Live data from Hacker News

PayPal Denies Providing Payment Information to Twitter Username Hacker

thenextweb.com

121–130 of 131 posts

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#121

Earlier quoted context omitted.

I dislike paypal as much as anyone, but since when does anyone have to prove innocence?

Since there is apparent evidence against their innocence?

What evidence? The chat transcript of a thief?

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#122

Earlier quoted context omitted.

- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee. - The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is eve…

When I worked at a call center, I eventually was promoted to call monitor, where I was actually the person listening to the recordings and grading reps on how they did. Our system did not record every call. It was a random sampling, and I had to hope a given MSR got recorded enough times in a month for me to hit my minimums.

I suppose I could have hedged a bit with the usual "may depend on the institution" disclaimer, heh. Anyway, I was responding to the apparent belief that someone might look at the inbound number and think "no need to record this one," which I'm pretty confident saying does not happen.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#123
post #70

Earlier quoted context omitted.

- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee. - The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is eve…

Re: recording... Why does the message when you call say something like '...may be recorded...' where "may" sounds like it's synonymous with "might"? I know why they have to have the message but I was just curious if there was a reason for the apparently odd wording.

Why commit yourself to a stronger statement than necessary? As you probably already know, it's just to satisfy laws against recording a phone call without the consent of both parties. It's just a nicer way to say "we will proceed assuming we have your consent to record this call," without promising or revealing anything further.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#124
post #27

What's interesting is in the original "i got hacked" post[0]. The email from the hacker says that he called paypal and posed as an employee. That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call. So if the hacker told…

When I worked at a large bank many years ago, internal calls were verified to be bank employees. It was low tech, but when a bank employee called and asked about a customer we had them verify they were a bank employee by telling them to look up, and tell us what was on a certain page and line of an internal bank book. If their answer matched what we were looking at as well then the conversation continued. The books w…

In my case we had a security code on an internal system that was updated in real-time. So the protocol was:

"Hi I'm an employee calling from [X]" "OK, can I get the security code?" (caller gives security code)

Any employee in the company could also request a no-questions-asked reset at any time. I actually had cause hit the big red button once when the call went:

"Hi, this is [employee] calling from [branch]" "All right, can I get the security code?" "Oh, (mutters "security code"), it's $foo"

See, that counted as a compromise because someone in the lobby may have overheard her.

A couple other fun stories:

- Once I called a branch and got transferred to someone else. The conversation at the other end:

Him: "Did you give the code already?" Me: "...are you seriously going to believe me if I say 'Yes'?"

- Apparently there was a phishing attempt where people would call our center opening with:

"Hi this is [person] from the fraud department, before we begin can I get the security code?"

I don't know if it ever worked, but we got several memos warning us not to fall for it.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#125
post #98

Earlier quoted context omitted.

I doesn't make sense to point fingers without proof. PayPal says that they did find records of the attempt, and they state affirmatively that they did not provide any credit card details. It sounds to me like they are saying they listened to a recording of the call, and they know they didn't disclose any credit card details. If you're PayPal in this situation, how do you know the hacker doesn't have their own recordi…

> If you're PayPal in this situation, how do you know the hacker doesn't have their own recording of the call? If I were PayPal, I would asks the question: Why would a hacker keep a recording -- of obtaining information illegally -- that would only incriminate himself? Obviously I have no way of knowing either way, but PayPal has earned the mistrust many have in their security best practices. PayPal has much more to…

I don't think it's uncommon for a hacker to believe they're invincible. Especially if they are doing something to a U.S. company or citizen when they are in a 3rd or even a 2nd world country. The laws and enforcement are often lax in comparison or even non-existent.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#126

Earlier quoted context omitted.

Unless you know every other digit in the card number, I don't see how knowing the luhn algorithm is going to narrow the possibilities of guessing just the two digits.

Also credit card can never be used by itself for any purchase, ever. You must have the name, expiry date, and if you're doing transactions online, often the address and ccv2 as well.

As far as I know, not true. Merchants get discounts for asking for more information, but it's not strictly required to process your card.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#127
post #48

http://thenextweb.com/insider/2014/01/30/godaddy-accepts-par... "Our review of the situation reveals that the hacker was already in possession of a large portion of the customer information needed to access the account at the time he contacted GoDaddy. The hacker then socially engineered an employee to provide the remaining information needed to access the customer account. The customer has since regained full access…

"evolving hacker techniques"? I'm pretty sure that these fancy tactics can be found in The Art of Deception , which was released in 2002. Social engineering is nothing new.

They can probably be found in any writing since about when people discovered that manipulation and lying got them a warmer spot in the cave and a bigger slice of mammoth pie.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#128

Earlier quoted context omitted.

Also credit card can never be used by itself for any purchase, ever. You must have the name, expiry date, and if you're doing transactions online, often the address and ccv2 as well.

As far as I know, not true. Merchants get discounts for asking for more information, but it's not strictly required to process your card.

It depends on the bank. Some require more data than others. In either case, though, if the transaction turns out to be fraudulent, it's the merchant that pays, so the merchant has a strong incentive to ask for more rather than less.

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#129
post #118
post #117

Earlier quoted context omitted.

GoDaddy have come out and specifically said they were at fault in this case.

Link?

"GoDaddy accepts partial responsibility in social engineering attack of @N's customer account"

http://thenextweb.com/insider/2014/01/30/godaddy-accepts-par...

Re: PayPal Denies Providing Payment Information to Twitter Username Hacker

#130
post #76

Earlier quoted context omitted.

In other words you're prejudiced and see no reason to logically validate your preconceptions? Great, that's what we need. More people commenting who have all the answers. What if PayPal were telling the truth, how exactly would that situation look different than the one we are in? Good thing PayPal's always wrong though!

It's more like extrapolation from a known set of data points. PayPal has a certain history. You can look up what's gone down in the past, and based on that, the accusations fall right in line with the sorts of things PayPal has historically done. At this point it seems far more likely that PayPal did in fact do what it's accused of than that it didn't. If PayPal is in fact telling the truth (and that's a big if), the…

> It's more like extrapolation from a known set of data points. PayPal has a certain history.

Exactly, the child who cried "wolf."

Post reply on HN