Live data from Hacker News

Is this Paypal experience customary?

gist.github.com

241–250 of 295 posts

Re: Is this Paypal experience customary?

#241

I rarely use Paypal, but was forced to use it recently for something with no other payment option. Whilst there I decided to change my password, and was horrified to find that they limit passwords to 20 characters. It got me thinking about the standard assumption that any system limiting chars in a password must be storing passwords in plaintext and not hashing them, else there would be no logical reason to do so (si…

I know the "logic" behind modern low password length limits for services like Paypal. Too many of their users are literally incapable of remembering their passwords and call/e-mail them bitching about how they're entering the right password and their account won't let them in and now they can't get to their money and bogus threats of legal action. So they encourage weak passwords and try to handle security on their s…

Their 2FA policy is awful, SMS or nothing. At least that's the case in Canada (I heard it might be different in other regions).

Re: Is this Paypal experience customary?

#242

I rarely use Paypal, but was forced to use it recently for something with no other payment option. Whilst there I decided to change my password, and was horrified to find that they limit passwords to 20 characters. It got me thinking about the standard assumption that any system limiting chars in a password must be storing passwords in plaintext and not hashing them, else there would be no logical reason to do so (si…

When I changed my password there, not too long ago, it was worse. The "change password" page (I later discovered) silently cropped the long random password I pasted, while the "log in" page required the saved (truncated) password exactly. I don't know how they expected anyone to figure that out.

I suspect the answer to your question is that what we know as "Paypal.com" is a collection of 57 different legacy systems that were hacked together over a period of 20 years. It's not that a designer sat down one day and spec'd out the design we see. It's more like it used to be much worse, and then they fixed 173 bugs (sometimes is an overly conservative way), and we're seeing the result of that.

Unless a software team is very careful, what the users see is software archaeology, not UX design.

Re: Is this Paypal experience customary?

#243
post #94

Earlier quoted context omitted.

We have Interac[1] in Canada and it works quite well. [1]: https://en.wikipedia.org/wiki/Interac

Interac "works" but has many pitfalls. Some examples: - Inability to issue refunds - Lack of 2 factor authentication - Non-unique payment addresses (receiving emails are not bound to one account or even one person)

Those are fairly small pitfalls. You can send money back without a refund button. Authentication is done through your bank, if your bank has 2FA, then you have 2FA for Interact. Not sure what you are referring to about the payment address, but declaring the email the unique ID seems to be a decent solution for me.

Re: Is this Paypal experience customary?

#244

Earlier quoted context omitted.

Why did this shake you so bad? You talked to a rep and they fixed it. That's what customer reps are for. If you have humans combing through records for malicious activity and reading off a rubric, you probably would've had the same issue.

There's a few different reasons: First, reading about similar experiences didn't make me optimistic. It seemed like 50/50 between getting someone who would help and someone who would tell you that the case is forever closed without recourse. I got the feeling that the in weird cases like mine these techs didn't actually understand what was going on and it was just the luck of the draw of what tech you got. Second, I…

The irony of this whole thing being that people are constantly creating fake accounts to bid on items and not pay. I rarely sell stuff on eBay, but when I do, some 0 feedback buyer with a fake address wins my auction, then never pays, and will never get banned. I just have a hard time believing that they do a good job at account auditing at all with how often I get fucked on my sales.

Re: Is this Paypal experience customary?

#245
post #157

Earlier quoted context omitted.

You don't have a problem with money flowing in to and out of your account, so long as it all balances out in the end? Really? Then you won't mind if I borrow the keys to your account. You'll never notice a thing. Even if PP is just covering their embarrassment over a mistake, it is still nonsense on stilts that they stonewall and bullshit about transactions flowing through your account. Who knows if they're even lega…

You would never notice a bank correcting it's own error on your bank statement. They don't post it as a credit followed by a reversal - they remove the accidental credit. It just disappears from your statement. It happens ALL the time, and you'd never notice or be notified.

no, it doesn't.

Re: Is this Paypal experience customary?

#246
post #52

Earlier quoted context omitted.

Bad idea. If you did that you could end up paying back the money twice, once for your own payment and another for paypal's own refund.

This is incorrect and not how paypal handles refunds. This is merchant 101: always refund suspicious payments before your payment processor has to do it, it'd be really bizarre if Paypal was somehow the only exception in the industry.

lol couldn't possibly be worse advice in this thread. 100% do not listen to this and NEVER refund the transfer

Re: Is this Paypal experience customary?

#247
post #246
post #52

Earlier quoted context omitted.

This is incorrect and not how paypal handles refunds. This is merchant 101: always refund suspicious payments before your payment processor has to do it, it'd be really bizarre if Paypal was somehow the only exception in the industry.

lol couldn't possibly be worse advice in this thread. 100% do not listen to this and NEVER refund the transfer

Why not?

The only way I see this going wrong is if instead of doing a refund you create a new transfer to send the money back, but you obviously shouldn't do that.

Re: Is this Paypal experience customary?

#248
post #193
post #10

Earlier quoted context omitted.

P.s. never ever link any account with shared funds to PayPal. Business or otherwise, open a completely separate account for PayPal if you must use it. Imagine having PayPal place a hold on the funds in your account to make sure refunds/fraud can be handled. Then when a customer does request a refund you’re literally unable to process the refund because it won’t take it from the funds you just received that are held.…

Why would you "automatically lose all disputes?" This is what happened to me: I got an eBay order and shipped it out, transferred the funds out of PayPal. Buyer sends me an eBay message saying "OMG I'm so sorry but my eBay account was hacked." I believe them because when I googled the shipping address the package went to a foreign freight forwarder. I don't worry because the address was "confirmed" in PayPal, so I'm…

We were on the merchant side.

First, PayPal doesn't like it when your dispute ratio increases. The best way to handle disputes as a merchant is just to give the customer what they want. Most times this is a refund.

Second, when fraud occurs most PayPal users dispute any transactions as soon as they get their account back.

Third, You cannot refund a payment from a held or rolling hold balance. PayPal retroactively applied a rolling hold to our account of ~30% of our monthly gross transactions for a rolling 90 days. The way this works on PayPal, at least at that time, means that until your rolling hold balance is equal to 30% of your last 90 days transactions any funding of and payments into the account IMMEDIATELY get sucked into that rolling hold. We would auto flush the completed transaction account balance nightly. So now we're in a situation where trying to refund a customer wants you to add funds to your account, but as soon as the funds are added they are applied to the rolling hold. So, you click Refund on the dispute and you're unable to refund it. Eventually the dispute is automatically closed in their favor and the account balance goes negative. At that point you can fund the account and it'll apply to the negative balance first.

This was my experience at least, and trust me it was one of the most stressful events I ever encountered. Most of that stress was not knowing what was going on and why, and trying to get anything out of PayPal. Their processes are so opaque for merchants in many cases.

Re: Is this Paypal experience customary?

#249

Learned the hard way you make a separate bank account to link to PayPal. You turn off overdraft and you keep that sucker empty . It's like living with a drug addict. They may be family but you sure as hell dont leave cash or valuables laying about...

> like living with a drug addict Great analogy! Despite enjoying a long relationship, Paypal will very possibly stab you in the back and rob you blind in a blink of an eye then become incommunicado.

As a business I can confirm that.

"Oh, yeah, don't worry, 3D secure can't be forced for all payments, but we got you, we'll enable it when we think it might be abuse. Also, our seller protection covers you."

All the time: "Here is a customer that made 12 purchases during the last 13 months. We took the money, but you have to prove that the card wasn't stolen and that the customer got what he paid for. We didn't enable 3D secure for this transaction, so please fix this for us and we'll give you your money back. Also, if you don't we'll take some more money from your account. Seller protection does not cover this as services are in a gray-zone."

240K frozen and taken since 2012 and still counting! At least I've started to win all the cases, but it takes a lot of time. Time to switch to stripe where I can force 3D secure...

PayPal is a joke. A bad joke.

Re: Is this Paypal experience customary?

#250

I rarely use Paypal, but was forced to use it recently for something with no other payment option. Whilst there I decided to change my password, and was horrified to find that they limit passwords to 20 characters. It got me thinking about the standard assumption that any system limiting chars in a password must be storing passwords in plaintext and not hashing them, else there would be no logical reason to do so (si…

My PayPal password is along the lines of thirty-two characters, so this comment confuses me a lot.
Post reply on HN