New Paypal gateway UI susceptible to spoofing
homakov.blogspot.com
New Paypal gateway UI susceptible to spoofing
1–10 of 53 posts
Re: New Paypal gateway UI susceptible to spoofing
#2Similarly, Google's "No CAPTCHA" (https://news.ycombinator.com/item?id=8693767) lets Google offer a better experience than a traditional CAPTHCA. I'm somewhat surprised that better fraud detection leads to better UX, but it's pretty neat.
Re: New Paypal gateway UI susceptible to spoofing
#3PayPal probably has good enough fraud detection that easier-but-riskier integration is still a net win for PayPal. (Not so much for the rest of the internet, though...) Similarly, Google's "No CAPTCHA" ( https://news.ycombinator.com/item?id=8693767 ) lets Google offer a better experience than a traditional CAPTHCA. I'm somewhat surprised that better fraud detection leads to better UX, but it's pretty neat.
Re: New Paypal gateway UI susceptible to spoofing
#4PayPal probably has good enough fraud detection that easier-but-riskier integration is still a net win for PayPal. (Not so much for the rest of the internet, though...) Similarly, Google's "No CAPTCHA" ( https://news.ycombinator.com/item?id=8693767 ) lets Google offer a better experience than a traditional CAPTHCA. I'm somewhat surprised that better fraud detection leads to better UX, but it's pretty neat.
It's not just PayPal fraud per se. Leaking user's PayPal email address and password has a lot of other consequences. (Yeah yeah in theory you should use distinct passwords for different sites etc etc)
(Yes, that's pretty nasty - but is putting a poorly-secured "startup" online really any better?)
Re: New Paypal gateway UI susceptible to spoofing
#5There is always a level of trust involved with entering these kinds of credentials on-line. This is why some of the 3-D Secure systems make you (the customer) give them a greeting of your own choice to incorporate in the prompt for your confirmation code.
However, it seems that for many vendors the losses due to a higher rate of aborted checkouts make such systems undesirable. Apparently most customers don't share the author's concern here, presumably either unaware of the potential security issues or just trusting that if anything does go wrong then some protection or guarantee from their payment service/card issuer will get it fixed.
I suspect the author here would argue that it would be better for on-line payments to be push transactions rather than pull, so users always actively send money via a trusted party such as their bank without ever handing over their bank-issued credentials to anyone else. No doubt many of us would agree with that; pull-based payment models are fundamentally insecure and absurdly vulnerable to fraud. But again, that goes for a lot more than just PayPal.
Re: New Paypal gateway UI susceptible to spoofing
#6Re: New Paypal gateway UI susceptible to spoofing
#7Re: New Paypal gateway UI susceptible to spoofing
#8[deleted]
Re: New Paypal gateway UI susceptible to spoofing
#9[deleted]
Re: New Paypal gateway UI susceptible to spoofing
#10[deleted]