Will be removing my bank account from it right now.
I refuse to use SMS as a second factor, so using it as the _only_ factor for what is effectively a bank account is absolutely batshit insane. They’ve completely lost their mind.
https://www.paypal-community.com/t5/Managing-Account/How-do-...
I cannot log in without a phone any more to paypal. At all. My mobile phone doesn't even work on my property, I live in a rural area, with no cell phone service for 1km.
I have a phone. Email. I could set up 2fa via the internet.
Nope.
Because of course, cell phones are always reachable?!
I use TOTP with my account just fine?
Of course it doesn't change the fact that using SMS for security should be illegal.
I don't get what you're supposed to do when travelling? Incur international texting charges?
At _minimum_ I need to swap the physical SIM card in my phone which for some reason breaks iMessage for a few days every time I do it. However roaming doesn't work in every country, so, sometimes I'm just fucked.
eSIM could make the first problem easier, but it actually makes it harder. With a physical SIM, if I lose or break my phone I still have my home SIM so I can still access SMS on a new phone. With eSIM, if I lose or break my phone my home SIM is lost along with it. No problem, just provision a new eSIM, that's the whole point right? Well, one of my telcos doesn't support eSIM yet, but they enforce SMS MFA, so I can see where this is going. I'll only be able to provision a new sim if I have access to the old one. Absolutely braindead. Another of my telcos doesn't allow eSIMs to be provisioned digitally; you need to obtain a physical QR code from a shop or have it posted to an address within the country (they won't send one overseas). It's actually unbelievable how telcos have managed to make eSIMs less convenient than physical SIMs. Anyway, this means I need to return to my home country if I lose or break my phone because without SMS I won't be able to access banking.
This is beyond infuriating, but I'm an edge case so no one cares. It should be illegal for critical services, banking/finance/govt etc to depend on SMS.
(No affiliation; I'm just a happy customer.)
I was able to get my hands on one of their cards, but it was useless to me as I couldn't actually put any money on it from my unsupported country.
Why?
> And there appears to be a lot less protection for you as their customer.
They have EU banking licenses (depending on where you are a different one applies to you), but they are a regular bank with all the protections that includes for a customer - if they go bankrupt, your money is guaranteed up to a certain extent; they can't just close your account and keep the money like PayPal do, etc. etc..
What do you mean? They provide banking services, they cannot do that without a banking license to do it under. They used to only have one, in Lithuania, and use it for all operations, but now they have a bunch more and the most appropriate applies (e.g. I'm in France, and I'm under the French one).
When I duckduck the question, even revolut has this in their FAQ: https://megous.com/dl/tmp/bbebf0d88acb54d8.png
It's possible to have a license and not use it.
- Basically none of the banking functions were available outside the app
- The app itself was buggy. There was some sort of "vault" or whatever they called it that had attractive interest rates (the reason I signed up), and after wasting hours of my life over a few weeks with customer support I decided it would never work
- Unlike any other bank-like service I've used, you can't just get mailed a check and close the account. Neat idea maybe, but at the time the app was buggy and wouldn't let you withdraw fully if you had anything in savings because of some sort of minimum balance nonsense
- You can't use the app if they think your phone isn't sufficiently secure. This is more on Apple/Google for caving to that bullshit, but IMO an app with its own security model shouldn't have any clue how you access your phone
- Deposits were capped to like $10 for the first day, $100 for the second, and so on. I don't remember the exact schedule, but it meant that instead of just depositing an old 401k I had to design over a period of time a series of increasingly large deposits of some other money (just like a fraudster would do? ELI5, what are they actually preventing?) just to be able to throw a check into the account
- Deposits to and withdrawals from Revolut took an obscene number of days, nobody on either side of the transaction could tell where the money was (magically available in neither account), and the transactions were 10x longer when I was trying to leave
And on and on. Like, I'm sure they're fine on average, and they're probably better than when I tried last time, but I haven't had a worse banking experience yet anywhere by a longshot. The basics for an online bank are logging in, depositing money, and withdrawing money, and neither the basics nor the fancy features they sold me on were very functional.
Happy to hear the virtual debit cards work for you :)
As a secondary concern, the bank has occasional 2fa, and definitely does some kind of anomaly detection. Primed by the ickiness of the user/pass request I just had a mental image of some hacky Selenium script on an AWS IP address filling out the login form and getting my online banking disabled proactively.
The bank is not in the business of allowing overdrafts and then somehow collecting the difference.
> The bank is not in the business of allowing overdrafts
> and then somehow collecting the difference.
But one's main bank is? I don't see how the intermediary is any different in that regard?Having a separate account with enough for the current Paypal transaction (that you refill from the main bank account as needed, in a few mouse clicks) means you limit your losses from a transaction gone wrong with a major company.
Can a malicious player try pulling money from your main account? Absolutely. But the chances of a large company, like Paypal, hitting you like this on an account not registered with them is zero. And your bank's fraud protection should stop an attempt to pull a large sum from your account by an unknown company in a sketchy country.
This doesn't stop PayPal from reversing a previous inbound transfer they decide shouldn't have happened, but it ought to stop PayPal unilaterally deciding they would like some of your money.
[1] https://www.forbes.com/sites/halahtouryalai/2013/06/11/yes-b...
There are a lot of checks on top of that which individual banks may or may not implement or care about, but at the end of the day those two numbers get you 99% of the way there. And for an organization the size of PayPal they're really going to be given the benefit of the doubt by banks.
Also not sure why that's not more common in comparison to credit card fraud.
Edit: I guess credit card fraud can be easier to cash out (for physical goods or services), while ACH fraud requires mules to act as intermediaries to receive the fraudulent deposits, which might be harder to come by and sustain.
There's millions of retailers that accept credit info in exchange for goods and services.
You can't use ACH to buy Wal-Mart gift cards.
The US banking system can be summarized as "withdraw first, ask questions later." The whole system is based around auditing after the fact. If at the end of the day (or week, or month), the numbers don't balance out, a flag is raised, and someone investigates it. And in many cases, there is a waiting period before you can access funds transferred.
Outside the US, people find this whole thing crazy, but that's how it is and it actually works well enough. My understanding is that banks are moving to a more modern system, but it's a slow process given how much is built around the current system.
But it does happen; google "check cashing scam" to find how they mule it out.
might also be a reason why US banks always seem nosy as fuck, calling people about transactions, blocking stuff, etc. instead of just giving the account owner a safe way to perform transfers/authorizations/set limits