Live data from Hacker News

PayPal Denies Providing Payment Information to Twitter Username Hacker

thenextweb.com

101–110 of 131 posts

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#101
post #48

http://thenextweb.com/insider/2014/01/30/godaddy-accepts-par... "Our review of the situation reveals that the hacker was already in possession of a large portion of the customer information needed to access the account at the time he contacted GoDaddy. The hacker then socially engineered an employee to provide the remaining information needed to access the customer account. The customer has since regained full access…

"evolving hacker techniques"?

I'm pretty sure that these fancy tactics can be found in The Art of Deception, which was released in 2002. Social engineering is nothing new.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#102
post #69

PayPal is lying or playing dumb and here's why: Ask them if the customer service agents can see the last four or if they have to enter them first before the customer's records come up. They can see the last four right away. Call paypal and ask them which card you have on file, you cannot remember. The agent can give you last four to identify it.

Those four digits aren't hard to get - - it's scary how much access was given with such minor info.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#103

Well PayPal once flagged a non-existent transaction on my account as suspicious. I had to call them to get it sorted out. The fact that something like that can happen surely doesn't help me trust PayPal...

Why? Sounds like they did you a favour.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#104

Earlier quoted context omitted.

- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee. - The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is eve…

When I worked at a call center, I eventually was promoted to call monitor, where I was actually the person listening to the recordings and grading reps on how they did. Our system did not record every call. It was a random sampling, and I had to hope a given MSR got recorded enough times in a month for me to hit my minimums.

Different use-case but we've implemented recording on all call-center calls; this isn't for employee monitoring, it's so we have a recording for legal purposes because some of those calls involve instructions for financial trades.

If I was in PayPal's situation I'd want to record every call, because dealing with money is a lot more critical than dealing with call quality.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#105
post #98
post #69

PayPal is lying or playing dumb and here's why: Ask them if the customer service agents can see the last four or if they have to enter them first before the customer's records come up. They can see the last four right away. Call paypal and ask them which card you have on file, you cannot remember. The agent can give you last four to identify it.

I doesn't make sense to point fingers without proof. PayPal says that they did find records of the attempt, and they state affirmatively that they did not provide any credit card details. It sounds to me like they are saying they listened to a recording of the call, and they know they didn't disclose any credit card details. If you're PayPal in this situation, how do you know the hacker doesn't have their own recordi…

> If you're PayPal in this situation, how do you know the hacker doesn't have their own recording of the call?

If I were PayPal, I would asks the question: Why would a hacker keep a recording -- of obtaining information illegally -- that would only incriminate himself?

Obviously I have no way of knowing either way, but PayPal has earned the mistrust many have in their security best practices. PayPal has much more to gain by covering this up than the hacker would by lying about it.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#106
Shouldn't it be easy enough for Twitter to just return the handle to the original owner? I guess Twitter has to cover their own ass to a degree, and it is possible the original owner is making up this story and actually sold the Twitter handle (though I suspect this would be against Twitter's policies).

However, based on what I've read, the people involved, and Occam's Razor, I believe the published story. Twitter should transfer ownership of the handle back to Naoki Hiroshima, do the right thing, and get some good press at the same time.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#107
post #6

Earlier quoted context omitted.

Exactly - as the article points out, without released voice recordings (if they exist, which is not a given), they can't prove that they didn't. Haven't similar things happened before with paypal though?

In a hearsay battle between Paypal and a thief, why is the burden on PayPal to prove its innocence?

Because the thief actually did acquire the last 4 digits of the credit card number, and there is plenty of anecdotal evidence that their techs can and will give out the last 4 digits of credit card numbers.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#108

Earlier quoted context omitted.

The 'burden of proof' is a social/legal concept which has absolutely nothing to do with elementary logic, so maybe you're the one that needs the refresher.

From https://en.wikipedia.org/wiki/Philosophic_burden_of_proof When debating any issue, there is an implicit burden of proof on the person asserting a claim. The fallacy of an argument from ignorance occurs if, when a claim is challenged, the burden of proof is shifted to be on the challenger. The burden of proof is a philosophical concept which extends into the legal domain. In fact, it's the only sane way to proces…

That really does not apply in this situation. A thief made a claim that he tricked PayPal into giving out personal information on his victim. We know the thief got the personal information. What is in question is if he is telling the truth that he got it from PayPal.

You are looking at this as a claim between the thief and PayPal. The thief made the claim, so the burden of proof is on the thief.

But that's not what's going on. PayPayl is asserting a claim that they are safe, and the other party is every potential customer of PayPal. The burden is on PayPal to convince us of their claim that they are safe, in light of the claim against them.

To me, it is credible that the thief got the information from PayPal. Between the thief and PayPal, I think the thief has little incentive to lie about where he got the information, but PayPal has high incentive to cover up.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#109
post #78

Earlier quoted context omitted.

I work for a bank and it's absolutely on us to show that our transactions and treatment of financial information is verifiable. We have to be able to demonstrate due diligence, there is no assumption of innocence when the auditors come knocking on the door, whatever 'elementary logic' may say. Thats why I completely believe the posters here claiming this wouldn't be possible in a banks call centre. What I don't know…

That's a different question altogether. Banks are required to keep meticulous and auditable transaction records -- nobody is disputing that or even questioning if PayPal does so. Banks are not required to show extend themselves to whatever demands made to them, in order to show that the claims of a random internet person are false.

Legally, no. But if enough people find the claim credible, then it is definitely in their best interest to convince everyone else that the claim is false. Whether or not you think that is fair is irrelevant; if enough people feel the bank is not safe to use, the bank will lose business.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#110
post #6

Earlier quoted context omitted.

Exactly - as the article points out, without released voice recordings (if they exist, which is not a given), they can't prove that they didn't. Haven't similar things happened before with paypal though?

In a hearsay battle between Paypal and a thief, why is the burden on PayPal to prove its innocence?

Because there are three parties here, not two: PayPal, the thief, and all real and potential customers of PayPal. PayPal has no obligation to convince the thief that they are innocent. But if they want to retain business, they must convince all of their current and future customers that they are innocent.
Post reply on HN