Live data from Hacker News

What’s going on with security at PayPal?

christianvarga.com

41–50 of 103 posts

Re: What’s going on with security at PayPal?

#41

This confuses me about discussions like these on HN: On the one hand, there are so many stories on HN complaining about incompetent and dystopian security practices in the financial industry. And many tips on how to cope with it. Like not giving PayPal your bank account, rather pay 3% to put a credit card between PayPal and your bank account. And to keep your phone number secret to avoid sim swapping and PayPal expos…

Because at the end of the day PayPal is better for the average consumer than a solution where somebody needs to handle a private key.

A lot of tech savvy people lost money due to losing their keys. Now imagine the disaster if your mother needs to handle them.

Payment solutions are also heavily regulated, often also in favour of the consumer. If my bank goes bankrupt or gets hacked I have much better garuantees of getting my money back compared to when I lose my private key.

The final reason (in my opinion) that "private key solutions" are not adding much is that to legally use it you need to comply with the regulations for traditional finance. Hosting an exchange without KYC can be considered illigal in many western countries.

Want to advocate for less regulations in finance? Sure, that's a valid political opinion. But you need to go into political solutions for that, not technological ones.

Re: What’s going on with security at PayPal?

#42
post #34

This is silly. Nobody is going to sim swap you to steal your paypal funds, getting the money out is way too difficult.

I’ve seen sim swaps to get desirable instagram handles. I have to believe it’s easier to extract money from a PayPal account takeover than insta.

Re: What’s going on with security at PayPal?

#43
post #10

If true, this is borderline criminal incompetence. However, I can't reproduce the issue described in the article.

Same. The author says when you enter an email, an SMS is sent and number revealed. What really happens is that it asks me for a password. Below that there's an option to get a one time code. Clicking that reveals the first digit of the area code, then the last 4 digits. You must then click yet again to make it actually send. So in short, it didn't immediately send an SMS and never showed the full number.

I was able to reproduce it in incognito. I’m guessing it works only on devices I have signed on before? Someone they have a way to fingerprint me? Irrespective of it, this whole dumbing down security for UX is unacceptable. It’s not even good UX for someone like me with a password manager.

Re: What’s going on with security at PayPal?

#44
post #38

This confuses me about discussions like these on HN: On the one hand, there are so many stories on HN complaining about incompetent and dystopian security practices in the financial industry. And many tips on how to cope with it. Like not giving PayPal your bank account, rather pay 3% to put a credit card between PayPal and your bank account. And to keep your phone number secret to avoid sim swapping and PayPal expos…

Cryptocurrencies are what you obviously mean by your "a solution based on cryptography" phrase. As they exist now, they are even more difficult to use safely and securely. For every one person who gets hacked via paypal's SMS crap and a simswap, there would be 50 people who would lose their crypto wallet to dropping their phone in the river and forgetting the passphrase. It's perfectly consistent to have issues with…

Which government? US? German? UK? Australian? ..

Re: What’s going on with security at PayPal?

#45

This confuses me about discussions like these on HN: On the one hand, there are so many stories on HN complaining about incompetent and dystopian security practices in the financial industry. And many tips on how to cope with it. Like not giving PayPal your bank account, rather pay 3% to put a credit card between PayPal and your bank account. And to keep your phone number secret to avoid sim swapping and PayPal expos…

I can't claim to speak for "everyone", but I was a crypto fanboy in the early days, when it seemed destined to be an actual currency, which would be great for all the reasons you mention. But at some point it all went off the rails: crypto became a deeply rigged casino targeting the most vulnerable people they could find, fueled by insane amounts of energy consumption and money laundering.

The same happened during the early days of the internet. Insane amounts of companies were founded, hyped and IPOed. Many many naive people turned into investors, losing trillions of Dollars.

Should we have discarded the whole internet idea because of that?

Re: What’s going on with security at PayPal?

#47

I have never once given one of these valley payments companies my bank account information, and this sort of garbage is why. If I need to pay something via PayPal, Venmo, or whoever the hell else, I'll use a credit card and happily eat a 3% fee for doing so, and that's the price I pay to be able to tell Chase or Amex to handle it when some fraudster gets at my info rather than watch my bank account get drained.

In Germany (Europe?) it's not allowed to charge additional fees for using a credit/debitcard. However even bank transactions that were externally charged from your account can be reversed for up to 6 weeks.

Re: What’s going on with security at PayPal?

#48

I have never once given one of these valley payments companies my bank account information, and this sort of garbage is why. If I need to pay something via PayPal, Venmo, or whoever the hell else, I'll use a credit card and happily eat a 3% fee for doing so, and that's the price I pay to be able to tell Chase or Amex to handle it when some fraudster gets at my info rather than watch my bank account get drained.

Paypal can link to your CC and I have never seen a reduced fee for Paypal either.

But why have the middleman if you can a avoid it.

Re: What’s going on with security at PayPal?

#49

This confuses me about discussions like these on HN: On the one hand, there are so many stories on HN complaining about incompetent and dystopian security practices in the financial industry. And many tips on how to cope with it. Like not giving PayPal your bank account, rather pay 3% to put a credit card between PayPal and your bank account. And to keep your phone number secret to avoid sim swapping and PayPal expos…

Because at the end of the day PayPal is better for the average consumer than a solution where somebody needs to handle a private key. A lot of tech savvy people lost money due to losing their keys. Now imagine the disaster if your mother needs to handle them. Payment solutions are also heavily regulated, often also in favour of the consumer. If my bank goes bankrupt or gets hacked I have much better garuantees of get…

For the average use "handle a private key" just means installing an app. If crypto currencies were popular enough, it would already come with a phone, just like a browser.

People already keep super important stuff on their phones. Their email accounts, their lifetimes photos, their contacts, their notes... Losing those seems to be more dangerous than losing your digital wallet. An event that would be similar to losing your physical wallet.

Re: What’s going on with security at PayPal?

#50

My recent PayPal experience: - try to pay for rental car in Mexico - transaction declined - get email saying account permanently locked - get 2nd email w/ link to unblock (says click on unblock notification) - no notification - chatbot asks if I want help, redirects me to help page - help page contains none of the following: unblock, unlock, locked - chatbot asks if I still need help, says I have to call - call link…

Too much software development is getting divvied into different product development groups, and collectively it leads to the creation of flows through the product that make literally no sense, yet all of the smaller parts are seemingly fine, because nobody is the thinking of macro-level experience.

Yep, or it made sense at one time, until the in that was overseeing the holistic workflow left.
Post reply on HN