PayPal Starts Banning VPN and SmartDNS Services
torrentfreak.com
torrentfreak.com
Its a common tactic for carders to throw $1 at something to test cards before they try to use them for something more expensive.
There are untold thousands of ways to beat whatever systems get put in place to stop them.
https://developer.paypal.com/docs/classic/fmf/integration-gu...
PayPal is a payment gateway... In the case you mean payment processor... Stripe's antifraud is pathetic at best (sorry, love you guys). BrainTree isn't any better. Authorize.net is bottom-barrel. "Let's add MaxMind!" not helping, it's trivial to circumvent.
Nothing can defeat a human, and nobody can be 100% about detecting a fraudulent transaction. The things that kill you are the things that a payment gateway doesn't look at.
My history is littered with circumventing the rules, bending them and breaking them. I'm a "student of the game" if you will (well, not anymore, I now help prevent and detect), and there are things that I've developed/learned/executed/manipulated into getting a transaction through that was so stupid simple that I laughed when I saw the words "order confirmation."
Please, please don't trust your payment processor or gateway to be enough to prevent fraudulent transactions. They're good for the 90% of carders who are idiots. The remaining 9% are the ones that will hurt you, and that last 1% are the ones that will kill your business.
It’s the same with PayPal, really. They’re prioritizing the people buying stuff over the people selling stuff.
It seems like buyers prefer protection a lot more than sellers do. Or maybe sellers just don't have any power to decide, and have to go where the buyers are.
It's a consequence of the regulations on credit cards. The cardholder can reverse allegedly-fraudulent transactions. Paypal can't reasonably do something else while processing credit cards, so they don't.
It's quite stupid because you end up with customers who aren't even looking for credit, they're willing to prepay and are willing to trust the seller, they just want to transfer funds digitally. But they can't because the seller/card processor doesn't trust the buyer not to reverse the transaction and the regulations don't allow the buyer to abandon that right up front.
The main difference between debit and credit is that if you're the victim of fraud with a debit card, money has been taken from your bank account and you have to fight to get it back. The fight is usually not very hard, but it takes some time. If it hits at the wrong moment you may have trouble buying food or paying rent on time, even though you'll get the money back before too long.
My first account is still in zombie state because it can't be closed without sending them scans of some papers I couldn't care less about sending (and didn't have them abroad). There was no money there so I simply opened another one, but still an annoyance.
The "problematic behaviour" you describe is invariably related to the fraud prevention mechanisms required to offer their service. That's the deal - Paypal are incredibly liberal in opening accounts, but they reserve the right to freeze an account pending investigation if something looks sketchy.
Paypal still fills a very useful role. I've used their services to receive payments for over a decade without incident.
Stripe only launched in Canada late 2012: https://stripe.com/blog/stripe-in-canada So did braintree: https://www.braintreepayments.com/blog/braintree-in-europe-a...
And we're america's hat. Many countries are still bereft of options.
(disclosure: I'm now a stripe employee, opinions are my own)
paypal is only relevant because they invented the uber-way. They ignore all legislation. push away. and nobody makes them accountable for anything.
they are pretty much a bank for free
They're more regulated than all but a handful of international banks, and it's not at all free.
PayPal is a licensed money transmitter in all 50 states, the District of Columbia, the US Virgin Islands and Puerto Rico. Most of those states have bond requirements for MTAs, typically six figure deposits. They're subject to 52 different regulatory agencies in the US, in addition to Regulation E consumer protections and the USA Patriot Act federally. Their US<->international transfers are overseen by the U.S. Department of the Treasury’s Office of Foreign Assets Control like any bank. They're not an ordinary bank in the US only because many years ago a judge ruled that they don't qualify to be one by the nature of their business; they tried unsuccessfully to be licensed as one in order to get FDIC insurance on deposits.
They are a licensed bank in all of the EU, with a bank charter in Luxembourg, regulated by the Commission de Surveillance du Secteur Financier. In Australia, they're licensed by the Australian Securities and Investments Commission as a financial product and by the Australian Prudential Regulation Authority as a purchased payment facility provider, which is a type of authorized depository institution (i.e. bank). In most of southeast Asia, they operate under their subsidiary PayPal Pte. Ltd. which is a licensed stored value facility regulated by the Monetary Authority of Singapore. They operate in 203 markets in total, most of which have separate financial regulations and regulatory bodies PayPal has to comply with.
go see how many other licenses and laws you have to comply to open a proper bank with a branch in any of those states.
I'd never use or recommend paypal for any business. Their history of seizing funds, freezing accounts, and pulling money from bank accounts is atrocious.
I am not sure who to blame: the PayPal management or the viscios copyright regime, where a company with the legal resources of PayPal is still afraid.
In reality their processes for investigating are often a neverending nightmare that punish innocent people, or in this case are hampering one of our only hopes for reasonably secure mobile communications: http://neo900.org/news/paypal-trouble-delays-project
Their invoicing system is ridiculously simple, nearly everyone I'm working with keeps cash in there or connected to it (or very worst, a credit card attached), it hooks up easily with FreshBooks, contractors like it since PayPal handles the 1099-K themselves, and it just works.
I see no reason to change. I just don't keep an absurd amount of money in the account and I feel safe using it.
You obviously have never used Bitcoin.
One of the big problems with using bitcoin for something like this is you're not just sending money. Your converting to a different currency, sending money, and converting it back. It would be akin to me wanting to send money to my Dad by converting it to Euro first, sending it, and him converting it back to USD. Neither of us have any interest or use for money in Euro or bitcoin. We both have/need USD.
You also get the volatility of bitcoin. If I send $10 to my Dad in bitcoin, it might be $9 by the time he gets around to converting it to USD. Or $11. Bitcoin could plunge in value (for seemingly no reason that I can tell) and be worth $5. I have no way of knowing what the value of that will be for him when he gets it.
If I want to send my Dad $10 on PayPal, he gets $10. He gets it instantly in his PayPal account as $10. If he transfers it immediately to his bank, it'll be $10. If he transfers it next week, it'll still be $10. It's guaranteed in value.
Also, I don't know if this is still the case but dealing with bitcoin is a pain. If I want to buy bitcoin at Coinbase and I don't have a credit card linked to my account (until recently, you couldn't even use Mastercard), I have to wait a few days for my BTC to arrive, even though they are directly linked to my checking account. I have no idea what the value of my BTC will be when it finally arrives a few days later. I have to send it to my Dad, he has to sell it back to USD (at least at Coinbase, at a lesser rate than buying it). The value could change dramatically at any of those steps.
And if you want to add a card at Coinbase, yeah, that's fun. When I added my card, my bank immediately kicked the attempted authorization out for fraud reasons. 10 minutes later my bank called me about it and I approved it, but the Coinbase told me I couldn't try again for a week. So I had to wait another week before trying to add my Mastercard again.
Bitcoin has a lot of usability issues for non-tech people. And using it for a simple USD->USD money transfer is like using a jackhammer when you need a scalpel.
> If I send $10 to my Dad in bitcoin
Have you tried to use BTC to do business with Amish? Or any other made-up situations where you force BTC on people who don't know how it works or have no business using it?
But that's primarily what I use PayPal for: sending money to family and friends. Paying for my share of dinner, or concert tickets in a group buy, that kind of thing. I will occasionally buy things using PayPal (usually eBay stuff), but mostly, it's simply a money transfer mechanism.
For that, PayPal is perfect and BTC is overkill. Parent said "You obviously have never used Bitcoin." I have. For this, it's a pain whereas PayPal is flawless ever time.
> Conversion USD->BTC and BTC->USD is hard simply because banking system is trying to make it hard.
But is it really that much harder than any other currency exchange? Off the top of my head, I don't even know how I would buy, sell or change Euro to USD without physically going to the bank.
> Have you tried to use BTC to do business with Amish? Or any other made-up situations where you force BTC on people who don't know how it works or have no business using it?
See, it's this type of attitude that makes people groan when talking to bitcoin advocates. You're calling a situation that I have personally encountered and provided a detailed accounting of to back up my assertion "made-up" and comparing me and my family to Amish?
Come down off your high horse, dude.
You've exposed your father to losses without explaining to him that BTC is in fact not USD and USD/BTC is a floating exchange rate. I don't see how this is problem of BTC and not your own personal screw up.
You are assuming that both of us were not aware of that. We both were and were interested in trying something new. But it is still a reality of using Bitcoin when the entire transaction is not in bitcoin.
Anyway, the larger point remains: there are some transaction that bitcoin is ill suited for and PayPal is great for. Sending money to people is one of the core features of PayPal that works like a breeze whereas buying and selling a different currency just to send money makes little sense.
Once again - if you are using other currency, being it BTC, CHF, EUR, RUB or CNY, you are exposing yourself and counterparty to exchange rate fluctuations. Difference is - with BTC you have some extra possibilities.
As for PayPal - yeah, it's a breeze until it's not. I.e. until they've blocked your account because reasons. With BTC I own my money. With PayPal, PayPal owns me.
No need if you earn and spend it.
> You also get the volatility of bitcoin
Absolutely true in the short term, absolutely false in the long run. Bitcoin's volatility has statistically declined as its usage has increased.
> using it for a simple USD->USD money transfer is like using a jackhammer when you need a scalpel
Cannot argue there. The key is to stop using USD whenever possible.
Bitcoin isn't easier, at least not ATM.
Then again:
> sending legitimate money from point A to point B could not possibly be any easier than with this service
- is this patently false as long as I have issues sending monies to Pakistan using PayPal.
The businesses I deal with enjoy US dollars and simple tax situations. Not the opposite.
(At least, that was how I read it).
As a consumer client, the only problem I've had from Paypal is the difficulty of changing my name.
BUT, I've heard many, MANY vendors complain - funds frozen, paperwork problems, poor communication.
They are solving a hard problem, but I have to agree: after so long, it's a shame there isn't more competition in the area.
Hasn't been a problem for me, but I'm not doing e-commerce,which seems to cause the most trouble.
What alternatives could you offer? I really don't feel like entering my Visa details in some random website and Bitcoin is still a mess to acquire and use. Yes, PayPal has it's cons, but unless some other service arise that could offer comparable convenience (fast email & password checkout) and safety (no need to enter personal or financial information) I don't see how it can become irrelevant.
I can somewhat understand the bank's motivation, but offering two-factor authentication would be a much better way of boosting security than blocking VPN traffic.
As for Netflix, it's totally short-sighted. Netflix is literally unusable from my home connection without a VPN (thanks, Time Warner!). Now that they seem to be consistently blocking my ability to use the service, I'm planning on canceling.
So you can easily find some no-name VPS provider or get a VPS on AWS/DigitalOcean/Azure/Racksapce but if the site is actively restricting access from VPN's/Proxies it won't help you much in most cases.
There might be options related to IPv6, but since Netflix has been supporting that for streaming since 2012 I suspect those are also covered.
https://medium.com/@ValdikSS/detecting-vpn-and-its-configura...
And MTU differs extremly between US and Europe (Thanks to PPPoE and PPPoA)
PTR is wrong. My Server is a home user and I'm a server?! Also this guy has a better database since he can detect linux 3.11 however on my home network I'm behind a proxy, thats something he didn't detected.
Edit: Oh and on IPv6 only networks with DNS64 and NAT64 you will get really aweful results if you operate on a ipv4 based service (i'm looking at you netflix)
That is what I don't get, because if I spin up a digital ocean server in London and put openVPN on it, they can probably tell the IP block belongs to a cloud services company. However, they can't just be running ips against a list right? So what is the work around?
In some cases it is more ambiguous, say the IP belongs to Verizon but it happens to one of the blocks Verizon provisions in the EU or as part of their PPI infrastructure. You only know this because someone has annotated this metadata (eg MaxMind). Or if its a Comcast Business account IP, do you call that commercial and block it? It could be someone at home who forked out for the business class service. This is again where IP-surveillance companies come into play.
In even more ambiguous cases, the IP belongs to AS####A (A hosting company) but is announced by AS####B (A residential ISP), such that traffic from to or from the IPs belonging to AS####A looks for all the world that it is really AS####B's traffic. Do you treat those users a residential because ISP-B is potentially renting that IP space or do you call it commercial?
[1] https://en.wikipedia.org/wiki/Autonomous_system_%28Internet%...
There is still plenty of implicit throttling going on though, with broadband providers refusing to provision enough capacity between their networks and the content source networks. The existing links then become congested at peak times and performance is degraded for the customers trying to access that content.
VPNs may improve performance in this situation not because they are hiding or disguising the content, but simply because the traffic is "re-routed" around the congested links. Assuming that the links from content network -> VPN host and VPN host -> end user are not also congested.
They refuse to add an adequate amount of peering to video services like Netflix and YouTube. The result is oversaturated routing during peak hours.
By using a VPN you change the route taken to the video service, bypassing the oversaturated connections.
Concerning the Time Warner issue - I can't say that I ever noticed being the victim of traffic shaping and throttling in similar fashion, but that's just outrageous; How can that be legal?
I don't watch Netflix, but I often have extremely poor speeds for YouTube videos at peak times on my FiOS connection. Of course Verizon says it's Google's fault for not paying for infrastructure upgrades, clearly not Verizon's responsibility to ensure I can actually get the 300Mbps they advertise.
My nearest exchange point is probably London Internet Exchange. If an ISP advertises X Mbps, and Netflix can deliver X Mbps of data for me to the exchange point, it's my ISP's job to get that X Mbps of data to me.
And really, I'd be happy with a mere 10Mbps to YouTube, if for some reason full speed is too hard.
All of these types of media deals stipulate that the licensee has to implement appropriate technologies (often spelled out on the contract) that support the licensing restrictions of the content (usually something like "commercially reasonable efforts" which gives Netflix some wiggle room over what measure are "reasonable")
Actually after Peter Thiel left PayPal, he founded Palantir, which is strongly inspired by their fraud tech. Just more general.
Sure - in an ideal world the law enforcement would just catch all the bad guys and manage to get the money back. But when that doesn't happen a business has to account for it.
IMO, the resources aren't there...and it's not complicated...
Cyber crime, fraud, identity theft...the manpower is simply not there to keep up with it all...sometimes you're lucky if someone has the time to complete a ticket, or report...
It's very possible conditions could get much, much worse before/if they improve...
IMHO, at a business level all sorts of decisions are being made that aren't going to be popular with the public...
https://www.expressvpn.com/blog/expressvpn-now-accepts-bitco...
https://www.astrill.com/pricing.php
Etc.
EDIT: Downvote all you want for disagreeing... but this (fraud and risk mitigation) is exactly why PayPal "won" the P2P payments space.
This is a stupid move by PayPal.
I have an issue with companies punishing other companies because their customers might be doing something that they don't agree with.
https://www.braintreepayments.com/legal/acceptable-use-polic...
Restricted activities include some obvious sketchy areas (check cashing) and some less obvious sketchy areas (human hair, fake hair or hair-extensions).
When it comes to financial situations, it's all about risk. It's completely within their right to mitigate that risk based on the profiles of the industries they deal with and this is what keeps them in business.
this is not true.
But instead, their reason is that these products bypass copyright protections. No mention of fraud or anything related to the actual transactions they're processing, they just don't like the products.
Which, fine, PayPal can choose to support or not support whatever products they like, but I'm not going to applaud them for playing copyright police with products which have, as the Supreme Court would say, "significant noninfringing uses."
I'm guessing PayPal isn't blocking all VPN services, just those which are insufficiently subtle about their ability to use them to bypass Netflix's location restrictions. Maybe UnoTelly should rename to UnoDefinitelyNotForWatchingNetflix.
Maybe PayPal is getting flak from rights holders (even Netflix), which makes VPN traffic too risky right now. Maybe they're really dogmatic about the issue ("we hate VPNs and copyright pirates!") or maybe they really just don't want to get caught in the middle of a political battle that they don't care about.
EDIT: Instead of making a snarky, low-information comment, I suggest you actually refute what I said. That's considered good HN etiquette.
It's not risk. There may be / are reasons, but painting them as "high risk transactions" is entirely disingenuous.
People are criticizing you because it looks like you wrote your first post without understanding the issue and now try to defend it by altering its meaning through redefinition of common terms.
I would argue that Paypal being the default payment method for eBay transactions might have been a more significant factor in their success.
Also... the scale wasn't as small as you think. According to the numbers [1], PayPal was doing >$2B in transactions at the time of acquisition. For perspective, estimates from 2014 [2] put Stripe at $1.5B in transactions (and a company valuation of $1.75B). Paypal wasn't small, even in 2002.
[1] http://www.fraudpractice.com/paypal_companyprofile.html
[2] https://pando.com/2014/01/24/memo-to-stripe-winning-the-hear...
They definitely do some dumb stuff but they also process five billion transactions per year and people need to take that into consideration. The scale of the fraud and the scope of worldwide regulations they deal with is way beyond anything you can imagine.
How are these risky? Or rather "more risky" than the average online transaction.
The number of chargebacks or fradulent transactions reported on your merchant account usually raises red flags and calls for account review. I am sure its pretty easy for paypal to identify such accounts with the data they have.
The most basic anti-fraud check is comparing card issuing country against the IP location. If there's a mismatch, it's a first red flag. If you see someone popping up from a VPN or a Tor exit, it's largely the same thing.
The question is about purchasing VPNs not using them.
Maybe a few VPN providers are fraudulent, but the major ones aren't. You pay them, you get a VPN. You pay for SmartDNS, you get that service. It's what people do once they have those services that's considered bad by copyright holders, and so they're applying pressure to payment services like Paypal, to get them to stop processing payments for those services.
If you look into the campaigns copyright holders are waging, the major one is an attack at funding sources for all kinds of services: file hosting, VPNs, etc. They are attacking those services and their funding, because trying to go after people who use those services—for things copyright holders don't like—has proven largely futile.
Again, what this article is NOT about: If you try to pay for things offered on a completely legitimate website and you pay with a completely legitimate credit card, but you're browsing using a VPN, it's likely to get declined. Risk of payment fraud or goods purchased using compromised accounts—via VPN which makes fraud harder to trace—is an issue but it's separate from what the article is talking about, and it's distinct from what people in this thread are complaining about regarding the article. While some people might legitimately complain about bans on payment for services over a VPN (it makes it difficult, if you don't trust your ISP or wifi service, to go VPN-only if you can't buy most things), it's fairly clear that such payment-provider or retailer behavior is motivated at combating fraud.
The issue here is entirely about copyright holders being mad and threatening the payment processors of service providers, because service providers are doing things copyright holders don't like, not because the service providers have unacceptable payment-collection risk profiles.
I suspect (without supporting evidence) that PayPal is only doing this in response to external pressure (eg. from Netflix, RIAA, MPAA) rather than making the decision unilaterally. I think it's unfortunate that PayPal has caved. But from a business perspective, I can understand why they've decided to cave: The transaction volume is small relative to the cost of fighting the rights holders (in legal costs, but potentially even in the political arena). Like all other banks dealing with cutting-edge issues (eg. weed legalization), they're being cautious; they have a lot to lose.
I imagine it's a bit like hosting, where an astounding number of signups are fraudulent.
It's not great that PayPal don't say that directly. Either explanation definitely adds up though.
I can understand a website blocking users from other locations or VPN users but for PayPal to do it seems unnecessary and a way to hurt genuine users.
UNLESS they're advertised as tools for piracy/circumventing the law.
The services that got banned here were being too cheeky. They weren't advertising a VPN, they were advertising the facilitation of lawbreaking behavior.
As a business, relying on such companies is one of the biggest risks you take. Use Paypal? Risk losing access to your funds. Use Amazon? Risk losing access to your computing resources, shopping platform, etc. You have no recourse if you anger the big gods of the Internet. Best not to depend on them at all or the smaller gods that also depend on them. Paypal's not taking payment from VPNs? Use Bitcoin and cancel that Netflix account. Why pay ten bucks a month to Netflix so they can pressure Paypal into shutting down legitimate businesses when you can pay it to a legitimate business (VPN) and watch whatever you want? Sure, torrenting is probably illegal, but one method shuts down small businesses and is immoral while the other one hurts no one ("losses" from piracy are not real). You may not agree with this conclusion, but there is no doubt that this is the direction of thought companies like Paypal, Netflix, and Amazon are steering their consumers in--on purpose.
[1] They have other payment options, too, but all are worse than PayPal.
From http://www.zdnet.com/article/tpp-ip-chapter-leak-reveals-us-...
"Another clause proposed by Australia, the US, Singapore, Peru and Mexico would also seek to prohibit circumvention of "technological measures" put in place by copyright holders over their works. The definition is broad and there are a number of exceptions still up for debate, but it could be seen to include the use of virtual private networks to access geoblocked content such as Netflix from outside the US. This comes despite the Australian negotiators seeking to raise the issue of geoblocking as a concern for Australian consumers as part of the negotiations."
US/AU: For purposes of greater certainty, no Party is required to impose liability under Articles 9 and 10 for actions taken by that Party or a third party acting with the authorization or consent of that Party. Negotiator's Note: CA seeks clarification of this footnote.
Yes, implementing TPP would require that anyone who circumvents a TPM be liable to civil and criminal penalties. Yes, getting access to Netflix content that you are not authorized to get access to, by using a proxy or VPN or any other tool, would be circumventing and would expose you to those civil and criminal penalties.
Nothing in this Agreement prevents a Party from determining whether and under what conditions the exhaustion of intellectual property rights applies under its legal system [13].
Article QQ.G.10 has the following for Australians:
US/AU: For purposes of greater certainty, no Party is required to impose liability under Articles 9 and 10 for actions taken by that Party or a third party acting with the authorization or consent of that Party. Negotiator's Note: CA seeks clarification of this footnote.
---
Basically, most Australians have watched whilst they were considered second class citizens and price gouged by U.S. corporations who don't pay any tax in Australia, and in a rare moment of insight our government forced this through.
PayPal dropped support for a Canadian VPN provider. Will PayPal continue to support Australian VPN providers, since AU gov permits geoblocking, even against Netflix ToS and the wishes of content rightsholders?
So Australia can break TPMs itself, and Australia can wiggle a few days here or there in determining just how long copyright protection lasts. So what?
HTH.
Its not a court of law, its terms of service. They can terminate your account without any recourse. That's how business work (unless you can prove they're discriminating against you based on a protected class).
While I don't how they can prove that the traffic primarily through those VPNs were infringing on copyrighted material, it is easier to prove that traffic through a VPN is attacking Paypal accounts for user or transaction fraud.
General complaints about PayPal are landing all over this thread, and Dwolla answers many quite nicely; you're welcome.
As for the article, I would say: a pox on both houses. I endorse neither EULA violators nor PayPal as an Internet police force doing online civil forfeiture.
The way to handle Netflix/PayPal is by international treaty regulation for nondiscrimination and uniform product quality. Netflix/PayPal is likely in violation.
Overseas users are in luck: treaty actions will only work OUTSIDE the USA. Kickstart a trade lawsuit. Any lawyer will work on contingency against deep pockets. Kickstarter only need fund initial research.
Pretty annoying that they don't inform users of this guaranteed failure prior to attempting, but whatever, i already learned not to use PayPal unless required.
And fuck Netflix.
And fuck Craigslist.
Anyone who is against privacy needs to just crawl back to the 90s and die.