PayPal and zero-dollar invoice spam
troyhunt.com
troyhunt.com
I actually got two of these messages while I was out for the holiday break. I don't work on the team that handles invoicing; but, I (among others) made them aware of this issue and they are definitely working on a fix.
The challenge, of course, is that there are plenty of legitimate reasons for sending $0 invoices and we don't want to artificially make our product worse for our many legitimate customers by going too far in trying to stop this spam.
Pretty sure they get a nice bump on their balance sheet for cash "in-transit" - and keeping the timeframe to 3-5 business days only magnifies that effect.
It's frustrating, and ideally not necessary, but it's essentially a safety net for the middle party.
So do not use Venmo for commercial transactions (buying things of Craiglist for example) and do not assume the money transfers immediately.
Also shame on Venmo for misleading their users; they should do a better job of explaining how the transfer actually works.
the longest I've had to wait from Paypal is 24 DAYS
If you're in the US and receive money via a "Friends and Family" transfer, it's just as 'instant' as Venmo.
Let's say you get 2 hrs of support per month free, after that it costs $100. If you don't use the full 2 hrs, you'd get a $0 invoice - but there may still be detail and record of work performed (which you would want)
For accounts which keep an average balance > $minimum you could wave the $10 hold and just confiscate $10 every time someone reported their $0 invoice as spam.
Another similar spam hack (that unless I'm mistaken is also legal) is the recent plague of Google Analytics referrer spam targeting people who pay attention to their GA referral reports.[1] It has actually caused some issues given that the volume can be quite significant and can easily skew your overall numbers by quite a bit if left unfiltered.
[1] https://moz.com/blog/how-to-stop-spam-bots-from-ruining-your...
> @troyhunt: It has my email address – I get email by sharing it with people who might want to send me email!
This is golden. Hilariously incompetent tech support trying to make someone delete the tweet complaining about their spam.
It is indeed very difficult to keep ALL your email addresses from being publicly listed, so I use GMail accounts for the ones plastered all over the web, and let GMail handle the spam.
It's similar to advice for "forgot password" forms not to acknowledge whether or not an email address or username actually exists--simply tell the user an email was sent for that account regardless.
Also, payment is way easier than it was before. Less bouncing back and forth.
It also allows a 1-click way to email anyone that "hasn't paid" with an update.
I'm not really surprised at how terrible the support via Twitter is. I almost never use chat/email support these days with any large company-because of how useless it has become.
There was a post here on hn over two years ago for the same issue which was top post and generated a lot of news.
https://news.ycombinator.com/item?id=6526481
It is obviously very well known to them for years but they continue to do it
Guy at PayPal sees post, tells a technical person about it, said person forgets about it. Suddenly PayPal doesn't know about it anymore.
Or a person wants to work on fixing this but a manager says no, because there are other priorities.
Or a person starts working on this, quits, and it gets lost among the things they were working on.
It's so easy for things to get lost in a company, even with all the bug trackers in the world.
I guess I have sympathy for the PayPal team in this case. They're working on an extremely large product, with a huge user-base. I would imagine it would be very easy for bugs like this to fall through the cracks even with a "process" in place
There isn't much you can do about it, detecting an abuse of an invoicing system and locally blocking it is much preferable to the other potential outcome of not knowing or being able to confirm where the hell did that invoice actually went.
https://www.paypal-community.com/t5/Access-and-security/Gett...
I haven't got more messages lately, so I'm guessing they managed it already.