PayPal data breach notification
apps.web.maine.gov
apps.web.maine.gov
But anyone with properly secured accounts seems to not have been affected by this breach.
The last 2 years directly emailed all independent sellers to set up alternative payment options to not go through such a careless operation.
Amazon killed my parents business by just sheer incompetence and support took a year to get partially back to operation, by which time it was over.
Facebook incorrectly nuked my wife’s Instagram account and hopes of becoming an influencer. No recourse.
Google can ban your account with your email with no recourse. You lose your email history, contacts, documents, etc with no way to login to a myriad of online services.
I’m really low on patience with the big tech companies. I hope the government reins them in.
And I say this as European, I mean, we at least have some regulations...
Also, for money things like PayPal, they should only be able to hold your funds for a reasonable amount of time, then they have to transfer them to your bank account. They should not be allowed to just keep your money.
For sales of digital items, they should not be allowed to revoke your access to the items you have bought. Maybe they should just have to provide a basic file download for a certain amount of time.
Then you get into what is a 'critical' issue but I think being locked out of your account that is used as a gateway to multiple other accounts qualifies.
1. When a service is blocked or terminated, the terminating company must provide clear and specific reasons for the termination (they almost never do this now)
2. Additionally, there must be a human support channel to discuss the matter - even if it requires payment for the privilege of gaining support help (think 900 numbers of the past)
3. Human support and decision paths must be documented and followed such that a final decision can be understood within the context of the rules of the organization (thereby enabling possible efficient legal options for the consumer to further dispute the ruling)
4. As other people have noted, having access to export your data if you are being permanently blocked from the service
5. Having financial compensation (refunds) or post-service DRM access to content you have paid for
It’s fine if they want to arbitrarily flag something as fraud and refund money, but saying something is suspicious therefore we keep your money isn’t.
[1]: https://www.sueddeutsche.de/politik/facebook-bgh-urteil-1.53... (German)
Whose fault is it that people are relying on free email service (with no human support) for critical things like livelihood, bank balance, etc.? Is the provider of a free email service liable for the damages they can cause? What do their terms and conditions say about it? Do they have a disclaimer in there for this kind of things?
The social responsibility is still there.
You can't go around providing free drugs to people and then get upset when you get locked up over it.
I think the elected representatives have to represent the people, otherwise you don’t really have a democracy, right?
It's not an accurate or sufficient or desirable representation of reality to allow these various big companies to actively seek out having you entrust them with parts of various critical paths in your life, and then be able to nuke those with no protection or recourse on your part.
In 1975 when no one had an email address or a cell phone, and neither were required to do anything in life, it was fine to treat them like luxiries that if you lose them, so what?
That was still true but just a bit less so a few years later, and it's just been gradually becoming less so every year, and by now, it is simply not true at all.
It should essentially be illegal for a service provider to completely break some of these services without some sort of graceful shutdown or hand-off process, in the same way and for the same reasons it's illegal to shut off electricity and gas and phone in a lot of cases even after the subscriber has failed to pay. They get shut off eventually of course, but there are exceptions and ways for the subscriber to fight, and they are mandated by the government, not out of the goodness of the power companies hearts. Basically the power company isn't allowed to just let grandma freeze in the winter even if she fails to pay. It's not unfair to the power company. The investors in the power company are free to be in some other business if they don't like those terms.
Today, an email account should not be treated the same way as a spotify account, even if you're not even charging money for the service. If you don't like that, you don't have to offer an email service at all.
The requirement I imagine is some minimal level of continued function enough to complete other account management procedures, which means being able to both receive and send at least some emails. Maybe a limited amount, maybe limited attachment size etc, but enough to at least send the one or few emails from the previously recognized address to other parties as part of the proof of identity to direct them to a new address.
This even in cases where the account was terminated for supposed cause like illegal activity.
This means that one of the other things government can do is recognize that exception for liability. The government can determine not to penalize a service provider or allow others to sue them for having one of these accounts active at that limited level of functionality if the account sends someone a phising email or something.
Or maybe the procedure is the accounts do stop functioning so no email is passed, but, it can still be used by the owner to contact the service provider to invoke some kind of recourse procedure 9f they need it. So the spammer is blocked but mom can still jump through hoops and eventually regain access, including old mails and maybe even including unread received mails while it was down.
There are all kinds of things a government can do, and fully fairly and defensibly and officially, just by codifying some principles.
What do I expect from the government? Something. They can absolutely do something. It's work to work out exactly what and how and develop some consistent rational legal theory to base it on, but that it literally their job is to to exactly that.
Why not? You have no clue what she was doing and it's a totally viable source of income for plenty of people.
Seems plenty do given the number of influencers who have made it into basically a career. I in some way share your cynicism towards it, but there are plenty of jobs we don't "need" yet don't look down on in the same way. For all you know this guy's wife is spreading valuable information and genuinely helping people. Not all influencers are Andrew Tate and such. Hell my wife's cousin is big into legos and has a thriving instagram showing off their builds and talking about what goes in to them. Tons of hobbyists genuinely enjoy their insight. I don't see the harm.
If that value is actually improving people’s lives it’s another matter, but from an economics standpoint it seems to exist.
I'm all for people sharing their knowledge and hobbies to inform others but the term 'influencer' has a connotation in which they are earning money from 'influencing' others and that seems an awful lot like basic advertising to me.
And I'm all for them getting paid to do so. I'm not sure where you draw the line. Is a cocktail influencer sharing a cool hobby or pushing a product? The answer is usually "both." So where do they fit in for you?
Whether or not they monetize that via advertising or not it’s largely irrelevant to that value proposition.
https://www.paypal.com/us/cshelp/article/what-is-2-step-veri...
I hope they got rid of this feature now and went back to "traditional" 2FA requiring both a password and code.
What alternative names could we use?
Credential attack?
Credential reuse attack?
Secondary credential attack?
to stuff - to push something into a small space, often quickly or in a careless way
https://dictionary.cambridge.org/dictionary/english/stuff
As in "I am going to try these credentials quickly and carelessly and see if they get me in."
[0] https://security.stackexchange.com/questions/209266/what-are...
Kudos to Paypal here for considering it a breach, and reporting it as such.
The fact that you choose to use usernames and passwords to authenticate humans is your choice. It is well known that humans don't secure passwords well (reuse, writing on postit notes, etc). As a bank, any losses attributable to someone evil finding/guessing a password are your own.
That's why credential stuffing counts as a breach. Even though most banks will try to tell you that it's your responsibility to protect your passwords, the law doesn't see it that way.
Technically, Paypal is not regulated as a bank (per FDIC). That said, they certainly have immense fiduciary & privacy duty to their customers considering the format of their business.
PayPal has a banking license in Luxembourg which allows them to operate in Europe.
I guess it depends on the region/country.
https://cybernews.com/security/we-found-6-critical-paypal-vu...
Perhaps the goal is to render breach notifications useless by flooding them with nonsense like this?
It's a leading payment processor. They have lots of money and developers. The state of things is pity.
Oh wait…
Really PayPal? You mean this Equifax?
https://en.wikipedia.org/wiki/2017_Equifax_data_breach
The security breach problem altogether has been turned in to a source of extra profit for the credit reporting companies whose faulty systems, lack of data verification, and resulting poor data quality are the root cause of these issues in the first place.
The problem has never been "oh no someone stole your identity!". Identity can not be stolen, only temporarily misattributed in the eyes of one party or another.
The actual problem is that companies like banks and credit card issuers don't actually know who they are dealing with and don't want to put any effort in to verifying that. Using just a few pieces of already available, static information about a customer was never enough to say you actually know who your company is signing a contract with.
Calling it "identity theft" when someone feeds your faulty signup process incorrect information is merely a means of passing the problem with your systems off to the customer. Now we're going as far as pretending the root cause of this stupidity can also sell us the cure? Nonsense.
If anyone ever "steals my identity", I'm going to sue the credit reporters for libel. They have admitted before that some 70% of their records contain inaccurate information and they know full well that a few bits of static information is not enough the identify an individual among hundreds of millions. They also know they don't do anything to establish that any new reports coming in from partner businesses are actually real and accurate. Yet they still peddle that inaccurate information to third parties. That is the same as if a journalist made up a story saying you did some shit you didn't do. They are knowingly giving out information about a person that is either provably false or which they have no good reason to believe is true in a way that can cause financial harm and loss of reputation. Classic libel.
Further, if some business reported that I took a loan from them when I didn't, that isn't my problem, it's theirs. They failed to adequately verify who they were dealing with. Not my problem. Reporting that inaccuracy to a third party who then broadcasts that to a bunch of other companies, is also libel.
They can make a case that they didn't know for sure that their claim that I owe them was false at the time, but they actually never had a good reason to believe it was true. Static information alone, especially that which we already know is in circulation among public entities, is not a valid way of identifying who you are dealing with. Pretending that it is anyway is just bad business.
People need to hold these businesses accountable for the damage their faulty system designs are causing.
Two years seems like the minimum they feel they can get away with. They just need to make it seem like they've done "something" to compensate their victims out of fear that if they didn't some regulation will come along that requires that they actually make up for the harm their negligence has caused in an actually meaningful (and more costly) way.
Paypal's 2FA is a bit of a joke. IIRC (this was quite some time ago) when I went to initially setup 2FA SMS was the only option, eventually they added support for authenticators but you can just click get a text instead of the authenticator. Last time I checked there was no way to tell paypal to only accept OTPs from an authenticator.
Gotta hand it to Equifax, they know how to sell nothing for something.
"Only" 35k affected so must be some narrow scope. The linked page doesn't seem to provide more details.