Live data from Hacker News

What’s going on with security at PayPal?

christianvarga.com

81–90 of 103 posts

Re: What’s going on with security at PayPal?

#81

Anything that involves money or things of value I use my yubikey for. If they don't provide 2FA via that method I just look elsewhere. If it's a magazine or comments section? who cares, use a mozmail temp address.

It's not about 2FA though. The problem is that PayPal allows users to log in via a one-time code sent via SMS, without the need to enter their password or TOTP (I assume this extends to hardware keys as well). They're doing 1FA over SMS and there's no way to opt out.

Re: What’s going on with security at PayPal?

#82
post #72
post #66

Earlier quoted context omitted.

Well in the EU credit/debit card fees are capped at 0.3/0.2% so while not exactly fair it’s not a huge deal compared to the US (where everyone is paying for credit card users rewards and cash backs). AFAIK only SEPA direct debit transfers can be canceled/reversed so normal transfers are still not (easily) reversible.

0.3/0.2% caps are for customers accounts (and don't cover missed payments which can be punitively charged). merchant fees can still be very high, and silently passed on to customers. The fact that the law obfuscates what the CC companies are actually getting from a transaction should worry us, as they can sneak merchant fees up each year without push-back from the general public.

You’re right. It seem the fees are still around 1% at least for smaller businesses in my country.

Re: What’s going on with security at PayPal?

#83
post #68
post #67

After reading the discussion here I decided to delete my paypal account. So I attempted to log in, and it required me to provide a 2FA authentication using SMS. Problem is that I don't have access to the registered number anymore. So now I can't log in, which prevents me from deleting the account.

Send a GDPR request to delete it to their support.

Thank you. I order to contact support, I had to log in, so I had to use a different account just you be able to ask the question. We'll see what they reply.

If this fails, I'll go the GDPR route.

Re: What’s going on with security at PayPal?

#85
post #17

> So I have a complex password and TOPT to protect my account. Forget these, because PayPal’s default method of login is now a one-time code sent via SMS. Yes, the very same medium that is generally considered unsafe for two-factor authentication is used by PayPal as the only factor; bypassing both password and TOPT for what appears to be full access to your account. You cannot disable this method of login, and you c…

Can't send sms if there's no phone number to begin with (I never added). Accidentally big brain time

Re: What’s going on with security at PayPal?

#86

Earlier quoted context omitted.

This comparison was also made a lot in the early days of crypto, but at this point we're 15 years into crypto and real-life use cases remain awfully thin on the ground.

15 years because the Bitcoin whitepaper was written in 2008? The Internet Protocol whitepaper was written in 1974. 15 years later, in 1989, real-life use cases of the internet were at least as thin on the ground as crypto use cases today.

By 1989 the Internet's primary applications are email, Usenet news, and the file transfer protocol. Those may not seem like much today, but they're a big deal in 1989.

Re: What’s going on with security at PayPal?

#87
post #17

> So I have a complex password and TOPT to protect my account. Forget these, because PayPal’s default method of login is now a one-time code sent via SMS. Yes, the very same medium that is generally considered unsafe for two-factor authentication is used by PayPal as the only factor; bypassing both password and TOPT for what appears to be full access to your account. You cannot disable this method of login, and you c…

I've been getting this off and on for a while now. It never proactively sent me the SMS, but it yanks me out of the normal auth flow and asks if I want to authenticate by text, making me click a button to just use my password + 2FA.

Re: What’s going on with security at PayPal?

#88

Believe it or not, PayPal has finally set up security keys and authenticator apps as a 2FA. This must have been recent. I remember trying to do this a year or two ago, after someone cracked my LinkedIn password (but not the 2FA), and 2FA was not available on PayPal at the time.

wow, webauthn is indeed available now.

i've been using totp for a long time but webauthn has been long overdue.

Re: What’s going on with security at PayPal?

#89
I've been getting spammed with these SMS codes. They've been baffling me because I use MFA, and didn't understand what mechanism could be sending me random codes. I'm glad I know now.

I hope PayPal fixes this shit soon. Not only is this a serious security problem, but the texts are incredibly annoying.

Oddly, I can't make it happen myself -- I don't get the screen being discussed -- but clearly some criminal somewhere does. Must be limited to certain geographic areas?

Re: What’s going on with security at PayPal?

#90

Earlier quoted context omitted.

15 years because the Bitcoin whitepaper was written in 2008? The Internet Protocol whitepaper was written in 1974. 15 years later, in 1989, real-life use cases of the internet were at least as thin on the ground as crypto use cases today.

By 1989 the Internet's primary applications are email, Usenet news, and the file transfer protocol. Those may not seem like much today, but they're a big deal in 1989.

In crypto, there are payments, store of value, decentralized exchanges, smart contracts, NFTs, DAOs...

I tend to think crypto is used more already than the internet was in 1989?

Post reply on HN