Earlier quoted context omitted.
I dislike paypal as much as anyone, but since when does anyone have to prove innocence?
Since there is apparent evidence against their innocence?
PayPal Denies Providing Payment Information to Twitter Username Hacker
121–130 of 131 posts
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#122Earlier quoted context omitted.
- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee. - The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is eve…
When I worked at a call center, I eventually was promoted to call monitor, where I was actually the person listening to the recordings and grading reps on how they did. Our system did not record every call. It was a random sampling, and I had to hope a given MSR got recorded enough times in a month for me to hit my minimums.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#123Earlier quoted context omitted.
- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee. - The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is eve…
Re: recording... Why does the message when you call say something like '...may be recorded...' where "may" sounds like it's synonymous with "might"? I know why they have to have the message but I was just curious if there was a reason for the apparently odd wording.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#124What's interesting is in the original "i got hacked" post[0]. The email from the hacker says that he called paypal and posed as an employee. That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call. So if the hacker told…
When I worked at a large bank many years ago, internal calls were verified to be bank employees. It was low tech, but when a bank employee called and asked about a customer we had them verify they were a bank employee by telling them to look up, and tell us what was on a certain page and line of an internal bank book. If their answer matched what we were looking at as well then the conversation continued. The books w…
"Hi I'm an employee calling from [X]" "OK, can I get the security code?" (caller gives security code)
Any employee in the company could also request a no-questions-asked reset at any time. I actually had cause hit the big red button once when the call went:
"Hi, this is [employee] calling from [branch]" "All right, can I get the security code?" "Oh, (mutters "security code"), it's $foo"
See, that counted as a compromise because someone in the lobby may have overheard her.
A couple other fun stories:
- Once I called a branch and got transferred to someone else. The conversation at the other end:
Him: "Did you give the code already?" Me: "...are you seriously going to believe me if I say 'Yes'?"
- Apparently there was a phishing attempt where people would call our center opening with:
"Hi this is [person] from the fraud department, before we begin can I get the security code?"
I don't know if it ever worked, but we got several memos warning us not to fall for it.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#125Earlier quoted context omitted.
I doesn't make sense to point fingers without proof. PayPal says that they did find records of the attempt, and they state affirmatively that they did not provide any credit card details. It sounds to me like they are saying they listened to a recording of the call, and they know they didn't disclose any credit card details. If you're PayPal in this situation, how do you know the hacker doesn't have their own recordi…
> If you're PayPal in this situation, how do you know the hacker doesn't have their own recording of the call? If I were PayPal, I would asks the question: Why would a hacker keep a recording -- of obtaining information illegally -- that would only incriminate himself? Obviously I have no way of knowing either way, but PayPal has earned the mistrust many have in their security best practices. PayPal has much more to…
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#126Earlier quoted context omitted.
Unless you know every other digit in the card number, I don't see how knowing the luhn algorithm is going to narrow the possibilities of guessing just the two digits.
Also credit card can never be used by itself for any purchase, ever. You must have the name, expiry date, and if you're doing transactions online, often the address and ccv2 as well.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#127http://thenextweb.com/insider/2014/01/30/godaddy-accepts-par... "Our review of the situation reveals that the hacker was already in possession of a large portion of the customer information needed to access the account at the time he contacted GoDaddy. The hacker then socially engineered an employee to provide the remaining information needed to access the customer account. The customer has since regained full access…
"evolving hacker techniques"? I'm pretty sure that these fancy tactics can be found in The Art of Deception , which was released in 2002. Social engineering is nothing new.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#128Earlier quoted context omitted.
Also credit card can never be used by itself for any purchase, ever. You must have the name, expiry date, and if you're doing transactions online, often the address and ccv2 as well.
As far as I know, not true. Merchants get discounts for asking for more information, but it's not strictly required to process your card.
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#129Earlier quoted context omitted.
GoDaddy have come out and specifically said they were at fault in this case.
Link?
http://thenextweb.com/insider/2014/01/30/godaddy-accepts-par...
Re: PayPal Denies Providing Payment Information to Twitter Username Hacker
#130Earlier quoted context omitted.
In other words you're prejudiced and see no reason to logically validate your preconceptions? Great, that's what we need. More people commenting who have all the answers. What if PayPal were telling the truth, how exactly would that situation look different than the one we are in? Good thing PayPal's always wrong though!
It's more like extrapolation from a known set of data points. PayPal has a certain history. You can look up what's gone down in the past, and based on that, the accusations fall right in line with the sorts of things PayPal has historically done. At this point it seems far more likely that PayPal did in fact do what it's accused of than that it didn't. If PayPal is in fact telling the truth (and that's a big if), the…
Exactly, the child who cried "wolf."