Live data from Hacker News

What’s going on with security at PayPal?

christianvarga.com

11–20 of 103 posts

Re: What’s going on with security at PayPal?

#11
“Guessing the 5 missing digits” isn’t exactly trivial, there are thousands of combinations. In the US you might figure out the area code, but good luck if the person isn’t a local (or if you just entered a random email).

Also I don’t see the rest being true. If I only enter my phone number, it still asks for the password. And I can’t reset my password unless I also enter my email address.

I do agree though that probably they should just email me instead if I forgot the password.

Re: What’s going on with security at PayPal?

#12
post #10

If true, this is borderline criminal incompetence. However, I can't reproduce the issue described in the article.

Same.

The author says when you enter an email, an SMS is sent and number revealed.

What really happens is that it asks me for a password. Below that there's an option to get a one time code. Clicking that reveals the first digit of the area code, then the last 4 digits. You must then click yet again to make it actually send.

So in short, it didn't immediately send an SMS and never showed the full number.

Re: What’s going on with security at PayPal?

#14
I have never once given one of these valley payments companies my bank account information, and this sort of garbage is why. If I need to pay something via PayPal, Venmo, or whoever the hell else, I'll use a credit card and happily eat a 3% fee for doing so, and that's the price I pay to be able to tell Chase or Amex to handle it when some fraudster gets at my info rather than watch my bank account get drained.

Re: What’s going on with security at PayPal?

#16
post #10

If true, this is borderline criminal incompetence. However, I can't reproduce the issue described in the article.

Same. The author says when you enter an email, an SMS is sent and number revealed. What really happens is that it asks me for a password. Below that there's an option to get a one time code. Clicking that reveals the first digit of the area code, then the last 4 digits. You must then click yet again to make it actually send. So in short, it didn't immediately send an SMS and never showed the full number.

But the author says a partial number is revealed?

Edit:

I just tried logging in. It's exactly as the author describes - I enter my email and get a "Log in with a one-time code" page with my partial phone number. The code is sent automatically. Must be A/B testing. (No password prompt is shown unless I click "Try another way" below the code field.)

Re: What’s going on with security at PayPal?

#17
> So I have a complex password and TOPT to protect my account. Forget these, because PayPal’s default method of login is now a one-time code sent via SMS. Yes, the very same medium that is generally considered unsafe for two-factor authentication is used by PayPal as the only factor; bypassing both password and TOPT for what appears to be full access to your account. You cannot disable this method of login, and you cannot remove your phone number from your account.

> Tested in Incognito – as soon as you enter an email address to log into PayPal, an SMS is immediately sent and the phone number is revealed.

Just tested, can't reproduce. I get the standard email => password => TOTP flow. Also happened to have logged in yesterday on a new device, so pretty sure nothing changed between the blog post and now, at least not for me.

Maybe it's something being rolled out to more customers at the moment.

Re: What’s going on with security at PayPal?

#20
post #17

> So I have a complex password and TOPT to protect my account. Forget these, because PayPal’s default method of login is now a one-time code sent via SMS. Yes, the very same medium that is generally considered unsafe for two-factor authentication is used by PayPal as the only factor; bypassing both password and TOPT for what appears to be full access to your account. You cannot disable this method of login, and you c…

OP here - I just tried again and got the normal flow this time. Guessing they must be A/B testing SMS one-time codes as the default.
Post reply on HN