Lazy Authentication Still the Norm
krebsonsecurity.com
krebsonsecurity.com
There's no excuse for a multi billion $ company to be this lax on security today.
Moreover, lots of people dropping PayPal gives a strong signal that PayPal is not a suitable payment provider. It makes room for a payment provider that does this better and discourages others from feeling forced into the PayPal trap.
(For the record: I closed my PayPal account many years ago, because of abundant evidence of PayPal's unreliability.)
I've listened to the calls made to PayPal by the attackers.
This is somewhat relevant: https://i.imgur.com/Q6j2Jmp.png
(inb4 yet another Krebs article complaining about me)
Finally he gave me a number and suggested I call him back at it. Same problem. He gave me the number. It's a random phone number. I ended up looking up the number and confirming it was associated with the bank and then calling him back on it. Not ideal, but the whole security model is completely broken.
Banks really need to stop phoning people like this. A simple way to do this would be to have a TOTP type password that the caller needs to confirm with the callee, regardless of which direction the call is going on; bank to customer, or customer to bank. As a customer you should be able to ask the bank representative for the shared password and if they can't answer the question then you should call your bank immediately to warn then.
In 2007 or so $50 was taken from my account and sent to SecondLife (remember them?), despite me never having played that game. I think even back then the only way I could prove I was the rightful owner of the account and get my money back was to send a photo of my drivers license.
I'm glad they've stepped up their security game in the past 8 years.
In this case, it's likely that phone support is optimized for speed, rather than security. Good if you're legit, bad if you're a target.
There was (Still is!) something very similar in an organization called CAcert[1], which was a predecessor to the current Let's Encrypt project (free SSL certificates) that hasn't succeeded dramatically because it hasn't been able to get its root certificate into browsers.
Basically they host parties, usually alongside a Linux or BSD conference, where trusted members will look at your legal documents and then affirm on their website that you are who you say you are. Some amount of "you are who you say you are" was then needed to get a free SSL certificate.
But imagine that in this context: everyone keeps one secure CAcert account, and then when you need to reset your password, some sort of OAuth handshake with CAcert proves it. You have one secure account with CAcert, and all of your utilities and cell phone stuff and PayPal will only reset your password with a handshake with the CAcert servers.
However, even given such a pure, charitable utility, OAuth is still the best way to do this stuff, and that's really what I meant in my comment. Authing through a universal standard means you're not tied to ANY parties, and you can always offer the best of the bunch as an option. In fact, any such "utility" should enforce interoperability/standardization as a primary feature, lest it leave its users subject to economic/political volatility.
As for forcing customers to be on google/facebook/whatever, I see this as a sub-optimal practice insofar as it does NOT include such a pure utility, but not for any other reason. I don't have up to date data on the topic, but offering both Google and Facebook OAuth surely covers almost everyone, and even for the occasional user of neither it would still significantly reduce account proliferation and bad practices if everyone forced people to sign up for one of a few select accounts vs. the alternative of everyone rolling their own.
1. I don't have a Google or Facebook account. Does that mean I cannot buy electricity?
2. I have a Gmail account that I was invited to join in 2005. Google's only link to my identity is a Yahoo email account that was deleted in 2007. Is there sufficient trust to allow me to sign up for electricity?
I guess you need a process if they no longer own that number, but it's a start.
I remember there are banks give you biometric reader and only then you can log into your account. Cpatial One's mobile app allows you to use fingerprint to auth the app, great for convenient but we can probably make the app even more secure by demanding the same fingerprint used throughout. Of course, there have been some attacks on iPhone's fingerprint device, but first, you need to have access to that fingerprint, so most likely targeting at some big fish.
Biometrics is horrible for auth. [1]
[1] https://technet.microsoft.com/en-us/library/cc512578.aspx
Everything can be stolen. I am not sure if you can stop identity thief. Someone would have done so if it can be stopped. The goal is to make stealing harder. Combine fingerprint with other verification (see above too). My original comment was on the fact that once you sign in with fingerprint, you are good to with for a duration (Captial One logs you out automatically after ~2 minute of inactivity on my iPhone, which is wayyyyyy more secured than other bank apps I have used).
Point being biometrics is a bad idea to start with. CapitalOne doing this means they are failing to make the same distinction much like a 6 char password minimum etc. etc.
Unless this is a very rare thing at PayPal and internally they know it.
"We didn't build or train our call center, nor is it actually part of a single central system. We get contracts and then their support staff plugs into our backend and we hope the security constraints written on the contract are real and the training is adhered to."
I'm in the middle of requirement gathering for an unheard-of project: a custom, in-house support console for a new product I'm working on. We're even going to source someone to make training and testing materials, and do auditing independently of the call center (along with their auditing).
Sad part is, while I find it a bit intimidating because I've never undertaken a project like this before, it's not proven very difficult. It's just the miserable state of most enterprise IT and how very bolted-on customer support is to most operations.
Without knowledge based auth, what is PayPal supposed to say when someone calls them and says that they lost their phone and therefore access to their email and can't remember their password?
Right now, to social engineer someones account (Like Krebs's in this case, I've personally listened to the call he's talking about here) you need almost all the information that's on the account already (besides payment history, which could be a big deal to someone I guess).
A detail worth noting is that stealing someones PayPal account in this manner doesn't allow you to steal money from them.
Add a waiting period for affected customers, let's say a week or a month. During this period, try contacting the user on all known communication channels (email, SMS, push, robocalls; Coinbase does this quite well for Vault transactions) to inform them about the impending account change.
It's certainly not the easiest thing to get right, but it's not asking for too much from a high-profile target like PayPal.
Would be awesome if there was a site that documented these, even if it was as simple as plaintextoffenders.com.
Does having two-factor auth even matter if it can be circumvented with social engineering from static data?
I also submitted the same article last night:
I strongly recommend you do this. It's actually stronger than the branch security.
If only. If only.
Forward the customer to a security department trusted to handle CCs.
They mailed you a plastic card that had a map-like grid. I believe it was mailed using USPS Certified Mail that you validated online. Once validated, you were asked to provide the code for "Column A, Row 14", and then were prompted for a password. IIRC, you could also set it up so that you can login and view your balances with just a password, but would need to do step-up auth to buy/sell/transfer securities.
IMO a nice solution from a security POV. Certainly better than online brokers -- Charles Schwab "protects" my retirement savings with some bullshit 6 character password.
Customers HATED it, and the "I lost my card" process involved having another card mailed to you. So they replaced it with another solution that is IMO less secure.
Requiring the full number of a current credit card seems much more sane to me too.
Or maybe you're referring to a driver's license?
"Use two factor" isn't a valid response here. If you expect the electric utility to throughly vet every service request, why would you allow them to assume that the authorized user actually controlled his phone? (Especially when people tend to connect/disconnect utility services when they are buying/selling/renting a house and often doing things like changing phone numbers.)
Why does Brian Krebs have anything like this in his name? I would think that someone this high profile would have an anonymized LLC or similar legal structure to hold these accounts.
Things you can do about that vary. For example, in New York, if you're a victim of severe domestic abuse (stalker, etc), you can actually get a special address provided by the State, who will confidentially keep your real address and forward mail to you. Maybe a similar approach/service can be used in this case.
NIST defines the various trust levels that underlie identity solutions and offer increasing levels of validation from level 1 (no proofing, just validation that you are the same individual) to level 4 (in-person proofing with "hard" crypto authentication token). Two-factor auth without proofing doesn't really change the game -- that's why PayPal MFA is a joke for many use cases.
The problem with this stuff is that proofing requires a big uplift in cost & effort. If I were a service provider, in the absence of a mandate to serve Mr. Krebs or other high-risk targets like him, I would terminate my relationship with him.
What advanced type of stupid makes articles like this seem completely fine to individuals in the tech sector?
Your solution is to somehow perfectly protect all CC and SSN info?
How do you propose to do that?
This problem isn't unique to Krebs and it doesn't just affect people deliberately sticking their hands in fire.
Regular people have their CC and SSN posted online too.
Brian Krebs, as a high-profile author on security who actively antagonizes black-market groups on the internet, is a common target. He has had all of his basic personal information posted on the internet publicly for some time. The credit cards that were used for this attack were all old, disabled ones, since he disabled them after the numbers were leaked; but apparently PayPal still has them listed on the account and so you can use knowledge of them to "prove" your identity to PayPal.
Sounds to me like they're both at fault then. It's really nice and idealistic to have this mentality that you're doing it in the name of infosec, but it's a position held from an ivory tower.
If he's in software, what did he expect? This isn't a wise approach. This is the advanced stupid I'm talking about. Someone who thinks it's wise to antagonize, but then cries and writes an article over it when they're attacked. It's a joke. Conventional wisdom here is nonexistent.
To me, that's a far less complicated question than anything security related at a technical level. You can literally ask a child this question and they'll tell you it's not smart.
This is advanced stupid.
He's not just some internet troll, he's doing real good that you very well may have personally benefited from as a result.