PayPal does not know how to detect fraud
tooltrainer.com
tooltrainer.com
Where I got lost though is the selling of an extremely valuable asset such as shop.com (a four-letter, dictionary, brandable, .com domain) at well under value. The first lesson in fraud detection is that if it seems to good to be true it probably is. A domain that probably has a value at close to a $1M going for under $1000 would fit the definition of too good to be true. Yeah, partners break up and can do some angry things, but selling an asset at such a heavily discounted price would certainly be shocking to me. A little more due diligence on buyer side would have prevented this. Otherwise I have a 100 foot yacht and an ocean front property in Nevada for sale for $1000 if you are interested. :) I mean even PayPal warns flat out warns about these types of transactions (https://www.paypal.com/eBay/cgi-bin/webscr?cmd=p/gen/fraud-t...)
To me this entire story is like saying I went to Walmart and parked my car. They have security cameras in the parking lot and I asked an employee if those cameras were monitored. The employee told me yes so I left the windows down in my car with my laptop and a wallet full of cash on the seat. I was only going in the store for a minute and I felt assured that if anyone stole them I could easily identify them and get my stuff back. When I came out everything was gone. When I asked the security guard to review the footage I could not see who the people were and could not identify them. I am now going to complain about Walmart's security practices because of this incident.
The good news for the OP is that at least he has ads on his site and I am sure the traffic he is getting from this post he may make back a few of those lost dollars in ad revenue :)
With domains you have to make sure you know the history of the domain (which takes a bit of research) and additionally most people in the domain business, at least with valuable domains, tend to use escrow.com as an intermediary to make sure there is recourse.
That said another thing to watch out for is buying a domain which has been stolen from someone which does happen. In that case a domain is priced attractively (not to cheap not to expensive) and unloaded quickly before the real owner even knows what has happened. This can happen as a result of a simple hijacking of an email address (of the rightful owner) or by social engineering the registrar. As only two examples. That is much harder to detect and even in the case of using escrow.com you would still be out of the domain once it gets yanked back to the original registrant.
Source of the above: Me, I've been doing this for almost 20 years and get paid to buy names as well as buy on my own account.
From another thread:
I once made a major purchase off eBay and received merchandise that was substantially different than what I ordered.
It took 4 months, many exchanges with PayPal via their "dispute center" and many phone calls to have my purchase refunded. They even closed my dispute at one point claiming that I hadn't returned the merchandise because their support staff was too incompetent to check the DHL tracking # on DHL's web site to verify that I had indeed returned the merchandise (at my expense).
I will never make a major purchase with PayPal again.
I actually never got around to making a purchase with PayPal before I decided to avoid them like the plague (based on everything I had heard about their business practices). I was a teenager when I made the decision and it was more about not supporting an unethical company, but it's nice to be periodically vindicated.
I bought a couple of monitors off the website, and apparently there was an issue with the calculation of taxes (which wasn't noticed) resulting in a pretty decent discount. Well, I paid for the monitors through PayPal and authorized a charge of ~$600. A few days later I check up on the status of my order and it states that I was charged ~$800 due to an "Additional authorization" charge. This was because Dell noticed their mistake and instead of communicating it to me, just decided to sneak it in there, which was only noticed by me after checking up on it, no notification was sent out about this.
So apparently, PayPal allows a company to charge a customer more than they have authorized a payment for, and don't even bother to send a courtesy notification about this.
Buyer beware.
Actually, I'm not surprised. Paypal has no incentive to resolve disputes or stop fraud. Every company has a limit over which they will intentionally try not to honor any fraud protections. With Paypal it's just zero. For example, American Express is usually good at resolving disputes, but a dispute that a few thousand dollars will not be resolved in your favor even if you can prove that what you got was not what you paid for I paid for an air-conditioned Marriott room and got 6 rooms (one at a time) in two different Marriotts, none with AC that worked over a period of three weeks. (Apparently, Marriotts in Cancun advertise AC but don't let you use it, a problem that I've ran into at one other major hotel as well, though only for one night.) Amex, at least is a reputable company. Paypal on the other hand is a company that knowingly signed up many people for credit cards without their knowledge. I would not expect anything from Paypal and I would only use a credit card and make purchases up to an amount I know I can dispute with the CC and win. If you're using Paypal any other way, chances are you will get fucked.
The takeaway is that PayPal has a ludicrous policy of accepting easily faked screenshots as indisputable truth that a domain has been transferred, as the OP demonstrates here: http://tooltrainer.com/blog/watch-me-hack-and-own-paypal-com...
Reminds me of the the people saying it was okay that Ashley Madison got hacked, because we don't like cheaters and therefore they deserve whatever they get. And while we're busy feeling morally superior, the real bad guys continue to scam and harm more people.
By selling shop.com for $500? A 4 letter, dictionary word, extremely brandable, .com?
> Has nobody even bothered to do a whois lookup on shop.com?
No, not even you apparently. Well done. This was a lesson valued at $500, be glad it wasn't more.
The entire reason Paypal exists as a Third-Party payment processor is to ensure fairness on both sides. They failed.
Importantly though in this case the buyer knew the price was to good to be true and his greed got the best of him. Plus the thing to keep in mind is the level to which a company like paypal can protect against fraud. Might be similar to expecting that a dry cleaner should detect a forged clothing ticket perhaps. Or a restaurant should detect that another diner is using your reservation. Doesn't scale very well.
I think your good judgement was clouded by what you though was an opportunity to make a large sum of money. As such you let your guard down. And ignored common sense.
For example, let's say you are on assignment for the US Government and you have a bunch of secrets in your briefcase. (Or you work for Google, whatever). You go to a bar and a super attractive hot woman (or man) strikes up a conversation with you. You are nowhere near attractive or rich or smart enough to have this women she is a 12 and you can only score 5's and that's if the woman is drunk. (let's hypothesize). So your brain should be saying "danger Will Robinson" [1] but instead it thinks "wow she likes me I'm surprised but hey anything can happen!!!". And the next thing you know she has walked off with your suitcase of secrets. What do they call that? A Honey Pot? Whatever. My point is perhaps greed is the wrong word so what is the word to describe what I am talking about here? After all you knew this was to good to be true and almost certainly not true however you did it anyway.
By the way I don't buy into that whole "to good to be true probably is" line it all depends on the circumstances. However what you did here was clearly someone outsmarted you, they knew paypal better than you did.
The lesson to take away is more "Use an escrow service and do due diligence" rather than "haha you got scammed"
Side note - author got his money back. Everyone wins!
tldr; I find it pretty hard to feel compassion for the author here.
That said, isn't the real story that domain escrow services exist for a reason?
No, story is that Paypal has been a haven for scammers and crooks since it started.
The lesson of the story is that they shouldn't be buying domains for any non-trivial amount of money without utilizing an escrow service.
The story is that every financial exchange has been a haven for spammers and crooks since they started.
Just think about the price you're paying/selling the site for. If the amount is more than you're willing to lose, use an escrow service.
Lost all respect for the author once I read that. Squatting on domains and making people who want to legitimately use the domains pay far above market rate is ridiculously scummy.
Here is one recent example that was eye-opening to me: http://www.bloombergview.com/articles/2015-07-07/can-you-rea....
What value does a domain squatter add?
Though, these are fairly complex financial concepts, so it's easy for people to jump to the conclusion that large swaths of the financial industry are worthless. (Of course, some are, but many are not)
The rest of us call the people who run websites like that domain squatters, because they are adding zero value to the internet and simply tie up a domain which they would likely sell for the 'right' offer.
Everytime someone trots out that squatter argument they assume that if the person who owned it that wants to sell it "for ill gotten gains" hadn't gotten to the domain first, that it would have been sitting around for them at the point they needed it for their idea. In 2015 or in 2005.
So, for arguments sake, if PG had wanted to use "Yc.com" instead of Ycombinator.com in 2005, the domain yc.com would just be sitting waiting for him to use at a cost of $NOMINAL_OR_AFFORDABLE because NOBODY ELSE would have used it for their "bake sale website".
Lesson learned for him, I guess.
Exactly, the only way to find out if PayPal is on the ball is to make a mistake, I can't understand why there are so many comments harping on about this blatantly obvious point.
Otherwise what would the author (or any journalist) do? Fake a fraudulent sale (which would still be fraud)? Or intentionally find a fraudulent seller? "Hey PayPal, I purposefully went and found a fraudulent sale, can I have my money back?"
Frankly, given that a thorough fraud investigation would have revealed two separate attempts to gauge eBay/PayPal's refund policy followed by the purchase of an asset, followed by the claim, he's lucky he hasn't been accused of being complicit in the scam. A more on-the-ball protection team certainly would have raised that possibility and escalated it.
Which means that PayPal still isn't doing their job correctly.
No. He called and spoke to both eBay (who said they would not) and to PayPal and they assured him they would underwrite it. Per his article:
"The very helpful gentleman I spoke to informed me that ever since the eBay/Paypal split recently, domains are actually covered by their buyer protection now!" (Emphasis in the original)
Frankly, I can't recall ever seeing any complainant more deserving of being on the wrong side of Paypal's discretion than this one.
Ebay was more than happy to let these guys operate on their platform, I have supplied them all the evidence but nothing happened.
s/PayPal/Author/
"I should totally provide them screenshots showing that I just sold their domain out from under them."
Let me elaborate, if your account is taken over and used, or your credit card is fraudulently associated with a PayPal account, then this is fraud (as per PayPal). However in this case, you were willingly using the account to pay someone and entered into the transaction willingly. Even though the outcome was not favourable to you, but PayPal doesn't have the information needed to mediate.
In fact to PayPal it doesn't have the necessary information to judge who is telling the truth: it is as easy to fabricate a GoDaddy letter or whatever documentations you provided, and there is no easy way to tell (yes, PayPal can call one by one to verify, but this isn't scalable and very expensive). That is one of the reasons why eBay doesn't offer buyer protection.
I doubt you will get better protection with other alternatives like credit cards or bank transfers.
PayPal's buyer protection is supposed to protect against items that are "significantly not as described" which this clearly was. So yes, in that respect and by PayPal's own stated guidelines, it is fraud.
A couple days after delivery I get a PayPal dispute saying he filed a fraud charge with his CC company for the $1100. It was basically a no questions asked refund to him in the full amount which left me with a $-1100 balance on my PayPal account. So not only did he receive the products, he got all of his money returned to him and I had no way of contacting him due to him living in the UK. I was only racking up my cell phone bill trying to reach him internationally all with no answer.
The only thing PayPal had to offer me in terms of why this happened was "he filed a claim with his credit card company".
So the author was fine taking part in a crime.
"No Mr. Judge, I did not know that large diamond could not cost $10."
However all he does is attempt to confirm is that he won't be the party to lose money in this scam. He does it thinking well either he will get shop.com and win (at the cost of the owners of shop.com), or it will be a scam and he will get his money back from Paypal and Paypal may or may not get the money back from the seller, in which case either Paypal loses money or everything is back where it began.
He try's to find a no-lose position in someone else's scam, basically trying to scam a scammer. You know what I could respect that, but whining about how you failed to scam the scammer is just annoying.
I'd very much be interested to see the listing, the comms, and the comms with Paypal/ebay.
It's also curious that someone who is posting all of this opted to call support agents all the way instead of having something on record.
Of course none of this proves anything but still these are curiosities.
http://tooltrainer.com/blog/watch-me-hack-and-own-paypal-com...
I always got back my money, but I guess it was riskier than I had thought. I was getting it from eBay, though, and usually the seller would refund to avoid bad feedback anyway.
Personally, I sleep better knowing my funds are in my bank, and you can, too! :)
I guess for this specific instance, they can conference call GoDaddy and have the third party vouch for things.
But how do you rule in a he-said-she-said situation? If a customer says they received a ceiling tile instead of an iPad? For other digital goods like in-game characters?
I forget what the scheme is called. With digital things the buyer and the seller put 100% of the value of the transaction in a bag. If either disputes the transaction you burn the bag.
© 1997-2015 SHOP MA, INC. All other designated trademarks, copyrights, and brands are the property of their respective owners. (prdmf002)
Doesn't really look like a shop that's ready to turn out the lights.
http://tooltrainer.com/blog/paypal-executive-escalations-del...
"Shop Now, Pay Later With PayPal Credit – Learn More"
Trying to bite my tongue here, but ... did you? Not saying this would tell you whether the domain was actually for sale or not, but it might offer some clues and/or at least a contact point (if not shop.com itself, which is totally active).
There wasn't much due diligence here, and it seems like OP was relying on Ebay's protection to secure a lazy gamble.