Live data from Hacker News

PayPal Denies Providing Payment Information to Twitter Username Hacker

thenextweb.com

91–100 of 131 posts

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#91
post #76

Earlier quoted context omitted.

In other words you're prejudiced and see no reason to logically validate your preconceptions? Great, that's what we need. More people commenting who have all the answers. What if PayPal were telling the truth, how exactly would that situation look different than the one we are in? Good thing PayPal's always wrong though!

It's more like extrapolation from a known set of data points. PayPal has a certain history. You can look up what's gone down in the past, and based on that, the accusations fall right in line with the sorts of things PayPal has historically done. At this point it seems far more likely that PayPal did in fact do what it's accused of than that it didn't. If PayPal is in fact telling the truth (and that's a big if), the…

(I can't reply to jessedhillon's follow-up comment yet & i don't want to wait so I'll just reply here....)

If you look as far as... oh say, the top of this thread on HN, you will hear accounts from people who have apparently done this very thing (asking PayPal for last 4 digits and gotten an answer). So it seems like their policy did not forbid it, anyone could do it, so why not believe the hacker's claim?

You can't have a policy of routinely giving out certain info then deny that you gave it out in a case where it caused a security breach. What is the defense there? "Well yeah ordinarily we DO give that out but we could tell this guy was a hacker so we didn't." Yeah, they wish. If they regularly give out last 4 digits, then the claim that they didn't in this case is absurd.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#92

Paypal's value lies in it's network and it's trustworthiness. There is no way in a million years they would divulge a f *-up of this magnitude unless there's was cold hard proof. But I think there is pretty convincing proof, and I think if anything, this makes them less trustworthy than if they had come out and accepted partial wrong doing. The "hacker" had no incentive to lie; the ace was in his hand.

Actually, neither the hacker nor PayPal has presented any proof whatsoever (there is as yet no proof that the hacker even had the last four digits of the card number, and if he did, there are plenty of sources to get those from).

Either could for all we know be telling the truth, but if you find yourself automatically taking the word of a known thief over that of a legitimate company, it's time to stop and re-examine, not only your conclusion in this case, but every aspect of the thought processes you use for such things. The hacker had several possible incentives to lie, and I'm sure you'd be able to figure out at least some of them if you stepped back and looked at the question objectively.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#93

Fuck PayPal, like you ever gave a shit about your customers. Do us all a favor and KILL yourselves

Take a timeout, come back in 20 and reread your post. Is it really worth it to get so angry and malicious? And protip, if you're going to get this angry, don't post it. It makes you look nuts, and does nothing to anyone about how they might feel about PayPal.

Honestly I think telling the corporation of PayPal that it should be destroyed, or truly threatened with destruction if they don't shape up, is a reasonable response to their abusive behavior. People are far too forgiving of misdeeds done by large corporations.

It's certainly an angry and illogical post but I can't bring myself to actually disagree with it.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#95

Earlier quoted context omitted.

After all the prison sentences lately, I'm not sure he wants to brag about himself.

If he were really that concerned about prison sentences, would he have done this to begin with? Not being snarky, that's a real question. I don't know the minds and rationale of hackers. I generally get the impression hackers honestly feel they're invincible, until they get caught. Maybe that's a misperception though.

That may be an age thing - often they are young males. Entirely conjecture.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#96

In my opinion, the hacker who hijacked this guy's Twitter account didn't have had ANY interest in explaining how he got to it, besides creating a hoax to confuse and divert attention. Just think about it, in just one email he puts the blame on both GoDaddy, for doing phone validation over unsecure criteria (like credit card numbers), and PayPal (for giving out the last digits of the card number to a complete stranger…

Clearly you've never watched a single Bond movie. The only thing a villain enjoys more than committing a crime, is revealing the intricate plan by which he will get away with it.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#97
post #27

What's interesting is in the original "i got hacked" post[0]. The email from the hacker says that he called paypal and posed as an employee. That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call. So if the hacker told…

- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee. - The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is eve…

When I worked at a call center, I eventually was promoted to call monitor, where I was actually the person listening to the recordings and grading reps on how they did. Our system did not record every call. It was a random sampling, and I had to hope a given MSR got recorded enough times in a month for me to hit my minimums.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#98
post #69

PayPal is lying or playing dumb and here's why: Ask them if the customer service agents can see the last four or if they have to enter them first before the customer's records come up. They can see the last four right away. Call paypal and ask them which card you have on file, you cannot remember. The agent can give you last four to identify it.

I doesn't make sense to point fingers without proof.

PayPal says that they did find records of the attempt, and they state affirmatively that they did not provide any credit card details. It sounds to me like they are saying they listened to a recording of the call, and they know they didn't disclose any credit card details.

If you're PayPal in this situation, how do you know the hacker doesn't have their own recording of the call? It would be one thing to claim no record of a call. But I think it would be incredibly reckless to claim you found the records, and you know you didn't disclose anything, if/when in fact you did.

The fact is, there's nothing PayPal can do to prove a negative. If the hacker, or anyone else, produces actual proof that PayPal discloses this information improperly (not just claiming it's easy), I'm sure we will see how PayPal responds then.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#99
post #69

PayPal is lying or playing dumb and here's why: Ask them if the customer service agents can see the last four or if they have to enter them first before the customer's records come up. They can see the last four right away. Call paypal and ask them which card you have on file, you cannot remember. The agent can give you last four to identify it.

> Call paypal and ask them which card you have on file, you cannot remember. Exactly. I've done this before when services ask me for my full credit card number or expiration date (to verify), and I ask them for the last four digits (to remind me which card I used). What PayPal did may be bad, but what GoDaddy did (use the last six digits) to verify is even worse. If you know the last four digits, you have a better th…

The last 4 digits are known, and the first 6 digits are based on the type of card (VISA/MC/AMEX + Bank/Issuer), so are guessable. Apply the Luhn algorithm to these, and you're left with only 10-100K possibilities for the remaining middle digits.

If you're only required to specify the last 2, you can narrow it down significantly by only looking at valid combinations of those last 2, which is far smaller than 100.

I've written up some of this here: http://tech.bluesmoon.info/2011/01/how-guessable-is-your-cre...

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#100
post #69

PayPal is lying or playing dumb and here's why: Ask them if the customer service agents can see the last four or if they have to enter them first before the customer's records come up. They can see the last four right away. Call paypal and ask them which card you have on file, you cannot remember. The agent can give you last four to identify it.

> Call paypal and ask them which card you have on file, you cannot remember. Exactly. I've done this before when services ask me for my full credit card number or expiration date (to verify), and I ask them for the last four digits (to remind me which card I used). What PayPal did may be bad, but what GoDaddy did (use the last six digits) to verify is even worse. If you know the last four digits, you have a better th…

Unless you know every other digit in the card number, I don't see how knowing the luhn algorithm is going to narrow the possibilities of guessing just the two digits.
Post reply on HN