Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

51–60 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#51
post #20

This doesn't surprise me. I'm currently trying to get a refund out of PayPal after what looks like a massive flaw in their refund process. I paid for something on eBay and it appears to have been a compromised account. The original auction, feedback history, etc, looked legit. The flow was this: 1) I pay for a product on eBay using PayPal, using my creditcard (direct from card, not from any existing PayPal balance).…

I've raised a chargeback with the issuing bank, which should hopefully make PayPal sit up and put a bit more effort into sorting this out.

Or just close your account and ban you.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#52

Earlier quoted context omitted.

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

Yet paypal's policy explictly says authentication bypasses, like the 2FA bypass they showed, are in scope >Authentication or authorization flaws, including insecure direct object references and authentication bypass Reading with the context of the other out-of-scope issues. I think they meant that the ability to buy or steal someones credentials is not a vulnerability in and of itself. >Vulnerabilities involving stol…

Bypass means skipping steps on PayPal's side (like reading user data without a a password), not skipping steps on user side (stealing their password).

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#53

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

Squid is vastly under-equipped to deal with the security hygiene needed for a project this important.

That's the tragedy of the open source world : mission critical for everyone, but no actor willing to maintain it properly. It's Heartbleed all over again.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#54
post #20

This doesn't surprise me. I'm currently trying to get a refund out of PayPal after what looks like a massive flaw in their refund process. I paid for something on eBay and it appears to have been a compromised account. The original auction, feedback history, etc, looked legit. The flow was this: 1) I pay for a product on eBay using PayPal, using my creditcard (direct from card, not from any existing PayPal balance).…

I've been bitten before by the fact that if you don't use PayPal, eBay's interest in helping you with a refund dispute is exactly zero. And now I learn this. I guess PayPal + credit card is the way to go if you want any chance of a successful refund.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#55

Earlier quoted context omitted.

All these regulations are bs. Designed to keep small players out.

To be fair they are probably not designed specifically for that, the issue is big players are much more likely to have more political leverage. Or is that one much like GDPR? Crazy fines that only big players can afford, in such a case, that was poorly designed.

GDPR max fine is (iirc) 4% of revenue. So if you are a small fish you will be paying less then the big fish. Also the fines are for wilful failure to comply, if you accidentally broke GDPR then your first offence is going to be more a slap on the wrist then an instant 4%.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#56

Earlier quoted context omitted.

All these regulations are bs. Designed to keep small players out.

They were created for sincere reasons, and with best intentions. In the real world best intentions always conflict with the motivations of individual players. It just isn't reasonable that PayPal would be cut off. That was always a toothless threat, at least for larger players. As an aside, PayPal is a marvel to me because it is effectively lost in time. Using their tools and interface is like stepping back to 1995,…

> They were created for sincere reasons, and with best intentions.

No? They were created by the industry to avoid actually being regulated and are a way to shift liability.

That doesn't mean they aren't also beneficial, but that's more a side effect than the intention.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#57
There is plenty of blame to go around beyond the management. Management is always going to deflect, deny, or do whatever to save their face. There must be “architect/lead engineer” level folks whose primary task is to engineer these stuff well. WTF are they doing?

There should be a wall of shame for these (not by person, but by company and group). Next time you get a contact/candidate who “lead the sign-on 2fa management” at PayPal, we will know to be extremely cautious.

There is no “karma” in tech world. People design the shittiest systems in company 1 and then move on to some other role in company 2 and float around taking credit for more and more stuff someone else did.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#58

Earlier quoted context omitted.

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…

HackerOne states they are a PCI-DSS auditor approved organization [1]. [1] https://www.hackerone.com/product/challenge

Yeah but someone reporting a vulnerability to HackerOne is not the same as HackerOne reporting it. Otherwise you could just spam HackerOne with reports and remove someone’s compliance.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#59

Earlier quoted context omitted.

Could you link that article? Because the screenshot in this article pretty clearly shows PayPal sending an SMS to the user's phone.

https://www.forbes.com/sites/zakdoffman/2020/02/22/paypal-cr... I should note that I haven't really investigated this so I don't claim to know any truth.

I was about to dismiss the article thanks to lines like this:

> In essence, it would work with phished credentials just as well as with stolen ones

But, sure enough, it's not the opt-in 2FA, triggered on every login, that was bypassed, but the 2FA checks triggered when PayPal detects suspicious activity. As far as I can tell, if you've enabled 2FA yourself, this bypass won't work. Thanks for the link! Going to go make sure I've enabled that...

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#60

Earlier quoted context omitted.

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…

HackerOne states they are a PCI-DSS auditor approved organization [1]. [1] https://www.hackerone.com/product/challenge

> HackerOne states they are a PCI-DSS auditor approved organization

Not anywhere on the page you linked. And a "PCI-DSS auditor approved organization" is not a "PCI-DSS approved scanning vendor" which if they were you could just quote the certificate number instead of link to HackerOne.

----

EDIT: I guess you are referring to this:

> Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.

This in no way is the same as claiming "we are a PCI-DSS auditor approved organization". Which again, would be irrelevant if it was the case.

----

Further, if you read the article, it is clear the "We" does not refer to "HackerOne".

> When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level.

As far as I can tell "We" refers to cybernews.com

And again even if cybernews was a PCI-DSS approved scanning vendor it would still have to qualify as an official external scan within the PCI-DSS framework.

Post reply on HN