However, I can't reproduce the issue described in the article.
However, I can't reproduce the issue described in the article.
The author says when you enter an email, an SMS is sent and number revealed.
What really happens is that it asks me for a password. Below that there's an option to get a one time code. Clicking that reveals the first digit of the area code, then the last 4 digits. You must then click yet again to make it actually send.
So in short, it didn't immediately send an SMS and never showed the full number.
Edit:
I just tried logging in. It's exactly as the author describes - I enter my email and get a "Log in with a one-time code" page with my partial phone number. The code is sent automatically. Must be A/B testing. (No password prompt is shown unless I click "Try another way" below the code field.)
> enter an email address to log into PayPal, an SMS is immediately sent and the phone number is partially revealed.
That said, below that it mentioned number guessing so I probably could have guessed that's what they'd meant to write.
>PayPal helps them by partially revealing a significant portion of your phone number
>Remember Mat Honan, who’s digital life was destroyed when his iCloud account was wiped in a targeted attack? In that attack, the hacker used social engineering to obtain a partial credit card number from an Amazon employee which Apple then accepted as verification of identity. With PayPal no such social engineering is required; instead revealing half your phone number to anyone who merely enters your email address on the login screen.
>Of course, PayPal also allows users to log in by entering their phone number. Now armed with a partial, a bad actor needs only to enumerate the remaining digits to reveal your full phone number.
[1] https://hacker-news.firebaseio.com/v0/item/32615770.json
[2] https://web.archive.org/web/20220827040709/https://christian...