Live data from Hacker News

PayPal Denies Providing Payment Information to Twitter Username Hacker

thenextweb.com

111–120 of 131 posts

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#111

Earlier quoted context omitted.

That's a different question altogether. Banks are required to keep meticulous and auditable transaction records -- nobody is disputing that or even questioning if PayPal does so. Banks are not required to show extend themselves to whatever demands made to them, in order to show that the claims of a random internet person are false.

Legally, no. But if enough people find the claim credible, then it is definitely in their best interest to convince everyone else that the claim is false. Whether or not you think that is fair is irrelevant; if enough people feel the bank is not safe to use, the bank will lose business.

Ok well if that's your hand, the converse principle is more pertinent -- if it has no impact on profits, nobody cares about the random rantings of an insular group of technologists, and how they think PayPal ought to conduct itself.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#112

Earlier quoted context omitted.

From https://en.wikipedia.org/wiki/Philosophic_burden_of_proof When debating any issue, there is an implicit burden of proof on the person asserting a claim. The fallacy of an argument from ignorance occurs if, when a claim is challenged, the burden of proof is shifted to be on the challenger. The burden of proof is a philosophical concept which extends into the legal domain. In fact, it's the only sane way to proces…

That really does not apply in this situation. A thief made a claim that he tricked PayPal into giving out personal information on his victim. We know the thief got the personal information. What is in question is if he is telling the truth that he got it from PayPal. You are looking at this as a claim between the thief and PayPal. The thief made the claim, so the burden of proof is on the thief. But that's not what's…

The burden of proof applies to all logical propositions. You are confusing two issues -- PayPal's marketing claims and those of a random thief. The truth is that you actually have insufficient information to decide one way or another who is telling the truth here, and at least you wouldn't be able to substantiate such a conclusion without appealing to prejudices. That's the point I'm making -- personally I think that the thief is telling the truth. But I'm reserving judgment because we certainly don't know enough to warrant some of the strong claims made on this thread.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#113

Earlier quoted context omitted.

That really does not apply in this situation. A thief made a claim that he tricked PayPal into giving out personal information on his victim. We know the thief got the personal information. What is in question is if he is telling the truth that he got it from PayPal. You are looking at this as a claim between the thief and PayPal. The thief made the claim, so the burden of proof is on the thief. But that's not what's…

The burden of proof applies to all logical propositions. You are confusing two issues -- PayPal's marketing claims and those of a random thief. The truth is that you actually have insufficient information to decide one way or another who is telling the truth here, and at least you wouldn't be able to substantiate such a conclusion without appealing to prejudices. That's the point I'm making -- personally I think that…

I think you are concerned with correctly filling out The Universal Ledger of All Objective Truths. That's not what we're concerned with.

We're concerned with figuring out what we think is most likely. You are correct that we have insufficient information to know with high confidence who is telling the truth, but if we are in a position to use PayPal, we have to make a judgement anyway. Further, not having enough information to know most things with high confidence is the common case; we usually have to make decisions based on imperfect information.

In such cases, we have to use the imperfect information available to us. Prejudices is one word for it; Bayesians call it our priors.

For the record, I actually think PayPal is a net-good. I think that most of the negative press they put up with is unwarranted, and is a result of people not understanding how they are allowed to use the service. In addition, I think most people do not appreciate that PayPal is much more tolerant than the alternative that was the only-game-in-town before PayPal, which were merchant accounts with banks.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#114

Earlier quoted context omitted.

The burden of proof applies to all logical propositions. You are confusing two issues -- PayPal's marketing claims and those of a random thief. The truth is that you actually have insufficient information to decide one way or another who is telling the truth here, and at least you wouldn't be able to substantiate such a conclusion without appealing to prejudices. That's the point I'm making -- personally I think that…

I think you are concerned with correctly filling out The Universal Ledger of All Objective Truths. That's not what we're concerned with. We're concerned with figuring out what we think is most likely . You are correct that we have insufficient information to know with high confidence who is telling the truth, but if we are in a position to use PayPal, we have to make a judgement anyway. Further, not having enough inf…

Well said, for the most part, although it should be noted that not all prejudices are appropriate priors!

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#115

Earlier quoted context omitted.

I think you are concerned with correctly filling out The Universal Ledger of All Objective Truths. That's not what we're concerned with. We're concerned with figuring out what we think is most likely . You are correct that we have insufficient information to know with high confidence who is telling the truth, but if we are in a position to use PayPal, we have to make a judgement anyway. Further, not having enough inf…

Well said, for the most part, although it should be noted that not all prejudices are appropriate priors!

Yes, agreed.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#116

Earlier quoted context omitted.

It's done all the time with class actions.

This line of reasoning doesn't make a whole lot of sense. As a member of several class action lawsuits over the past 20+ years, I bet I've made out like a bandit - no less than $2.50 distributed over maybe 5-7 CALs. Sweet! The lawyers, however, probably made $500,000,000 with those 5-7 lawsuits. So while there's a financial want from the lawyers' perspective, why would I want to go that route?

Generally speaking, class action suits--especially for smaller claims, like what chris_wot implies--are less about seeking individual relief and more about leveraging the potential for significant damages to force a defendant to initiate a change in a given behavior. So even though you might only walk away with a few pennies, on balance, there's a net benefit to the public value that stems from behavioral changes.

If Mr. Burns is dumping his chemical waste into Lake Springfield and you're winding up with little three-eyed fish as a result, you're hoping to force Mr. Burns to stop polluting the lake.

Are there sleazy class action attorneys? Absolutely. They can be found on late night television, ugly billboards with creepy mugshots, and stalking ambulance drivers (:D). Basically, anywhere your regular run-of-the-mill scheister attorneys can be found. But they're also fewer in number, mainly because class action litigation is significantly more resource-intensive than other types of litigation. And since class action attorneys are almost always working on a contingency basis, there's a lot to support the idea that they earn their fees here.

It might not seem fair when you're looking at a $2.50 check, but that's the tradeoff you accept in order to bolster your ability to force a change.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#117

In my opinion, the hacker who hijacked this guy's Twitter account didn't have had ANY interest in explaining how he got to it, besides creating a hoax to confuse and divert attention. Just think about it, in just one email he puts the blame on both GoDaddy, for doing phone validation over unsecure criteria (like credit card numbers), and PayPal (for giving out the last digits of the card number to a complete stranger…

GoDaddy have come out and specifically said they were at fault in this case.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#118
post #117

In my opinion, the hacker who hijacked this guy's Twitter account didn't have had ANY interest in explaining how he got to it, besides creating a hoax to confuse and divert attention. Just think about it, in just one email he puts the blame on both GoDaddy, for doing phone validation over unsecure criteria (like credit card numbers), and PayPal (for giving out the last digits of the card number to a complete stranger…

GoDaddy have come out and specifically said they were at fault in this case.

Link?

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#119

Earlier quoted context omitted.

> Call paypal and ask them which card you have on file, you cannot remember. Exactly. I've done this before when services ask me for my full credit card number or expiration date (to verify), and I ask them for the last four digits (to remind me which card I used). What PayPal did may be bad, but what GoDaddy did (use the last six digits) to verify is even worse. If you know the last four digits, you have a better th…

Unless you know every other digit in the card number, I don't see how knowing the luhn algorithm is going to narrow the possibilities of guessing just the two digits.

Also credit card can never be used by itself for any purchase, ever. You must have the name, expiry date, and if you're doing transactions online, often the address and ccv2 as well.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#120

Earlier quoted context omitted.

- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee. - The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is eve…

When I worked at a call center, I eventually was promoted to call monitor, where I was actually the person listening to the recordings and grading reps on how they did. Our system did not record every call. It was a random sampling, and I had to hope a given MSR got recorded enough times in a month for me to hit my minimums.

I've implemented this is a call center. We recorded every call. It's actually harder to do "random sampling" than just have the button auto-click every call. It sounded like Paypal reviewed the call transcript before making a statement.
Post reply on HN