Sadly, as far as I know, Paypal only allows SMS. I believe business account, you cannot link your Paypal to Braintrees and thus you cannot use any 2-auth authenticator. If I am wrong, please correct me, but I see no other options on Paypal, which is ridiculous, considering Paypal is such an important service. SMS should not be used for any critical services, but in cases like Paypal there is no choice.
It is possible to enroll hardware tokens, but I believe SMS is a prerequisite. It's also allegedly possible to deactivate in a bunch of other ways, e.g. by adding a new credit card. https://github.com/dlenski/python-vipaccess
Vulnerabilities in mobile networks opens Bitcoin wallets to hackers
51–56 of 56 posts
Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers
#52Earlier quoted context omitted.
What a frightening experience! I'm sorry this happened to you. Curious to understand how these attacker obtain your phone number in the first place? I mean it's not something you publish widely right?
I don’t mean to say it was OP’s fault but you shouldn’t really use your primary phone number for 2FA anyways. Using a burner dumb phone dedicated only for 2FA should be standard, right?
Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers
#53I was targeted this evening by a hacker who ported my phone number, and then got into FB + Yahoo (SMS reset). The motive appears to be bitcoin, based on the people contacted via facebook. Is it possible the initial PIN that was sent by Tmobile was intercepted via SS7? I am trying to find out if my phone (android) is compromised as well. The accounts and phone number are back under my control but I want to find out th…
What a frightening experience! I'm sorry this happened to you. Curious to understand how these attacker obtain your phone number in the first place? I mean it's not something you publish widely right?
Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers
#54Earlier quoted context omitted.
What a frightening experience! I'm sorry this happened to you. Curious to understand how these attacker obtain your phone number in the first place? I mean it's not something you publish widely right?
I don’t mean to say it was OP’s fault but you shouldn’t really use your primary phone number for 2FA anyways. Using a burner dumb phone dedicated only for 2FA should be standard, right?
Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers
#55This is why I use a hardware wallet https://trezor.io
I'll be a happy man when the code and specs for this little guy become public: https://firefly.city ("Airgap" ETH wallet for $5)
https://www.reddit.com/r/ethereum/comments/71jc83/firefly_up...
New crowd-funding page!
Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers
#56Slightly less exciting TLDR: as many of you already know, SMS isn't a good second factor for auth. That includes entrusting your Bitcoin wallet's private keys to a company using SMS for 2FA. Let's mention "cryptocurrency" as well to show up in more news alerts.
Paypal is offender number one. I don't understand why they can't use google authenticator. Is it some kind of pride thing, like paypal and Amazon?
But They still haven't ported all their systems to 2FA yet. Some pages require you to enter your password and append your 2fa token to the end of it (Mainly when logging in on mobile) and I know of a couple of stores that due to their PayPal integration I can not get to the final "Pay Now" page on paypal even though I successfully log into PayPal. But when you would normally get to that final page to press "Pay" the page just times out. I have to disable 2fa and do it again.
You can use "Symantec VIP" (it was renamed after Verisign was brought out). Though they don't make the sign up very easy. You have to go to the 2 factor page ("Security key") under security, press "Get security key", when prompted to enter your phone number press "cancel" then press "Activate your PayPal or VIP (VeriSign Identity Protection) token" and then enroll up as normal.
Its not Google Auth and it kinda feels like I can now gaining a collection of 2FA apps (iirc Namecheap's non sms 2fa is powered by Authy but you can not use Authy) so I do which they would all adopt a standard.