I'll never use PayPal again. No way in hell I'll trust a company with handling my money when they make it impossible to contact them.
I'll never use PayPal again. No way in hell I'll trust a company with handling my money when they make it impossible to contact them.
Just over a week ago, when I tried logging in to PayPal (2FA is not enabled) a new screen appeared saying they'd sent an SMS with code to my phone number, and I need to type it in.
Problem being, the phone number they displayed is not mine. I've never given them my mobile number, as they've always had a little blurb about that saying people have to also give them permission to receive marketing messages. Hell No.
So now I'm locked out of my account. With sufficient screwing around in their help system, there is a phone number you can call:
+44 203 901 7000
Trying to get through to a human being there however has proved an impossible task (after many attempts). From just being hung up on by their system, through to being told they're out of business hours (nope, double checked that), etc.Looks like in about 51 weeks, they'll start stealing the remaining balance until the account is empty.
Fucking scammers.
PayPal is the main reason I'm not positive on Elon Musk's history... they've been "known bad" for many years, including when he was there. He started his fortune from building a company that knowingly scams people. :(
There's plenty of possible things to criticize him for, but this seems like a weird one. PayPal was started by Confinity. He founded X.com in 99ish and they merged like a year after, but then he got the boot as CEO in a matter of, months? Weeks? Don't remember why, but while he still owned a ton of stock he was out in management. Then Ebay bought it all in like 2002. 20 years after his departure, itself before he had any real chance to make a mark, and 18 years after being bought, seems like a bit of a stretch to hold that of all things against him?
Edit: also man what a crazy time, I mean it was obviously crazy even at the moment but still thinking back on the timelines it's still wild.
You seem to imply PayPal being scummy is a new development. Always has been.
Might as well criticise Tim Bernes-Lee for not developing the HTTPS spec in the 80s
Re: PayPal, just knew he used to run it, and they've been scammy pretty much from the start. Thus the poor impression from that.
Also Re: PayPal: I used to know a guy that worked there from the very early days, and he told wild stories about employees freezing people's accounts and withdrawing the money for their own use. Apparently it was widespread, and pretty common.
It's kind of funny you say that too, as people have been saying that forever. eg "If they were so bad, stuff would have been done" (sic).
Look at PayPal's reputation going back a decade or two, and you'll see there are tremendous amounts of stories about it. People used to set up dedicated websites collecting the copious horror stories. Not kidding about that, in any way.
At the same time, there were multitudes of other people going "Oh, I've never had a problem with them, you must have done something wrong". (etc)
They've cleaned up their image _a bit_, so things don't seem as obviously bad now (latest development aside). Back then though... sheesh...
PS: I read somewhere that customers who swear on the line will be connected to agents quicker ;-) or generally receive better experience. Sigh. What a world.
Ironically, swearing at the bot memorably just ended up in an automatically dropped phone call pretty much right away.
Not sure if that was due to them just dropping the call anyway (guessing so), or there's detection for people swearing.
Is this a European or UK account? That's them implementing the PSD2 regulation [1], and they should have emailed you quite a few times about it.
But yes, PayPal customer support is hilariously bad.
[insert usual rant about their customer support] They've asked me to provide charity information for my personal account some months ago, and subsequently limited my receiving/sending privileges.
Phone calls to them trying to sort this out have always ended up at some call centre in the Philippines, where the agents can only tell their users that the account limitation is "for their safety".
That account of mine is still limited.
They've also limited the personal account of a friend of mine (who was interestingly enough ex-PayPal) before, also asking for charity information.
They did email me a few times saying they wanted my mobile number, but each time I went to the page it had the little text blurb about needing to accept marketing texts.
Again, not going to happen.
That being said, they shouldn't get to invent a phone number when one isn't provided. ;)
---
On a related note -> I remember trying to change the address in my PayPal account a few times after they emailed, as I moved from the UK back to Australia. (thanks to fucking Brexit for forcibly removing my EU citizenship, which I very much wanted to keep. Grrr :< )
Anyway, PayPal didn't allow changing account country through the UI, and there didn't seem to any other way of doing it either.
Not sure what people who move country are supposed to do... o_O
I believe the "proper" way is to close your old account, and reopen a new one from that country's site. Most people I know just have multiple accounts. I don't know if PayPal warns or shuts people down for doing so.
It makes sense legally, since a user would have to agree to a different set of terms in a different jurisdiction.
While it's true that different terms - or at least different provisions within a single terms document - might need to apply when someone travels or (especially) moves to another location, plenty of other companies implement various versions of this without needing an account to be closed and reopened.
So, not being able to change country in PayPal is pretty bad. It doesn't match up with the actual reality of how people live. :(
Peter Thiel the “libertarian” went on to found Palantir, for example, which helps governments do precrime and encourages mass surveillance of their citizens.
He also opined that “competition is for losers and you should build a monopoly” which as the first check in Facebook helped influence Mark Zuckerberg, and the results we see today. Back then Mark Z wanted to make peer to peer encrypted networks like Wirehog.
Peter thiel also wrote op eds saying stuff like giving women the vote ruined the USA by making it more social-democratic instead of capitalist.
Musk I think has long moved on from the PayPal days.
Same as the Google model then? ;)
On the other hand, you now have to give them your SSN #.
I think the one you're talking about is the previous system, whereas PayPal would be the transaction processor anyway. You'd still get email (receipt?) and other bits from PayPal after the transaction was done.
Now though, the CC processing on Ebay seems to be a non-PayPal version. At least, that's what it looked like today when getting stuff. No mention of PayPal anywhere, which I was pleased with having had a very bad experience with them (PayPal) a week ago.
From that day i haven't used any 2fa and just use password manager with additional backup.
this removes the "two factor" nature of two factor, but retains the one time password nature of one time password.
I honestly can't relate to people losing their access because something happened to their phone. The QR code is just a string of letters and numbers and you can save the QR code and the string of letters and numbers. I've been doing this for like a decade.
Up until about 18 months ago I used to live in a part of the UK without any mobile phone coverage. So, any mobile number I had (with Vodafone) always expired after 3 months.
That does not make for any kind of fondness of places trying to blindly force SMS based 2FA on everyone. ;)
To use OTP I had to break out of that flow and start from a different part of the site.
But to add to this, I wouldn't ever set up a 2FA on a service that doesn't allow multiple second factors, and mostly static backup codes. Having only one (ie. device) is a much higher risk, of being locked out, than having the password stolen.
When looking at the actual attack vectors though it is vastly improved:
Mitigated - Online attacks on your account at any service
Mitigated - In person attacks on your account due to post-it notes
Mitigated - Losing your phone which was the only way you could generate a one time password
All this drama is mitigated, turning a disaster into a 5 second recovery.
I have an encrypted backup of all my TOTP QRCodes and this has been tremendously useful.
I loathe sites that only do SMS 2FA, and I assume by default they just want my cell # for marketing or other privacy invasive purposes. Too many sites using SMS 2FA have poisoned the well.
Funny (and infuriating!) to be in the same situation. I have lost access to my account and the money in it, because they have the wrong phone number on file. In their support forum, there are pages of people with the same issue - they're locked out of their account, with seemingly no way to contact anyone at PayPal to resolve it.
I hope they get sued for this practice of abandoning their customers, cutting off contact, and keeping the money.
Not trying to make an excuse for all the horror stories, just some advice: Make sure you have backups/exports of the 2:nd factor keys so they can be imported when lost. For example print your password and store it on one location, for example in a safe, then print the 2nd factor key/export (QR code, or backup codes) and put it in another safe/location. Or make several copies and store on many safe locations. And don't forget to TEST YOUR BACKUPS on regular intervals to make sure they work when that day comes.