Live data from Hacker News

PayPal discloses data breach that exposed user info for 6 months

bleepingcomputer.com

21–30 of 93 posts

Re: PayPal discloses data breach that exposed user info for 6 months

#22

Great, who from PayPal is going to jail over this?

Wow!

Lets take the article at face value: "The financial technology company said it has reversed the code change that caused the incident, blocking attackers' access to the data one day after discovering the breach."

Great thats your bug. Key word here being BUG. Your name next to the commit that caused this.

Should you go to prison? Probably not.

Tell me you never had a bug, a security hole, never took production down. Never made a mistake. Tell me that you want to go to jail for human error. Not intent, error.

Re: PayPal discloses data breach that exposed user info for 6 months

#23
post #2

So from the Article they claim: "PayPal has since rolled back the code change responsible for this error, which potentially exposed the PII. We have not delayed this notification as a result of any law enforcement investigation." That does little to explain the 2 month-ish delay in disclosing it. I presume they could have disclosed _at least_ that account data was leaked even if the underlying bug wasn’t yet closed?…

Just before Christmas? I doubt it

Re: PayPal discloses data breach that exposed user info for 6 months

#24
The ignorance of a company like PayPal is obviously bad.

That said, I think we need to have an equivalent of automated integration testing for security vulnerabilities.

Even if PenTesters (or whatever they're called these days) do some testing and uncover some bugs, the applications under continuous development will inevitably introduce "bugs" not seen before.

Re: PayPal discloses data breach that exposed user info for 6 months

#25

Irrelevant to the current breach, but at the end of the article... > In January 2023, PayPal notified customers of another data breach after a large-scale credential stuffing attack compromised 35,000 accounts between December 6 and December 8, 2022. > Two years later, in January 2025, New York State announced a $2,000,000 settlement with PayPal over charges that it failed to comply with the state's cybersecurity reg…

You don't have to do 2FA, but there's liability in being vulnerable to credential-stuffing, and 2FA is one of many ways to mitigate that.

Re: PayPal discloses data breach that exposed user info for 6 months

#26
These kind of breaches are why I'm against KYC's current implementation.

If the government wants to know who I am, that's fine, I'm not here to fight law. I however don't think it should be necessary to tell banks and private businesses where I physically sleep. That is more information than they need to operate, and every few months it seems someone has a data breach.

Re: PayPal discloses data breach that exposed user info for 6 months

#27

Great, who from PayPal is going to jail over this?

Wow! Lets take the article at face value: "The financial technology company said it has reversed the code change that caused the incident, blocking attackers' access to the data one day after discovering the breach." Great thats your bug. Key word here being BUG. Your name next to the commit that caused this. Should you go to prison? Probably not. Tell me you never had a bug, a security hole, never took production do…

When a bridge falls, there is a case in the courts, and sometimes engineers go to prison.

Why shall be different with code?

Re: PayPal discloses data breach that exposed user info for 6 months

#28
At one point on the internet PayPal was the most trusted way to send and receive money - at least you are limiting sharing your personal payment information with random companies on the internet who may or may not be compliant. Lately though, with companies like Stripe and Plaid making it nearly frictionless to add payments to your website just as PP once did, and things like Google & Apple pay - why is there a need to use PayPal anymore? Their support is notoriously awful, the product is slow and dated, as a consumer at least I see no reason to not stop using PayPal (and their subsidies) entirely.

Re: PayPal discloses data breach that exposed user info for 6 months

#29

Earlier quoted context omitted.

Wow! Lets take the article at face value: "The financial technology company said it has reversed the code change that caused the incident, blocking attackers' access to the data one day after discovering the breach." Great thats your bug. Key word here being BUG. Your name next to the commit that caused this. Should you go to prison? Probably not. Tell me you never had a bug, a security hole, never took production do…

When a bridge falls, there is a case in the courts, and sometimes engineers go to prison. Why shall be different with code?

I don’t know about civil engineering but don’t people only go to jail for negligence or worse?

Similarly, if the change was a bug, write a postmortem, find ways to make the whole and move on. If it was malicious, then prosecute.

I doubt it was malicious though.

Post reply on HN