Live data from Hacker News

What’s going on with security at PayPal?

christianvarga.com

1–10 of 103 posts

Re: What’s going on with security at PayPal?

#2
My wife has been getting a bunch of these today. I still don't see what the potential problem is if an attacker has my wife's email (which I can imagine has been made public by 100 data breaches etc) and phone number. A bad actor can't use those to log into Paypal? You still need to GET the text message code. Is the risk a SIM Swapping attack?

Re: What’s going on with security at PayPal?

#5

My wife has been getting a bunch of these today. I still don't see what the potential problem is if an attacker has my wife's email (which I can imagine has been made public by 100 data breaches etc) and phone number. A bad actor can't use those to log into Paypal? You still need to GET the text message code. Is the risk a SIM Swapping attack?

SIM swapping is pretty easy, or you just call the number right after or before and pretend to be PayPal checking something.

“We’re verifying your account, please read the number I’m about to send you.”

This is made worse because actual banks actually do this.

Re: What’s going on with security at PayPal?

#6
> PayPal’s default method of login is now a one-time code sent via SMS

> You cannot disable this method of login, and you cannot remove your phone number from your account.

Well. I'm used to thinking poorly of PayPal, but that's remarkable. Wonder if someone lost money if they could take PayPal to court on account of what could be argued as negligence? (Or maybe not; IANAL for a reason.)

Re: What’s going on with security at PayPal?

#7

My wife has been getting a bunch of these today. I still don't see what the potential problem is if an attacker has my wife's email (which I can imagine has been made public by 100 data breaches etc) and phone number. A bad actor can't use those to log into Paypal? You still need to GET the text message code. Is the risk a SIM Swapping attack?

If nothing else, it's information disclosure; you should not be able to go from having a person's email address to having even part of their phone number.

Re: What’s going on with security at PayPal?

#8

My wife has been getting a bunch of these today. I still don't see what the potential problem is if an attacker has my wife's email (which I can imagine has been made public by 100 data breaches etc) and phone number. A bad actor can't use those to log into Paypal? You still need to GET the text message code. Is the risk a SIM Swapping attack?

Six digit code means they can brute force it if they try across enough accounts. 500k tries they'll have 50% success rate of brute forcing 1 account.

Re: What’s going on with security at PayPal?

#9
No strong disagreements with the article, however... It's TOTP, not TOPT (a mistake made throughout the article). I am skeptical of the qualifications and much of the basis for complaint.

Using anything based on a phone for sole verification is inexcusable in any situation, but is that really the case with PayPal? I have an account with MFA and... I don't think that's true

Post reply on HN