Live data from Hacker News

PayPal bans Linux users with a GPU name containing the string "Apple M1"

vt.social

21–30 of 44 posts

Re: PayPal bans Linux users with a GPU name containing the string "Apple M1"

#21
I'd guess this is due to some Paypal fraud protection thing thinking that Linux on M1 is an "impossible" configuration to have and that anyone with that configuration must be spoofing their hardware.

If you click onto the bug she filed, it's also kind of sad/funny that the Mozilla employee responding to it ALSO assumes that nobody can actually run Linux on M1 and renames the bug to "paypal.com - Spoofing as Apple M GPU breaks the login process by triggering a block to the security challenge".

It's a shame because Asahi runs really well on M1 & M2. I hope that they're able to get this resolved and that other issues like this don't pop up in the future.

Re: PayPal bans Linux users with a GPU name containing the string "Apple M1"

#23
post #18
post #8

I think the real problem is that any website can get a ton of information on your GPU, including vendor, model, supported extensions etc. via WebGL/WebGPU.

Yeah, I understand it's probably part of their fraud protection, but feels weird that they get my GPU info when doing a payment. Seems very unrelated. Anyone who works on fraud protection who can explain how this info is used?

The problem is they have the ability to get it to begin with. The browser or OS should prevent this.

Re: PayPal bans Linux users with a GPU name containing the string "Apple M1"

#24
post #18
post #8

I think the real problem is that any website can get a ton of information on your GPU, including vendor, model, supported extensions etc. via WebGL/WebGPU.

Yeah, I understand it's probably part of their fraud protection, but feels weird that they get my GPU info when doing a payment. Seems very unrelated. Anyone who works on fraud protection who can explain how this info is used?

Not exactly on the backend, but I worked on the frontend (SDKs) at a previous employer whose product offering was fraud detection literally. Over the period of those years, I realised the team wanted "get whatever you can" and then just kept it and used it as needed. A few things I recall - heuristics, some matches with data sources they had of fraudulent actors, et cetera. I am talking about the time when "AI" as we know it was just picking up, and that company was actually calling these systems ML-backed. They pivoted to "AI" as soon as the term became more commonplace, and in the beginning it was just the name change, but I am sure they'd have changed the systems as well, or I hope so.

I can tell you that any kind of "abnormal" combination of system metadata (basically sysinfo) was technically frowned upon by that team, and of course, the system was designed by that team. So, say you had a rooted Android (we had solutions for all devices out there; pretty much) - naughty boy, the system suspected you of spoofing GPS - instant reject, disabling GPS - it was not a mandatory permission in the app (and we asked for it only for some clients) – but it didn't like it, you had changed the default resolution of the system - suspicious, we also captured typing/tapping speed (not only for text entry but also for interacting with the interface) - too fast was considered weird because you were not supposed to have known our interface (because it was interact once or twice in a lifetime or years, kind of thing).

I am speaking more from memory of new joinee intros and rare discussions with the team. The team was kinda "different," so other teams just wanted to avoid them and also wanted them to stay away from other teams. So a lot of things might not sound exciting, might not be accurate either and these are not technical observations anyway.

Another aspect I just remembered. Say you had an app list (oh, we read that too) that matched with known fraudulent actors datasets, you had app(s) that showed you were not well off (we served a lot of instant loan givers around the world), you had an old phone, your OS was very old – all these things were taken into account, along with your PII (which were of course mandatory), when their backend received the data and we gave the final reco/score to the client's system in the API response.

Re: PayPal bans Linux users with a GPU name containing the string "Apple M1"

#25
post #8

I think the real problem is that any website can get a ton of information on your GPU, including vendor, model, supported extensions etc. via WebGL/WebGPU.

They even query if the monitor is connected in a HDCP compliant way.

There is a bug in either that process, my monitor, or the DP protocol.

Sometimes when that detection happens, my monitor turns grey, which is what it's supposed to do when you play HDCP content over a non-HDCP link.

But I'm not doing that. I'm just visiting a website.

Re: PayPal bans Linux users with a GPU name containing the string "Apple M1"

#26

Earlier quoted context omitted.

Revolut! There are also pretty high referral bonus (around 80 dollars per referral where I come from). You can ”charge” it using Apple Pay or Google Pay, and it’s very convenient.

Doesn’t work in South Africa, India or Singapore. When you meet up with from people from enough places, there really aren’t many options.

Good news, PayPal works once from these places. then you will get 180 days lock on your account for suspicious transfers.

Re: PayPal bans Linux users with a GPU name containing the string "Apple M1"

#27
post #8

I think the real problem is that any website can get a ton of information on your GPU, including vendor, model, supported extensions etc. via WebGL/WebGPU.

They even query if the monitor is connected in a HDCP compliant way. There is a bug in either that process, my monitor, or the DP protocol. Sometimes when that detection happens, my monitor turns grey, which is what it's supposed to do when you play HDCP content over a non-HDCP link. But I'm not doing that. I'm just visiting a website.

I have Firefox set up to always ask for permission to play DRM protected content. This happens way more often than I ever expected. it seems that a lot of video ads have DRM. maybe that's what you're running into?

Re: PayPal bans Linux users with a GPU name containing the string "Apple M1"

#28

Why would anyone use PayPal at the first place? I have only negative experiences with them. Constant blocking, freezing account and then unfreezing it with no explanation why it was frozen in the first place just panacea "fraud detection", chargebacks months after the purchase.

One click checkout vs filling in credit card info on yet another website. None of your issues apply to using PayPal as a form of payment; you don’t need to keep a balance at all.

My experience in DigiKey (One of the biggest part store) on attempt to pay via PayPal it triggered fraud detection and DigiKey told me to wire up money via bank account. So from paying in few seconds I was waiting on transfer move for several days. Never using PayPal again, what a garbage service.

Shopping on DigiKey via debit card is absolutely without problem.

Re: PayPal bans Linux users with a GPU name containing the string "Apple M1"

#30
post #16

That's disastrous, imagine getting cut off from financial services because of being an early adopter.

With PayPal you don't need to imagine, you will get cut off randomly just by using it. Oh you have triggered fraud detection, let's waste a week of your time talking to customer support.
Post reply on HN