Live data from Hacker News

What’s going on with security at PayPal?

christianvarga.com

71–80 of 103 posts

Re: What’s going on with security at PayPal?

#71
post #66
post #63

Earlier quoted context omitted.

Actually its not allowed to tell the customer about additional fees for using credit cards. The fees are still applied to the merchant, the law just forces the merchant to recoup the fees from all their customers. So in the EU, you are paying credit card fees even when not using a credit card. And i have witnessed many examples in the EU where a person had money transferred from their bank account and the banks could…

Well in the EU credit/debit card fees are capped at 0.3/0.2% so while not exactly fair it’s not a huge deal compared to the US (where everyone is paying for credit card users rewards and cash backs). AFAIK only SEPA direct debit transfers can be canceled/reversed so normal transfers are still not (easily) reversible.

> Well in the EU credit/debit card fees are capped at 0.3/0.2% so while not exactly fair it’s not a huge deal compared to the US (where everyone is paying for credit card users rewards and cash backs).

And cash has it's own processing fees (security - cameras, register, transportation; counting), which are also hidden. Some smaller places (e.g. cafés) have moved to cashless payments only, because the costs around cash, and the hassle involved at every step, is too much.

Re: What’s going on with security at PayPal?

#72
post #66
post #63

Earlier quoted context omitted.

Actually its not allowed to tell the customer about additional fees for using credit cards. The fees are still applied to the merchant, the law just forces the merchant to recoup the fees from all their customers. So in the EU, you are paying credit card fees even when not using a credit card. And i have witnessed many examples in the EU where a person had money transferred from their bank account and the banks could…

Well in the EU credit/debit card fees are capped at 0.3/0.2% so while not exactly fair it’s not a huge deal compared to the US (where everyone is paying for credit card users rewards and cash backs). AFAIK only SEPA direct debit transfers can be canceled/reversed so normal transfers are still not (easily) reversible.

0.3/0.2% caps are for customers accounts (and don't cover missed payments which can be punitively charged). merchant fees can still be very high, and silently passed on to customers. The fact that the law obfuscates what the CC companies are actually getting from a transaction should worry us, as they can sneak merchant fees up each year without push-back from the general public.

Re: What’s going on with security at PayPal?

#73
post #17

> So I have a complex password and TOPT to protect my account. Forget these, because PayPal’s default method of login is now a one-time code sent via SMS. Yes, the very same medium that is generally considered unsafe for two-factor authentication is used by PayPal as the only factor; bypassing both password and TOPT for what appears to be full access to your account. You cannot disable this method of login, and you c…

>Just tested, can't reproduce.

I have seen this for weeks/months now. It happens when you are about to make a purchase. So for instance, if you click on pay with paypal on a different website, it shows up, presumably to reduce friction or improve clickthrough.

Re: What’s going on with security at PayPal?

#74

No strong disagreements with the article, however... It's TOTP, not TOPT (a mistake made throughout the article). I am skeptical of the qualifications and much of the basis for complaint. Using anything based on a phone for sole verification is inexcusable in any situation, but is that really the case with PayPal? I have an account with MFA and... I don't think that's true

OP here - thanks for pointing that out, for some reason when I try to type TOTP my fingers keep defaulting to TOPT - some kind of muscle memory I guess. In any case, this has been corrected, although I'm unsure how a simple spelling mistake discredits the basis for the complaint. > I have an account with MFA and... I don't think that's true Try log in using Incognito/private browser. I am either defaulted into the on…

>although I'm unsure how a simple spelling mistake discredits the basis for the complaint

Welome to HN, the bikeshedding capital of the world.

Re: What’s going on with security at PayPal?

#75
I recently created a new PayPal account. Got locked out almost immediately after adding 2FA via TOTP. First login worked, on the second login I just got a message that they were unable to verify it's really me. When contacting customer service, I was told that this is a known problem and I should just write them an email so they can remove 2FA from my account and then readd it a few days later myself.

When signing up it also told me my provided contact details weren't correct because I had a forbidden special character in the password that I typed in the previous form. Took a while to figure that one out.

Re: What’s going on with security at PayPal?

#76
post #67

After reading the discussion here I decided to delete my paypal account. So I attempted to log in, and it required me to provide a 2FA authentication using SMS. Problem is that I don't have access to the registered number anymore. So now I can't log in, which prevents me from deleting the account.

I had a similar problem for nine months before I could get hold of someone at PayPal. At that moment I was so angry that I chose to close my account. I also don't support businesses that use Bitcoin.

In my case, I had got 2FA through being called by an automated voice giving me a OTP. However, my number in their database had somehow been mangled with a 0 before the country code, so the 2FA had attempted to use the country code as a domestic area code.

BTW. The support assistant on the phone was a young person who had never used land-lines and did not understand what an "area code" was, so I had to explain it to her.

Re: What’s going on with security at PayPal?

#77

> PayPal’s default method of login is now a one-time code sent via SMS > You cannot disable this method of login, and you cannot remove your phone number from your account. Well. I'm used to thinking poorly of PayPal, but that's remarkable. Wonder if someone lost money if they could take PayPal to court on account of what could be argued as negligence? (Or maybe not; IANAL for a reason.)

Likely not. Most companies auto-enroll you into binding arbitration agreements now. If you ever want to opt out of it, you have a small window where you need to print out forms, sign them, and snail mail them. Kind of the opposite philosophy of SMS to login.

Re: What’s going on with security at PayPal?

#78
post #30

The past week I've received two invoices for "bitcoin" in my rarely used paypal account. More deviously, the notes for the invoice contain the phone number to a fake paypal support center run by the scammers. So if you were savvy enough not to pay the invoice they might still steal your info when you call to dispute. There's no way to report it through their website, because it's not a completed transaction. I didn't…

>EDIT- I didn't know you could even set up TOTP.

For a long time you couldn't. They supported Symantec's app, which was TOTP but obfuscated. So for a long time, you had to extract/reverse engineer the seed from the Symantec app.

Re: What’s going on with security at PayPal?

#80

Earlier quoted context omitted.

This comparison was also made a lot in the early days of crypto, but at this point we're 15 years into crypto and real-life use cases remain awfully thin on the ground.

15 years because the Bitcoin whitepaper was written in 2008? The Internet Protocol whitepaper was written in 1974. 15 years later, in 1989, real-life use cases of the internet were at least as thin on the ground as crypto use cases today.

I am so tired of the comparison with the internet because it tries to conclude that crypto will be successful despite the scepticism because people were also sceptic of the internet. You could compare any new thing with the internet and come up with a similar prophecy, but it just isn't given that the success is ever going to come.
Post reply on HN