PayPal terminated my account because I use a VPN
uwnthesis.wordpress.com
uwnthesis.wordpress.com
If your true IP is obscured by a VPN this is just a red flag for PayPal or any other payment processor. Especially if you happen to share the same IP as someone committing actual fraud - which is very much likely if you are using public proxies. Very few legitimate customers pay over VPN.
Do not use VPNs if you do not want to be flagged or blocked.
EDIT1: In response the comments, no I am not sarcastic at all. The number of legitimate VPN users (among general Internet population, not HN) is miniscule and does not justify the financial risks involved. If you are using VPN you are seen as hiding something and flagging/blocking you from sensitive transactions is an obvious response.
EDIT2: I am talking about public VPNs that can be anonymously abused by anyone - where you'd be likely sharing IPs with criminals. By all indications that's what OP was using if he wanted to hide himself. If you use VPN from work or coffeeshop you'll be identified by some innocuous-looking residential / corporate IPs.
I do understand that legitimate VPN users are probably a small percentage of Paypal total user base and that a large portion of frauders use VPN (I don't know what percentage of VPN users who paypal are trying to commit fraud, could be the majority, I don't know) But using VPN should cause you to get flagged. It has a very legitimate use. A lot of people use them when on the go to protect themselves while on wifi. I use a VPN all the time when I'm not at home (well aside from working at home which I do over vpn).
I don't see why I should expose myself to avoid being flagged.
Don't you explain this yourself? If few PP users use VPN and a large portion of fraudsters use VPN, I think we can chalk this one up to cold math despite the is/ought problem.
Because it isn't worth PayPal's time to cater to you. Seriously, go and use a different provider.
I know that sounds incredibly flippant, but it's the reality- PayPal will stop blocking VPNs when it is financially prudent for them to do so. Of all companies, would you expect anything different from PayPal?
The number of legitimate VPN users (among general Internet population, not HN) is miniscule...
VPN usage is increasing, not decreasing, even if as you claim, a "miniscule" group of users are using VPNs it's a dumb move by PayPal.Many corporate environments require the use of VPNs for mobile equipment (laptops, phones, etc.). Now imagine a business that uses PayPal and requires the use of VPNs for all of their PayPal account managers.
The argument that most fraudsters use a particular technology so we should ban use of that technology is myopic at best.
And if they do, you can be sure they aren't going to be using a VPN provider outside of the country to get around geolocation restrictions, or to mask the originating IP. They'll be sending their outside data _into_ a secure intranet, not back out into the general net.
Basically, the OPs only mistake isn't using a VPN, it's masking his original location, intentional or not. It's a stupid rule by PayPal, but it's not very surprising that they'd follow a "common patterns of fraud" checklist word for word. Thats what they do.
I do wonder which VPN the OP used. If he use one of those anonimizing VPNs that is popular with bittorrent downloaders, spammers and the like, then he shouldn't be surprised if Paypal's fraud detection unit was suspicious.
Feel we're not getting the whole story here.
There are too many ways things can go wrong even with HTTPS. First, how do you get to PayPal? Do you enter www.paypal.com or https://www.paypal.com? If you do the former you can be sslstrip'd [1]. You can check for the padlock icon (plus the correct domain name in the URL) but what if you forget? All it takes to be pwn'd is forgetting once, and if you're hurrying to get a bid in on eBay you'll probably forget. What if you do go to the HTTPS URL but get a certificate warning? I'm sure most HN users would do the right thing and reject it, but for ordinary users it's probably easier to just have a corporate policy that says "always use the VPN when on the road." And even if you always go to the HTTPS URL and reject invalid certificates, what if the site operator does something stupid like include non-HTTPS content or use session cookies without the secure flag?
HSTS is making things much better, but it's not a panacea - you have to have visited the site recently from a trustworthy connection for it to work. I still say VPN is better.
http://src.chromium.org/viewvc/chrome/trunk/src/net/http/tra...
[1] Remember, not all websites uses HTTPS, and even the ones that do might still be insecure (for example, by using non-secure cookies). Plus you have to constantly check to make sure you're accessing the correct HTTPS URLs or you can be sslstrip'd. It's much easier and safer to just use a trustworthy VPN.
[2] http://justinsomnia.org/2012/04/hotel-wifi-javascript-inject...
If the site is delivered via SSL, I just can't see what a VPN provides other than anonymity, which is not security.
True, you have to trust your VPN provider, but at the end of the day you have to trust someone, including the many certificate authorities on which HTTPS relies. But a good VPN provider is way more trustworthy than the types of networks you encounter when traveling. You should still check for SSL when using a VPN but you don't need to be as vigilant about it.
This is beside the point, but VPNs really don't provide anonymity. Many VPN services log and comply with court orders. Some VPN providers claim to not keep logs but you have no way of knowing if that's true. If you need anonymity you use Tor.
When we started icouch.me while in Shanghai, China, PayPal flagged my account and constantly locked it even though I jumped through their hoops "proving" our legitimacy and that no transactions (at that time) were actually China-originated. Just the simple fact that I logged on from China caused us to get locked out of our payments for up to weeks at a time (even though they still had no problem collecting the fees from our still-incoming transactions.) Then once I got that nonsense sorted, I started traveling more frequently for the company. So when I arrived in New York City, once again I was locked out of my account for 5 business days for "security" reasons, even though we've never had a single chargeback or any sort of security complaint or issue. Then I worked out of Texas for several weeks and once again, my account was locked. Despite the fact that we had the same US corporate bank account since 2010 (when the company was first founded.) By using a VPN, I was able to ensure my US "presence" to manage our business without PayPal's ridiculously retarded IP-detection security lockouts. I've since told paypal to go suck an egg and we use Stripe for everything.
When a company like PayPal can hold my operational funds hostage for weeks at a time with no way to clear it up expeditiously, then they just became thieves. They're making interest off of MY money while I can't access it. If they were "really" worried about security, then they'd block all transactions as well. But no, they have no problem taking money.
Interestingly, the credit bureau websites are locked to US only IPs as well. So if you have a subscription to some credit-monitoring service, they'll gladly take your money even if you can't access their services with a non-US IP address.
Those folks can all go to hell. It isn't my problem that some russian and nigeria scam artists have a tendency to cause problems. The IP address isn't the issue -- it's the security of their overall application. They're using geo-location as a shorthand for actually doing their job in securing their site.
Interestingly, I can access my US Chase bank account, my Simple account, Fidelity Investment account, Stripe from around the world without any sort of of VPN, yet somehow PayPal can't seem to figure out how to get security or customer service right.
Why do people still use PayPal? This stuff is not news.
Use PayPal or don't. Just don't expect them to let you use it anyway you want.
Wow, this sentence must win some "highest offense:words ratio" award. It insults so many people in so few words!
I've just been getting increasingly annoyed with the content on HN. We have Slashdot/reddit for developer bitching, why do we need it here?
I don't think we need mindless bitching anywhere. I think the site would benefit if more people showed up wearing their business hat and left their developer hat somewhere else.
I could be mistaken, but I thought that was the point of this forum in the first place.
No matter which hat you wear, feedback is valuable. It updates my probability that I'll get screwed by PayPal a tiny bit higher.
As far as "entitled" -- hell yes we're entitled. The developers here on HN make the apps that use the services like PayPal -- they/we have a right to demand that PayPal not suck. PayPal has a right to not listen, but we certainly have the right to complain and take our business elsewhere and as a community of spoiled, entitled, not-actual entrepreneurs we should ALL tell PayPal to pound sand.
TLDR: It's against the legal agreement to access PayPal that way.
Telling: Type "PayPal VPN" into Google and what you get are VPN services advertising how they help you sign up for PayPal when you're normally forbidden, with FAQ pages like "why is my PayPal account now terminated".
...I have uber security… and blocks against eavesdropping and MITM, and SSL and AES 256 encryption via an EFF sponsor, who runs a VPN… https://uwnthesis.wordpress.com/2013/04/08/paypal-terminated...
Looks like they were using a very public VPN that Paypal probably already had pre-flagged for fraud.
However I'll take the author at his word for a moment. Judging from the content on the author's blog, I think it's fair to assume he lives in Europe (where PayPal is regulated as a bank). Where does his VPN reside? It's certainly possible that it resides in a region that is regulated differently. One could look at this situation similarly to how YouTube, Hulu, Netflix, BBC, etc, block by region; not because they want to but because they have to. In the case of the mentioned sites, because of licensing terms, and in PayPal's case, because of financial regulations.
Paypal like any other big corporation has lost touch with its customer base. Its been that way for a long time now, someone needs to come in and beat Paypal in its own territory. Payment providers like Square are still the small time, they're not in countries like Australia or New Zealand or any other first world country that needs some Paypal competition.
I agree this is hostile and not friendly. But nor is dealing with fraud. I dislike PayPal and avoid them as much as possible, but it's hardly an easy task and I'm not sure other people would do vastly better if they had to operate with the same parameters.
I remember a little while ago having to supply some identifications documents to Paypal (scan of my passport, scan of my assigned credit card with most of the numbers blacked out, etc). If an account owner is willing to provide that information and is say from a country like the United States, Australia or the UK, then Paypal should lower their suspicions.
I can see where Paypal is coming from here. IP scanning is one of many criteria that determines if a user is potentially fraudulent (I've used Maxmind fraud protection before and it operates with similar criteria).
Well, they don't want people to use VPNs/tunneling and such because they are being used time and again to mask the country of origin, IP etc. They can even block your account for logging in from another country that you're visiting (they've done that to me and ask for photo ids and such).
It's not about "security" or lack thereof, it's about stopping certain kinds of fraud and keeping certain tabs.
(Sure, a VPN may protect from other kinds of fraud, e.g MITM attacks and identity theft. But then again, most actual PayPal customers don't use VPNs, whereas lots of identity theft and fraud guys do).
I guess that's reason why Paypal seems to endure beyond reason in spite of repeatedly showing the middle finger to customers. We in the US are relatively well off in terms of Paypal alternatives, but this is simply not true for a lot of other places. Plus Paypal has entered the status of being the 'default' for a vast majority of the non tech populace.
The good thing is, hackers are often the canary in the coal mine in terms of signaling future preferences of the masses, so we can hope Paypal will either reform itself, or die.
Probably not.
Or plain not being let into the bank. Most banks (in the UK at least) will not let people covering their faces into the bank.
PayPal is (still) not evil. It charges too much, and does some shitty things, like all companies.
It's ridiculous to jump to conclusions based off a blog post that doesn't even post a copy (redacted if necessary) of the allegedly offending communication.
It appears there's an internal lottery that all their customers play without their knowledge. If your numbers come up, the fuckup fairy will come visit your account and you will have little to no recourse.
If you have a website dedicated to chronicling just how badly you suck ( http://www.paypalsucks.com ) it probably means you're doing something very wrong.
Seriously, if you don't have pages devoted to how you suck, it means you haven't done anything noteworthy
Bank tellers are useful in that they are a human being with whom I can discuss things about my account with face-to-face, which is useful when something's gone belly-up with their systems and you need a real person who can see you're also a real person and hit the damn thing a few times until it works.
Finally, I'm still going to need a proper bank account for things like credit, overdrafts, standing orders of rent and such to people who haven't moved over to bitcoin yet, not to mention paying my taxes and taking my earnings from companies that pay in pounds sterling, US dollars, euros or other traditional currencies. It only makes sense that instead of holding a mass of bitcoins, that my bank (nominally HSBC for myself) holds a much larger mass and allows me to make payments in BTC much like I would in any of the hundreds I already can. If I wanted to hold BTC myself, then I could open an account in BTC much like I could open a EUR or USD account now.
[1] The i is a 20 pence newspaper by the makers of the Independent. Prior to moving to London where if you're not paying attention you can amass fifteen copies of the Evening Standard whilst walking across the river, I tended to buy a copy of the i every day going into college because it was something I could read entirely whilst eating breakfast and tended to avoid the fluff I noticed in larger papers on slow news days.
1. None of the ~ two dozen websites I've bought from in the past year supports it (and those are already technical shops). And most importantly, Amazon doesn't support it.
2. None of the people I've wanted to send money to have it
3. Never heard of it; why would I trust it? (well, ok, they have some well-known clients, so that gives them some level of trustworthiness)
I am aware it's a chicken/egg problem, but as a user, I don't care.