did the hacker get the last 4 of the CC from?

That's always been the question. Until you know better, what you have is a situation where you're believing the word of an anonymous criminal, relayed to you second-hand, over PayPal. I'm just saying you have no evidence either way at this point, and are simply expressing your preconceptions, which are not helpful.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#87
post #69

PayPal is lying or playing dumb and here's why: Ask them if the customer service agents can see the last four or if they have to enter them first before the customer's records come up. They can see the last four right away. Call paypal and ask them which card you have on file, you cannot remember. The agent can give you last four to identify it.

> Call paypal and ask them which card you have on file, you cannot remember. Exactly. I've done this before when services ask me for my full credit card number or expiration date (to verify), and I ask them for the last four digits (to remind me which card I used). What PayPal did may be bad, but what GoDaddy did (use the last six digits) to verify is even worse. If you know the last four digits, you have a better th…

You are right that Last Six is a miserable password.

One correction thought: the attacker didn't guess the two digits in a single try, they guessed them in a single phone call. The GoDaddy agent allegedly let them just try numbers until they got it.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#88

Earlier quoted context omitted.

When I worked at a large bank many years ago, internal calls were verified to be bank employees. It was low tech, but when a bank employee called and asked about a customer we had them verify they were a bank employee by telling them to look up, and tell us what was on a certain page and line of an internal bank book. If their answer matched what we were looking at as well then the conversation continued. The books w…

That's just like early days video game anti-piracy measure. What is the third word on the second paragraph of page 42 of the Dungeon Master's manual? Etc.

Military codebooks are used in this way for authenticating over unsecured links. Letters or numbers laid out in a grid-like format, and you make the far side read off a certain cell.

http://en.wikipedia.org/wiki/DRYAD

http://en.wikipedia.org/wiki/BATCO#Other_functions

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#89
PayPal records every call, 100% and also all the screen captures of the agent answering the call. So, either they're telling the truth, or they're lying. Not sure how anyone could tell the difference. but I guarantee you, they listened to the call.

I can't see why a hacker would actually give his secrets away.

Post reply on HN