PayPal Allows Bypassing Two-Factor Authentication with a Button Click
medium.com
medium.com
Seems like maybe a good idea for a class action lawsuit? I'm not sure what to do about that. A company shouldn't be able to do this and still meet compliance obligations.
I'll have to delete my account, unfortunately.
edit:
1. I didn't give Paypal my phone number so that they could use it for this. I gave it to them for banking purposes only. I wonder if this constitutes a GDPR violation?
2. I wonder if contacting their auditors would do anything.
3. Maybe email some of the politicians who care about this stuff - Ron Wyden, Elizabeth Warren?
Bit of a stretch...
> Personal data shall be: […] collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
1. a company or entity which processes personal data as part of the activities of one of its branches established in the EU, regardless of where the data is processed; or
2. a company established outside the EU and is offering goods/services (paid or for free) or is monitoring the behaviour of individuals in the EU.
After all a free lunch doesn't exist.
(This August it would refuse to let me finish logging in without setting up a phone number. I discovered that getting a friend to send me a paypal requst for $1 would get around that requirement.)
But then on the login screen they moronically offer a one click bypass of it, asking if you want to login by SMS instead. What's the fucking point of a Yubikey then!?
Similarly, Amazon does not offer a way to remove SMS from your account once it’s added, even after setting up another OTP method.
My wife and I had money stolen from our Wells Fargo checking account and I had a bunch of questions for them. Somebody from higher up eventually called me and when I got to the point about asking why the password was limited to 12 characters (they should be storing a hash and not the password) she told me to stop worrying about it because I'm not responsible for fraud.
> Amazon does not offer a way to remove SMS from your account once it’s added
Even if you no longer have that phone?
I'd start asking to be reimbursed for the time I have to waste on dealing with the fraud then.
I know all the historical reasons, etc. but this is still ridiculous to me. All the security in the world, and I still have to worry whether my brokerage funds are missing some each month.
You don’t need to clone it, you just change the SMSC registration to reroute delivery to the screen of your choice. If you have access, it’s trivially simple to do, but I believe it’s harder to buy your way into access these days because of some high profile news articles about the method in the past.
Also, I don't like the condescending tone of the article, implying that everyone at Paypal is a moron who has no idea what they're doing.
On iPhones by default the contents are only shown after your face is recognized by FaceID.
That being said, I don’t like to have one factor authentication tied to my phone number, especially not when I’ve enabled two factor authentication in the settings. I guess the logic behind this decision is that they see your password as the weakest link, so for them 2FA is not so much about having a second factor, but about not being able to use the password as the only factor.
But yeah basically they're gaining access to the entire bank a/c and doing thousands of damage instead of usual credit card stuff which is obv protected legally
So, at least for me, anyone who stole my phone for the purpose of hacking my paypal account would still need my fingerprint or unlock pattern. Someone with a non-smart phone will have a different experience though.
And yeah, sms is a poor choice from a technical pov but i can see why they did it for a mass-market service.
Wouldn't your phone be covered in your fingerprints?
Plenty of easy ways to pick up fingerprints from things like that. eg sticky tape + lead pencil, etc.
But yeah thanks PayPal
So... you don't hold your phone with your other fingers? ;)
AWS should offer the ability to enroll multiple second factor devices and to configure a policy for what subsets of them can log in. But they don’t even come close, and their actual capabilities are far worse than, say, Gmail or GitHub.
--
Since we recognize this device, you’ll continue to stay logged in, so you can skip typing your password during certain activities such as check out.
--
What?!
And there is no opt out, except for you to set a cookie saying you don't want that.
Hello?! How will I have a cookie for that at $random.place?
They literally care nothing about security.
Another annoying thing: switching back to English language every time (my OS and browser is English, they are using geoip instead)
for comparison, instagram at the time allowed 250 characters
Edit: Oh and everytime that happens I get a mail that there is a login with a new device from "dusseldorf nw de". No, I don't live in Düsseldorf, not even close. The fact that they misspell the name and that their GeoIP is reliably off doesn't inspire any more confidence.
Strangely though, when I logged in I wasn't prompted to use a one-time code.
I've seen mechanisms on some sites like my energy provider...but I doubt the crooks feel like paying my energy bills so whatever
Except PayPal does not monitor the only email address it lists on its own website, the one designated for the purpose of sending them data deletion or access requests:
https://twitter.com/ConsciousDigit/status/158782474176688947...
(Source: my nonprofit runs YourDigitalRights.org where we make it easy to send the likes of PayPal data deletion request under the GDPR / CCPA etc)
Very long time ago someone abused a referral program of a taxi service by registering multiple accounts just by random-guessing the code. They had badly written rate limiters so a list of 10k proxies, good broadband and a java threadpool were enough to get thousands of free rides in a couple of days.
I do HATE those who state a crappy Android/iOS OTP app is safer than an offline hardware token just because thanks to their app they also ask for permission for extra stuff like accessing phone location history, contacts etc all with plausible excuses (that's happen in most EU countries with banks crapplications) and so on.
ANYTHING tied to closed-source connected platforms can't be secure. That's is.
cannot reproduce bug
First, common attackers are opportunistic and they are unlikely to know your phone number. Even if they did, it would take skill and effort to clone your SIM. For this to happen you need to be targeted as an individual and that's a different scenario from random PayPal attacks.
Second, PayPal aren't stupid, and they have to be aware of SIM cloning. They also have data that we don't. Looking at their data and the probability of an attacker carrying out SIM cloning, they must have decided the cost of probable cases is acceptable if and when these attacks take place. Or that it's fairly rare to actually happen.
Besides, this option isn't available to all users, so there might be more going on than we realize.
I understand the author is upset that they can't set a single TFA channel to be used exclusively. But I think the real gripe here is that the author feels loss of control rather than a massive security issue.
I presume you have loads of verifiable data, to prove this?
Or is this a logical fallacy? EG, appeal to authority?
Corps of all sizes do very, very stupid things.
And just because an argument's a logical fallacy, that doesn't make it incorrect. https://existentialcomics.com/comic/9
An argument that uses fallacious reasoning is an incorrect argument, but pointing out a fallacy doesn't negate a conclusion (that would be the fallacy fallacy).
So, we can't tell if the conclusion is wrong when someone uses a fallacy.
I'm guessing your link laid it out clearly.
Take the conjunction fallacy. Ultimately, it comes down to the representativeness heuristic. However, the representativeness heuristic matches how we use language: to use Wikipedia's example, "Linda is a bank teller active in the feminist movement" is more correct than "Linda is a bank teller" if Linda is active in the feminist movement, but not a bank teller.
The mistake in such a situation is interpreting it as though the speaker is using classical logic, when they're actually using a fuzzy logic more akin to Bayesian inference. People focus too much on logical fallacies, and not enough on how the average human actually uses language. Precise language is useful, but that doesn't make "heuristic language" wrong, or fallacious.
An argument that's a logical fallacy can still be heuristically correct.
Many people might realise that cloning is an unaccounted for aspect of a 2FA, but the manager in charge, say, thinks cloning is not a realistic possibility and so doesn't allow it to be taken into account. Or, the manager does think it needs addressing but they get a bonus if the system is completed earlier and they know it will take longer to address the issue, so they argue it's not a realistic attack ...
So stealing a phone and knowing an email address could be enough. New iphones require face id by default, but there loads of cheaper android models that don’t. That is a low bar.
Apple and Google should agree on a standard code sms format and prevent such sensitive information getting displayed on the lock screen.
W3C tried: https://github.com/wicg/sms-one-time-codes
SMS 2FA from Apple actually implements that standard from what I can see.
As discussed very recently, many HNers would contest that assertion.
https://news.ycombinator.com/item ?id=33463535
I don't know if every user of PayPal would agree with this strategy, even though it makes PayPal the most money.
I can’t think of another universally available fallback method.
They've decided it's pretty much always better to close the barn doors after the cows leave.
Card fraud problems? Just promise people 'zero liability' rather than some sort of security paradigm stronger than "we told everyone they're not allowed to store the CVV."
Everything identity-theft related? Why bother actually engineering some sort of secure 21st-century authentication systems when you can just pay for a few months of credit monitoring after the inevitable data breach and class action suit.
I wonder if it would be possible to create a more proactive liability framework. Maybe stockholders would be a party with standing-- if you're still doing $known_stupid_thing years after alternatives have been documented, you're failing your fiduciary duty to investors, just waiting for an avoidable damage to the stock price to happen.