Live data from Hacker News

Bypass PayPal's Two-Factor Authentication

duosecurity.com

11–20 of 29 posts

Re: Bypass PayPal's Two-Factor Authentication

#11
post #6

Based on this timeline, I don't understand why Duo didn't go public on 2014-04-28 when PayPal began being weasely about their bug bounty program. This probably would be better for users for two reasons: one, in the past 2 months, this bug may have been exploited in the wild, and two, it would make it easier for users to make informed decisions about which payments providers to use in the future (as well as which 2fa…

The disclosure process is always fraught with peril (and pain) and its a safe bet that no matter what a discloser does, there will be some person or group who thinks they should have handled it differently. In a case like this, when reasonable time is given, and the world gets to benefit from a great deal of work (effectively done for free), i tend to simply say thanks, and make notes..

Re: Bypass PayPal's Two-Factor Authentication

#12

I'm glad this was found independently and reported. While I was at PayPal I had started email threads about it but nothing was done. I am sure I was not the only one there who "discovered" this. For instance, even if you have 2FA you can add PayPal to Uber as if you never had 2FA. The other big issue with their 2FA authentication is that it really isn't two factor. You can say you don't have the token and instead can…

I would think that, if you have a big fraud-detection engine like Paypal's in place, 2FA isn't so much an enforced requirement for login, as it is a big fraud-signal when the user chooses to circumnavigate it.

Like any other fraud-signal, though, it can be countered with enough evidence that you are who you say you are--with security questions at a weak level (maybe enough to counter a 2FA token that was only set up a few days ago), or with demands for scanned photo ID at a higher level (if you use 2FA all the time.)

Re: Bypass PayPal's Two-Factor Authentication

#13
post #10

A bigger problem for me is that two-factor authentication for PayPal is available only in few countries (US, UK and Germany I think). I tried to get a token but no chance; not even software with mobile app. When contacting support I was considered as a freak probably - they completely didn't what is the problem without 2FA. I really don't get it, why being global they limit 2FA to a few countries.

Actually I use PayPal more often since they provide 2FA. They are stupid because this could be a win-win for them and tech aware consumers like us. I also wished they used Google Authenticator instead of this SMS... they (SMS) sometimes take ages before delivered.

Re: Bypass PayPal's Two-Factor Authentication

#14
post #10

A bigger problem for me is that two-factor authentication for PayPal is available only in few countries (US, UK and Germany I think). I tried to get a token but no chance; not even software with mobile app. When contacting support I was considered as a freak probably - they completely didn't what is the problem without 2FA. I really don't get it, why being global they limit 2FA to a few countries.

Actually I use PayPal more often since they provide 2FA. They are stupid because this could be a win-win for them and tech aware consumers like us. I also wished they used Google Authenticator instead of this SMS... they (SMS) sometimes take ages before delivered.

They also support VeriSign VIP (https://idprotect.verisign.com/mainmenu.v), which you could take mobile app - should be better than waiting for SMS. At least in theory as I cannot validate it, because 2FA is not available in Poland.

Re: Bypass PayPal's Two-Factor Authentication

#16
post #12

I'm glad this was found independently and reported. While I was at PayPal I had started email threads about it but nothing was done. I am sure I was not the only one there who "discovered" this. For instance, even if you have 2FA you can add PayPal to Uber as if you never had 2FA. The other big issue with their 2FA authentication is that it really isn't two factor. You can say you don't have the token and instead can…

I would think that, if you have a big fraud-detection engine like Paypal's in place, 2FA isn't so much an enforced requirement for login, as it is a big fraud-signal when the user chooses to circumnavigate it. Like any other fraud-signal, though, it can be countered with enough evidence that you are who you say you are--with security questions at a weak level (maybe enough to counter a 2FA token that was only set up…

If there is no legitimate reason to circumnavigate 2FA, i.e. the S/N of detecting fraud by detecting circumnavigation is 1.0, why not just automate the anti-fraud enforcement and make the circumnavigation impossible?

Re: Bypass PayPal's Two-Factor Authentication

#17

I'm glad this was found independently and reported. While I was at PayPal I had started email threads about it but nothing was done. I am sure I was not the only one there who "discovered" this. For instance, even if you have 2FA you can add PayPal to Uber as if you never had 2FA. The other big issue with their 2FA authentication is that it really isn't two factor. You can say you don't have the token and instead can…

It is not real two factor authentication, if you can bypass it with questions.

It is more security theatre, giving PayPal's users a feeling of security.

Re: Bypass PayPal's Two-Factor Authentication

#18

I'm glad this was found independently and reported. While I was at PayPal I had started email threads about it but nothing was done. I am sure I was not the only one there who "discovered" this. For instance, even if you have 2FA you can add PayPal to Uber as if you never had 2FA. The other big issue with their 2FA authentication is that it really isn't two factor. You can say you don't have the token and instead can…

Yes, I've contacted PayPal before and asked them for a user setting to be able to disable the 2FA fallbacks, but they don't really seem to care that much for security. I hope someone from PayPal Security team reads this and considers implementing this change.

Re: Bypass PayPal's Two-Factor Authentication

#19
post #6

Based on this timeline, I don't understand why Duo didn't go public on 2014-04-28 when PayPal began being weasely about their bug bounty program. This probably would be better for users for two reasons: one, in the past 2 months, this bug may have been exploited in the wild, and two, it would make it easier for users to make informed decisions about which payments providers to use in the future (as well as which 2fa…

I was wondering the same. I think paypal was very unresponsive and the could have for sure done a better job. That said when they asked for 3 days more I think Duo could have complied and would have made everyone more happy.

Re: Bypass PayPal's Two-Factor Authentication

#20
post #15

You never trust the client; this is amateur hour shit TBH. How could a company like PayPal let something like this through? SURELY there were employees raising hell before it ever hit the app stores?

This. When the employee wrote that popup and manually logged out of the app they must have been high.
Post reply on HN