Live data from Hacker News

Bypass PayPal's Two-Factor Authentication

duosecurity.com

21–29 of 29 posts

Re: Bypass PayPal's Two-Factor Authentication

#21

I'm glad this was found independently and reported. While I was at PayPal I had started email threads about it but nothing was done. I am sure I was not the only one there who "discovered" this. For instance, even if you have 2FA you can add PayPal to Uber as if you never had 2FA. The other big issue with their 2FA authentication is that it really isn't two factor. You can say you don't have the token and instead can…

Yes, I've contacted PayPal before and asked them for a user setting to be able to disable the 2FA fallbacks, but they don't really seem to care that much for security. I hope someone from PayPal Security team reads this and considers implementing this change.

I was also thinking that the community should start calling this type of implementation 2FAil, to give the companies a little extra 'shame peer pressure'... Anyone up for making a logo, heartbleed-style? :)

Re: Bypass PayPal's Two-Factor Authentication

#22
post #14

Earlier quoted context omitted.

Actually I use PayPal more often since they provide 2FA. They are stupid because this could be a win-win for them and tech aware consumers like us. I also wished they used Google Authenticator instead of this SMS... they (SMS) sometimes take ages before delivered.

They also support VeriSign VIP ( https://idprotect.verisign.com/mainmenu.v ), which you could take mobile app - should be better than waiting for SMS. At least in theory as I cannot validate it, because 2FA is not available in Poland.

Thanks alot @prohor ! But it was quite complicated and hidden to activate it in German Paypal. But now it works. wohoo...

Re: Bypass PayPal's Two-Factor Authentication

#23
post #6

Based on this timeline, I don't understand why Duo didn't go public on 2014-04-28 when PayPal began being weasely about their bug bounty program. This probably would be better for users for two reasons: one, in the past 2 months, this bug may have been exploited in the wild, and two, it would make it easier for users to make informed decisions about which payments providers to use in the future (as well as which 2fa…

I was wondering the same. I think paypal was very unresponsive and the could have for sure done a better job. That said when they asked for 3 days more I think Duo could have complied and would have made everyone more happy.

> That said when they asked for 3 days

they asked for a month and 3 days. Duo wanted to disclose on June 25th, PayPal has a fix on July 28th.

Re: Bypass PayPal's Two-Factor Authentication

#24
post #14

Earlier quoted context omitted.

They also support VeriSign VIP ( https://idprotect.verisign.com/mainmenu.v ), which you could take mobile app - should be better than waiting for SMS. At least in theory as I cannot validate it, because 2FA is not available in Poland.

Thanks alot @prohor ! But it was quite complicated and hidden to activate it in German Paypal. But now it works. wohoo...

Glad it worked. And this is what I don't get. I understand they may not want to distribute hardware tokens in some countries, support SMS, as it is a burden. But why don't they just allow me to activate an existing token?!

Re: Bypass PayPal's Two-Factor Authentication

#26
post #15

You never trust the client; this is amateur hour shit TBH. How could a company like PayPal let something like this through? SURELY there were employees raising hell before it ever hit the app stores?

It's shit like this that makes me trust bitcoin. Down with fiat.

Re: Bypass PayPal's Two-Factor Authentication

#28
post #14

Earlier quoted context omitted.

Actually I use PayPal more often since they provide 2FA. They are stupid because this could be a win-win for them and tech aware consumers like us. I also wished they used Google Authenticator instead of this SMS... they (SMS) sometimes take ages before delivered.

They also support VeriSign VIP ( https://idprotect.verisign.com/mainmenu.v ), which you could take mobile app - should be better than waiting for SMS. At least in theory as I cannot validate it, because 2FA is not available in Poland.

Unfortunately, there is no open source implementation of the VIP number generator. On the other hand, Google Authenticator is based on TOTP, and has several open source implementations. I don't want to run a separate, proprietary 2FA app for every single service, when they can all just use the standard set out in IETF rfc6238.

Re: Bypass PayPal's Two-Factor Authentication

#29
post #15

You never trust the client; this is amateur hour shit TBH. How could a company like PayPal let something like this through? SURELY there were employees raising hell before it ever hit the app stores?

It's shit like this that makes me trust bitcoin. Down with fiat.

Right, because poorly designed software only gets written when fiat currency is involved?

I hope you were being sarcastic...

Post reply on HN