27 ms·
Klarna users are being signed in to random accounts
- corroclaro 5y ago"The payment giant Klarna, which has 87 million customers globally, currently has major technical problems. Users of the company's app saw other customers' payments and personal information, before it was shut down completely. The supervisory authority Finansinspektionen, FI, has asked Klarna to explain what happened." A future, fascinating post-mortem I hope!
- yreg 5y agoHappened to Steam in 2015. In their case it was a caching issue. https://old.reddit.com/r/Steam/comments/3y7lxm/when_i_go_to_my_account_details_in_the_steam/ https://old.reddit.com/r/Steam/comments/3y7lxm/when_i_go_to_... https://www.forbes.com/sites/insertcoin/2015/12/25/steam-is-randomly-logging-users-into-other-peoples-accounts-and-exposing-their-information/ https://www.forbes.com/sites/insertcoin/2015/12/25/steam-is-...
- Raed667 5y agoReminds me of what happened to Steam a few years ago https://www.youtube.com/watch?v=dkSslseq9Y8 https://www.youtube.com/watch?v=dkSslseq9Y8
- jchw 5y agoThis also happened to GitHub recently, although limited. https://github.blog/2021-03-18-how-we-found-and-fixed-a-rare-race-condition-in-our-session-handling/ https://github.blog/2021-03-18-how-we-found-and-fixed-a-rare...
- EE84M3i 5y agoIMO this sounds more similar to the steam issue as it's probably cache related. The GitHub issue was far more subtle.
- user3939382 5y agoIt also happened to Chase (!!) a few years back.
- Kipters 5y agoAlso to Italian Social Security agency last year (anyone surprised the site was built and maintained by a big ITC company?)
- jonas21 5y agoI remember when this happened to Apple with iTunes Connect (where developers submit apps for the App Store) back in the day: https://techcrunch.com/2015/01/29/itunes-connect-issue-logging-developers-into-other-accounts/ https://techcrunch.com/2015/01/29/itunes-connect-issue-loggi...
- dustinmoris 5y agoI find the default Twitter response by the Klarna social media account really annoying. The issue is not a system disturbance. The issue is clearly in the whole implementation of the system itself, code which was written by developers and where something really stupid has been implemented and where security was not taken into account at all because an issue like this could have been prevented at so many layers and yet it happened.
- rrrhys 5y agoWhole implementation? It's probably the edge cache catching a cookie on the way out, a toggle box somewhere.
- dustinmoris 5y agoWith all respect, I don't disagree with your assumption about a silly cache somewhere, but that is sort of my point, if such a severe privacy and security vulnerability can be introduced by a single toggle box somewhere then the architecture of their platform is hugely lacking IMHO. This is not a cat photo sharing platform but a fin-tech business and there should be more layers to security than a single toggle box.
- johbjo 5y agoYes? The session layer should confirm and only accept that the other SSL-endpoint is an authenticated app. The app should do this as well. If a toggle box exists that can cause this, I'd wonder how much of else of the implementation is worth saving.
- useerup 5y agoI've seen something like this happen because of a race issue during login. Basically the developer(s) had refactored something and were not aware that a global variable was being captured by a closure used for auth. This meant that whenever two users signed in at the exact same time, there was a non-negligible chance that they swapped accounts during the flow. It was actually not that easy to spot in the code. Sometimes what looks really, really stupid on the surface may in fact have a complicated and not-so-stupid explanation, often involving multiple developers and modernizing legacy code. If it is a race condition, it can be incredibly hard to find during test. Even if it is a stupid mistake, like e.g. not marking session cookies as secure and private, it does not mean that all of the rest of the code is bonkers.
- yummybear 5y agoI've had this happen, although not on a scale as this, when implementing caching and disregarding authentication as a parameter that varies the cache...
- EE84M3i 5y agoHappened to Valve too, Christmas 2015: https://arstechnica.com/gaming/2015/12/valve-explains-ddos-induced-caching-problem-led-to-xmas-day-steam-data-leaks-and-downtime/ https://arstechnica.com/gaming/2015/12/valve-explains-ddos-i...
- Saint_Genet 5y agoyou have to wonder why they decided to stay up. Surely, if you have a leak this bad, you pull the plug until you can fix it.
- whizzter 5y agoProbably a push to prod of something of something that worked on the developers machine, Klarna is at the size where any fault like this would be seen by thousands within any reasonable reaction time.
- K0nserv 5y agoAccording to the article they shut down all logins in the app. Unsure if this means you can still use it you are already signed in or not
- peach 5y agothey shut off the whole app, and kicked off who was logged in. Fair approach until they figure out how to sort it.
- gpvos 5y agoAs I read it, they did shut down as soon as they knew.
- arkitaip 5y agoJust nu svettas det mer än det regnar hos Klarna i Stockholm.
- Inhibit 5y agoHuh, from the headline I was thinking it was intentional! Nothing but marketing fluff in the newsfeed yet, still waiting on an article that's not walled in Swedish(?).
- queuep 5y agohttps://www.svt.se/nyheter/inrikes/storningar-i-klarna-appen-okant-fel https://www.svt.se/nyheter/inrikes/storningar-i-klarna-appen...
- corroclaro 5y agoSwedish is easy to translate with GT, here's a quick translation of the state news reporting, "Users of the payment service Klarna's app testify about disruptions on Thursday. Anyone who logs in with a bank ID has in many cases been able to see other people's information, including payments and invoices. - It is very serious and violates privacy, says David Bjurhede, one of many who noticed the disturbances. Many who have logged in with a bank ID on Klarna's app have on Thursday morning been able to get to someone else's account, users tell SVT Nyheter. David Bjurhede is one of those who noticed that it was possible to see another person's information in the app, including what purchases had been made and parts of the account number. - It is very serious and violates privacy and risk of fraud if you can find out user information so easily, he says. Another user says that he discovered the error at 11 o'clock and that it was possible to take part of other people's information for about 20 minutes. - It was possible to see almost everything, parts of the card details and exactly what they had bought and what their finances look like at Klarna. It's a little scary. I have not been through it before and I think it should not happen, he says."
- speedgoose 5y agoIt will be an interesting post mortem if they make it public.
- kesor 5y agoif they make it though alive ...
- fogihujy 5y agoLet's hope not. They're deliberately trying to get people to take on debt rather than just do card payments, and even simple things like buying a book through a web site requires declining several offers for paying with credit. Unfortunately, they're huge, and I doubt the Swedish authorities will do more than give them a fine and a slap on the wrist.
- prestigious 5y agoCard payments are usually debt also?
- fogihujy 5y agoDebit cards is more common in quite a few places. My impression has always been that paying everything with a credit card is a U.S. thing. Here in Finland, It's not uncommon to have no debt apart from the mortage on one's home.
- rossmohax 5y agoMS Exchange outlook web interface sometimes showed me completely unrelated mailbox content upon login: folders, list of messages, read status, subjects, etc. Trying to open email never worked though and the whole problem goes away after page refresh.
- rightbyte 5y agoSometimes I see my own mails before logging in for a short while in Outlook web app. They have some issues.
- yread 5y agoI like how when the session expires and you login again you get redirected to the random resource your browser requested when it just expired. So instead of the mail view you sometimes get the new mail jingle or some minified js. Makes me feel better about my own imperfect software
- def_true_false 5y agoThe Klarna effect?
- ThePhysicist 5y agoTheir German counterpart, Sofortüberweisung, didn't properly blacklist test credentials given out by banks e.g. to developers in the beginning, so people could simply use those and pay for goods and services with fake accounts. For me there are so many red flags with all these services, as they basically "steal" your credentials to log into your online banking. And while they claim that they only use the credentials to make transfers they could as well look at all my other account data. I really wonder how such a scheme can be legal and how banks can allow this, as they normally tell people to never give their credentials to anyone. The situation of course recently improved with the mandated 2FA for logins and transfers, but still there are so many attack vectors in this model that it boggles my mind how it can still exist.
- toxik 5y agoHear hear, I used Klarna (not by choice) and it surprised me they would feign being me in interactions with my bank. Exactly the type of behavior techies are trying to teach the older generations to NOT fall for. With this, we know that Klarna's software quality is papier-mâché level. I am happy I refused to let Klarna have my account authorization.
- tapland 5y agoThere have been some weird legal cases in Sweden where businesses and scammers have been freed after having signed in using other people's "BankID" to change retirement savings around or send cash. Its the ID method I use for credits, pharmacies, health care, taxes, but was apparently not an ID so it's not id-hijacking. Klarna has man in the middled my bank account before and performed a purchase and I've boycotting any company having them as the only payment option since. OH, now I also remember Klarna adding credit in my name since they only needed my tax registered adress. I lived in a dorm so someone just used our public information to take out credits to order sneakers and could break into the crappy entry mailbox.
- flemhans 5y agoIn Denmark, you're forced to use the state-run "NemID" for credit card payments, making for some weird situations where you authenticate with NemID inside iframes on shady URLs. The same NemID is also used to file your taxes, look at all your health info, get married, everything basically. Credit card payments are much lower security level, and they're basically forcing sharing credentials amongst all the sites you pay on.
- josteink 5y agoLots of times when I’ve been buying things in e-shops I’ve been offered to pay using Klarna as a payment broker. But doing so has always been more confusing for me compared to “regular” payments with a credit card anywhere else, and has on overall been a negative experience for me. I really don’t understand why anyone would prefer to use them at all. What am I missing? Can anyone help me understand?
- queuep 5y agoNot sure where you are located, but in Sweden, Klarna at the start (if I remember it correctly) only needed your 'personnummer'(social security number) to process payments. Now I think they manage to track your devices so I only have to enter my postal code, and then I just click purchase, and it's all done. They used to use really weird/dark patterns, to make you forget to pay and then pay huge fees to Klarna. Nowadays as I've configured Klarna, it just subtracts the amount from my bank account, hassle free, and I don't have to do a bunch of reserach wether or not the website is credible. Somewhat like Paypal, but smooother.
- jiofih 5y agoiDeal is smooth enough. Hoping this dystopian future does not come to the rest of the EU.
- rightbyte 5y agoYe Klarna was really scammy early. Making their living on reminder fees.
- LinAGKar 5y agoAnd they don't notify you when it's available for payment, or when it's about to expire. So if you order something, and it for some reason takes a few weeks/months before they ship it and it becomes available for payment, you'll end up with a reminder fee with no warning.
- ptx 5y agoHm? I always get an e-mail when the invoice is ready and another e-mail when the payment has been received.
- diveanon 5y agoIf you rely on your application layer to enforce data privacy instead of enforcing it in your storage layer its just a matter of time until you have an issue like this. It says a lot about the security of their api and development culture that they are even struggling with something like this. This should be caught in the first architecture review session.
- deleted 5y ago[deleted]
- bni 5y agoIn my experience very few have storage layer separation for customers data. It all logic in the application layer to control access. Do you mean stuff like row-level security in the database tables?
- corroclaro 5y agoCached data in middle layers can get even the safest of row-level secured databases. I agree in general that you need to enforce things at the storage layer.
- diveanon 5y agoYou're right, and cache policy issues can be really hard to debug. As a rule I don't cache personal information for this reason. Out of curiosity do you have any knowledge on GDPR's stance on caching PI?
- jablan 5y agoHow would any measures at storage layer prevent, for example, issues in caching?
- mewpmewp2 5y agoAnd how can one enforce it on a storage layer? There must be something in the application that determines user identity, which either threading, flawed logic, bug or caching (most likely) can mess up. In which case storage layer gets this identity information from application layer.
- K0nserv 5y agoI suspect this might be request threading/confusion[0] issue similar to the one GitHub experienced a while back. This would explain why seemingly random user data is being returned. 0: https://github.blog/2021-03-18-how-we-found-and-fixed-a-rare-race-condition-in-our-session-handling/ https://github.blog/2021-03-18-how-we-found-and-fixed-a-rare...
- toxik 5y agoWe can only speculate, but what baffles me is that it happens for something so private, and for a company that is so rich. Do they not audit their code? Do they not risk assess these things? "Ah, storing user credentials in thread local storage, that sounds sane and bug-proof" said no auditor, ever.
- deleted 5y ago[deleted]
- corroclaro 5y agoIIRC, Klarna is mostly written in Erlang, Scala and some parts in Clojure. If someone should be aware of thread-local storage and its implication it ought to be them.
- K0nserv 5y agoI was under the impression that they had switched to Java more in recent years
- def_true_false 5y agoUsing trendy tech doesn't solve much by itself. Especially if you can't (or don't) compete with FAANG on compensation.
- sidebits 5y agoThis has changed many years ago.
- BasedInfra 5y agoProbably caching set incorrectly. happened with steam years ago - https://www.bleepingcomputer.com/news/security/steam-caching-error-leads-to-account-disclosure/ https://www.bleepingcomputer.com/news/security/steam-caching...
- generic_dev_47 5y agoI worked in a project over 10 years ago where something very similar happened! We had built and authentication service that, among other things, was used by a SyncML service that was used back in the day of feature phones to syncs contacts etc. You can imagine that getting someone else's contacts on your phone isn't exactly ideal. This was how we came to know about the problem, from customers getting other customers data! The error was caused by a CDN switch. Our instructions to the the CDN team responsible for the switch was "Make sure the CDN honors our cache headers, if our HTTP responses say something can be cached do so, if they say that the response should not be cached then don't". We were in at least three meetings where we repeated this mantra. I believe that the CDN team thought that they had setup the CDN correctly but they had missed an edge case. The CDN was in fact setup to cache even uncacheable responses, and served those, _only_ when it could not reach our servers. So if there was a traffic spike and the CDN determined that our authentication servers were unreachable it would fall back to serving data that should never have been cached in the first place! Happily returning tokens to random users that had authenticated just before the traffic spike...
- corroclaro 5y agoOuch.
- matsemann 5y agoSomething similar happened a few years ago in Norway, when the yearly tax returns were released. Everyone of course logs in at the same time. It goes down, and the cache serves someone else's data instead.
- Silasdev 5y agoHappened for the danish tax authority about 10 years ago as well. Although I think the issue for them was that the unique login token was based on a timestamp that several users happened to share during very busy peaks.
- AtNightWeCode 5y agoI would expect this to happen if an option in the line of "serve stale content if target server is unreachable" is enabled.
- Flow 5y agoKlarna wants to be Facebook of payment. When I buy and pay with Klarna, they get the list of items and on Klarna's app and homepage I see pictures of whatever it is I bought. I'm not sure what to think about this. My first thought is "Is this really legal?".
- gpvos 5y agoWay to make me run away from them fast.
- ecmascript 5y agoTime to GDPR my account on klarna then.
- onoira 5y agoYou can't—at least in Sweden—remove much from Klarna. Your marketing profile is tied in with their accounting system. The law requires them to store accounting data for at least 7 years, with no obligation to actually remove it once that time is up. Since the accounting laws supersede the GDPR: they can hoard data pretty effectively. The Swedish 'Data Protection Authority' tried to launch (yet another) investigation for their shady practices, but Klarna strategically applied for bank status and now the reach and power of the data authority is cripplingly limited.
- chopin 5y agoYou can forbid Klarna sharing the accounting data with anyone. I doubt there is a legal sharing permission overriding GDPR for accounting data aside from tax authorities.
- onoira 5y agoThat's correct, but the data still stays with Klarna. I interpreted the OP as wanting to remove the data Klarna stores, or remove the 'account' pages. Neither of these are completely possible.
- elliekelly 5y agoWhats Klarna’s argument for the data in a customer’s marketing profile being necessary for accounting purposes? You can’t just store data in your accounting system and wipe your hands of GDPR.
- onoira 5y agoThat's what the investigation aimed to find out before it was cut short. Klarna's general reasoning has been (A) 'because', and (B) 'because it's all in the same system and we have no obligations or confidence in thinning it'. Any request for data or information regarding their architecture is rejected on the grounds of 'trade secrets'.
- 3dbrows 5y agoReminds me of this GitHub incident: https://github.blog/2021-03-18-how-we-found-and-fixed-a-rare-race-condition-in-our-session-handling/ https://github.blog/2021-03-18-how-we-found-and-fixed-a-rare...
- sublimefire 5y agoJunior dev was facing a dilemma. Before pushing to production please finish this code and choose the id you want to use: "select * from users where id = ?" > user_id > profile_id > user_profile_id > profile_user_id > id > rand()
- speedgoose 5y agoI don't think it's nice to make fun of beginners in our industry.
- jasonladuke0311 5y agoI _think_ it's intended to be a joke about the IQ test they supposedly administer to applicants.
- sublimefire 5y agoI was not trying to make a joke about the beginner devs. The list of choices a novice developer needs to make is reflective of our industry (why would there be so many choices). It is easy to make an error and bring the whole system down which in turn is the joke about "senior" people who instead of reducing complexity - increase it, and make it fragile.
- cblconfederate 5y agoI m sure it s not random but somehow systematic
- markburns 5y agoCould be random. I've seen this behaviour when enabling puma and using non thread-safe code. Just entirely depends on the timing of the requests. I suppose that maybe comes down to your definition of what 'random' is.
- bellyfullofbac 5y agoReminds me of a colleague implementing "emailRecipients" as a field in a singleton service. The first online order got an order confirmation mail, and when a second online order came s/he also got their confirmation mail (the field just grew and grew...).
- andix 5y agoOne more reason not to make singletons.
- Aldipower 5y agoI like the Whisky.
- andix 5y agoSingleton Malt? Me too!
- showsover 5y agoTo be fair singletons are pretty useful. You just have to understand that they're not made for mutating state.
- jaywalk 5y agoSingletons are fine and useful in many situations. You just have to understand what singletons entail, and design them correctly. If his singleton had a "SendEmail" function that accepted an Email object with To, From, Subject, Body, etc. fields, it wouldn't have been an issue.
- vikramsinghvs 5y agoThank you for sharing useful information with us. please keep sharing like this. You might like the following article also. Queen Scotia https://www.guidebooktolife.com/who-was-queen-scotia https://www.guidebooktolife.com/who-was-queen-scotia
- AtNightWeCode 5y agoWill be interesting to see what the problem is here. From what I have seen in real life my top guesses are. Some dependency on static variables in code. Reversed proxy with incorrect cache rules that ignores headers or some parameter.
- corroclaro 5y agoHow do you envision the static variables thing? I've seen the cache thing myself in real life but not the other.
- adflux 5y agoStore user in static variable during processing data, then forget to clear the variable when you are done, so for the next request it still has access to the old data?
- AtNightWeCode 5y agoIn C# for instance. If you mark a field static it is the same for all instances of a class (if you don't mark the code as thread static). So if you have static User field that changes on logon it will change for everyone. I have seen this but typically more complicated versions of it.
- chopin 5y agoThese can act like a cache across all instances. For exactly this reason I use them only as final (constant) variables and very, very rarely mutable.
- deleted 5y ago[deleted]
- snthd 5y agoSo a maximum gdpr fine of ~$48M?
- mrweasel 5y agoKlarna is a weird company. Last I interacted with them it was clear that they are completely designed to operate within Sweden, but have no idea of how to deal with the outside world. Maybe that have changed. I talked to Klarna maybe 10 years ago. One of the things I wanted to know was how they dealt with abuse in Sweden, given you just need the social security number of a person and then you can do purchase as that person, and Swedish SSNs are not secret. The friendly Klarna rep. had no idea what I meant, as you could only get stuff delivered to the address associated with the SSN. Based on how that would be abused in Denmark we suggested ordering a box of random sex toys to any random person in Sweden. The only answer I got was "Why would anyone do that?" It took less than six month for Klarna to start asking us to block addresses, because they had no way to prevent abuse.
- 2rsf 5y ago> "Why would anyone do that?" That's such a typical Swedish answer... but they do allow (but not as default!) to block orders and request digital confirmation
- neuronic 5y agoOf course, Sweden's largest export are lessons about morality. Interesting for a country that slowly eradicates their indigenous people btw. https://en.wikipedia.org/wiki/S%C3%A1mi_people#Discrimination_against_the_S%C3%A1mi https://en.wikipedia.org/wiki/S%C3%A1mi_people#Discriminatio... https://en.wikipedia.org/wiki/Swedification#Swedification_of_S%C3%A1mi_and_Tornedalians https://en.wikipedia.org/wiki/Swedification#Swedification_of...
- anticristi 5y ago> Of course, Sweden's largest export are lessons about morality Not sure why you were downvoted. I think your comment is rather fair. :) Although, let's give them some credit, they do have a pretty successful mixture of socialism and capitalism. > Interesting for a country that slowly eradicates their indigenous people btw. I think that sad story is over. They significantly ramped up protection for indigenous people.
- sneak 5y ago> Hear hear, I used Klarna (not by choice) It was by choice. You weren't born with an account. Not taking personal responsibility for the rise of the ubiquity of these terrible online services (WhatsApp users, I'm looking at you) is a huge part of the problem. Pretending that you didn't opt-in is a lie you've told yourself; you shouldn't propagate that lie to others in society.
- rbmks 5y agoIn principle I agree, but you can be tricked into using Klarna. However, in Europe you should be able to cancel the order without reasons.
- Aeolun 5y agoWhatsapp was fantastic when it started. Right up until it was bought by facebook.
- gpvos 5y agoSofortüberweisung needed your bank credentials from the start.
- nemetroid 5y agoIt at least used to be very easy to accidentally sign up for Klarna, thinking you're just paying by card.
- moogly 5y agoKlarna are the masters of dark UI patterns.
- toxik 5y agoI needed to buy things, because that is life, and the merchant only offered Klarna. You might want to reconsider your hostile rhetoric, it does not come across well.
- 5y ago
- justkez 5y agoThey also had a snafu with marketing emails late last year [1] - not a great look for a company handling bank/payments. [1] https://www.bbc.co.uk/news/business-54521820 https://www.bbc.co.uk/news/business-54521820
- timdaub 5y agoSometime in the future, people will stop belittling crypto currencies when they realize that the digitization concepts of traditional finance technology providers are inferior to those of crypto currencies and blockchains. Putting safety and security first for anything that handles money makes sense. The calls for "you don't need a blockchain, just use a database" will become less and less. Edit: Of course, Hacker News hates this comment.
- junon 5y agoYes and we'll be screaming "please shut off your computer" because of all of the excess heat and insane power bills.
- timdaub 5y agoWhy not separate concerns? Crypto currencies work without Proof of Work today.
- novium 5y agoYeah, so basically use something like Chia instead and create tons of e-waste?
- gspr 5y ago> Why not separate concerns? Crypto currencies work without Proof of Work today. You mean through proof of stake instead? Yay, now all the people who wanted to avoid having a competent central bank in a free democracy control the money supply get to have the people with the most money control the supply instead. Jesus fucking christ, you cryptocurrency lunatics have lost it.
- macintux 5y agoI don’t necessarily disagree with the sentiment, but HN guidelines demand more constructive disagreements.
- sneak 5y agoThere was that time that Dropbox let you log in to any account with any password, too. I've never run a line of Dropbox code on any machine I own since that day. Even if you have no tests whatsoever on your app, you should have some basic smoke tests on your auth system.
- andersco 5y agoMy email includes a common Swedish first name so I regularly have people mistakenly use my email address for Klarna orders. What’s most annoying/troubling is that, at least last time I checked, they don’t verify an address before sending invoices, etc. so I end up with other people’s order info in my inbox. I finally started unsubscribing from notifications for orders that weren’t mine.
- tapland 5y agoIs your email adress firstname@something.etc? I've seen a lot of people not get their emails and wondering if they parse lastname.firstname@something.etc wrong
- temptemptemp111 5y agoGiant Swedish companies really help underscore the issues with Swedish culture & honesty.
- vesinisa 5y agoKlarna is no stranger to criminally lax attitude towards data privacy and security. In Finland, they implemented a checkout flow based only on your SSN (personal ID number). By simply entering someone else's SSN (which is not hard to guess/pry) you can reveal anyone's official home address. Further, they enable a "pay later by invoice" checkout flow, again by just knowing someone's SSN. Scammers use this to order items from web stores to automated pick-up lockers with someone's else's SSN for payment info. The victim usually only becomes aware about this activity when they start getting debt collection notices for unpaid invoices from multiple stores for thousands and thousands of euros. The debt collection process in Finland is famously unfair and harsh towards the supposed "debtor" (here: victim of fraud). Unless the "debtor" (victim) actively opposes each and every individual collection, the cases will eventually end up in court with summary judgement. This will ruin the victim's credit rating, which has devastating results for just about all aspects of life. People are known to have collapsed under the burden of all this and ended up taking their own life. Klarna's response to all this is that they want convenient checkout experience and some fraud is unavoidable. Although there are excellent technical means available to strongly identify users in Finland, they add a minor layer of inconvenience compared to just typing in your SSN. This is OK for Klarna since they give exactly zero fucks about security as long as they can make a little buck from it.
- 2rsf 5y agoIn Sweden you can ask them to require Mobilt BankID confirmation to every buy, their competitors (like qliro) don't have that yet so Klarna are only half bastards. But they did get a lot of criticism from the Swedish government about the same things you have presented.
- e_proxus 5y agoTranslation: Major technical breakdown at Klarna when customers saw other people's data - The Swedish Financial Supervisory Authority (FI) has contacted the company Payment giant Klarna, which has 87 million customers globally, is currently experiencing major technical problems. Users of the company's app saw other customers' payments and personal data, before it was shut down completely. The supervisory authority Finansinspektionen, FI, has asked Klarna to explain what happened. In its app, Klarna has major technical problems. It means that users were logged into other customers' accounts and thereby see sensitive data such as their payment and purchase history and postal address. Users were also able to see part of the bank details linked to Klarna, but not the full account number. One of Di's journalists accessed an account belonging to "Elisabeth". When the app was reloaded, another customer's login became visible. When customers logged in with their own bank ID, they accessed other people's accounts. Each time they refreshed the page on the app, they brought up the details of a new, seemingly random user. It is unclear whether customers have been able to shop with other people's money. Klarna had a total of 87 million consumers worldwide at the end of 2020, but it's unclear how many of those have an account on the company's app. The technical breakdown also extends beyond Sweden's borders, with outraged reactions pouring in on Twitter from Klarna users in various countries. Klarna has now closed the app, citing a service outage. The company's press officer Niklas Gillström will return to Di after a while with a written comment. "We are currently experiencing disruptions in our systems caused by technical problems. We are doing our utmost to restore the system and our services to full capacity and apologize for any inconvenience this may cause our customers. We have currently blocked all logins to the app until we are sure the problem has been fully resolved." Di continues to seek the company for follow-up questions on whether the technical problems are due to an internal breakdown or external influence, how seriously the company views the sharing of personal data between users and whether customers may now have accidentally traded with other people's money. Klarna has asked for a response. The Swedish Financial Supervisory Authority, FI, which among other things is the supervisory authority for banks, states that it has been informed of the situation. "We have contacted Klarna and asked them for an explanation of what has happened," says Karin Lundberg, head of the business area Banking, to Di. At the moment, FI has no further comments, she adds. Di also seeks the Privacy Protection Authority, IMY, formerly known as the Data Inspectorate, for comment. IMY has the right to fine companies up to 4 percent of their global annual turnover for serious violations. In addition, Klarna could face civil litigation, not least in the US where it has 15 million users. (Translated with www.DeepL.com/Translator)
- gladw 5y agoThis seems to have been brigade-flagged, as always if Fintech is criticized.
- gladw 5y agoOther discussion that is rapidly sinking from the front page: https://news.ycombinator.com/item?id=27301311 https://news.ycombinator.com/item?id=27301311
- Raed667 5y agoTotally anecdotal, and probably unrelated, I interviewed for Klarna a few years ago. Mid process, they sent me some sort of timed bizarre IQ test that the recruiter claims EVERYONE who works there has to take. That's when I knew that kind of working culture wasn't for me.
- the_monocle 5y agoA recruiter contacted me aswell and I asked about their salary. They pay 50k euro for juniors in berlin with afaik no stock vesting. How they even manage to get qualified personnel is beyond me, I would expect much more for a fintech with over 3B evaluation
- 2rsf 5y agoactually they are a top tier payer in Stockholm
- adflux 5y ago50k in euro's is pretty ok for European developers, no?
- the_monocle 5y agoI am from munich so my opinion may be skewed, but it is at best very average, as in some no name devshop/consultancy would pay this much(and even they tend to pay more). Nothing I would expext from a Unicorn, but maybe the market in Berlin is THAT different.
- towway78954 5y agoStripe, another payment company, has salaries starting at 130k euros in EU
- tkiolp4 5y agoIn all Western and Northern Europe (except UK and Switzerland), 50K for a junior position sounds about right. It’s around 25K in Southern Europe, and probably less in Eastern Europe.
- cpach 5y agoDupe https://news.ycombinator.com/item?id=27301311 https://news.ycombinator.com/item?id=27301311
- tapland 5y agoThat thread got spam flagged or something and is no longer visible, but has a lot more comments and discussion.
- kruxigt 5y agoWhy did this one disappear from the front page so fast?
- switch007 5y agoWho knows, many of the HN algorithms are secret and there is no moderation log a la https://lobste.rs/moderations https://lobste.rs/moderations
- dang 5y agoTrue, but it's still always possible to get an answer to a question—you just have to ask. However, we might not see it unless you ask at hn@ycombinator.com.
- switch007 5y agoI don't want to appear ungrateful - let me take this opportunity to thank you sincerely for all that you do. Your set up appears to work, and I'm probably in a minority with my demands. We wouldn't have to ask if you had a public mod log (and banned sites list etc) and a public explanation of the algos that power HN. Your comment reminds me of hotels - "X is available, just ask". A scheme clearly designed to reduce usage of X. I'm guessing the current audience is quite diverse, as most engineers would see through that kind of BS in about 0.2ms.
- maxekman 5y agoTheir iOS app shows “Down for maintenance” :)
- nopcode 5y agoLooks like a JWT oopsie
- terminalserver 5y agoKlarna says they are “experiencing technical disturbances due to technical errors”. Sounds like a poltergeist.
- marvin 5y agoIn Norway, we call this class of error "a Kenneth", after everyone who logged in to see their tax return in 2012 received the tax return of a guy named Kenneth. The culprit was allegedly a misconfigured load balancer.
- terminalserver 5y agoI once got a credit card statement that told me I would be able to pay off my credit card in 100,000 years. It was discouraging.
- ddalex 5y agoOnce a colleague made an accounting error and it showed that we're in debt something like 100 million.... I told him to stay calm and relax, we don't have that kind of money so why worry :)
- matsemann 5y ago"If you owe the bank $100 that's your problem. If you owe the bank $100 million, that's the bank's problem"
- adamlj 5y agoCaching and Vary headers can be tricky to get right
- cotillion 5y agoYup, when you get it wrong you get to meet interesting people from the compliance department. The "enable cache" button in the load balancers should come with alot of warnings.
- cerved 5y agoKristel and Sonya seem to have the same due payments
- alkonaut 5y agoYes the chance of that is almost zero. Either the due is the actual users value (only profile name is changed) or this is some kind of test data being exposed.
- ericmay 5y agoDoes Klarna still do the IQ test as part of their hiring process?
- artemonster 5y agotangential thought, but related: I am, in general, a proponent of nuclear energy as a green alternative to whatever the hell we are doing today. But when I see such stories that humans manage to fuck up simple payment processing apps, still make errors while maintaining bridges, still manage to do hugely negligent screw-ups (most likely corrupt) in *cable cars maintenance*, I immediately think that it is imminent, that something will go wrong with such complex thing as a nuclear reactor and the price there is much bigger.
- bellyfullofbac 5y agoThe Italian cable car was really messed up. The emergency brakes of that cart were intermittently triggering, so the operator jammed a piece of metal to stop that from happening. His assumption is surely, "Relax, what's going to happen, the cable won't break!".
- ectopod 5y ago> The emergency brakes of that cart were intermittently triggering My guess: each time a strand within the cable broke the cable stretched a little and the brake triggered. Five years ago a company was hired to maintain the cable car. They took one look at the state of it, wrote to the operator (the town council) saying it needed to be shut down and exited the contract. It was an accident waiting to happen long before the brake fiasco.
- viraptor 5y agoI kind of get the worry, but the requirements and processes seem to scale exponentially with reliability needs. Online companies may fuck up every day in new and creative ways and we barely get to hear about it. On the other hand we know of every nuclear failure so far with enough public details to discuss the whole time line, system design, steps each person followed, etc. and the death count is still minimal. Then each of those is an input to the future processes. Nuclear power plants and air traffic are in their own class of reliability and safety processes - not even comparable to that's happening in internet commerce.
- saos 5y agoahh thats why im struggling to sign-in
- ho_schi 5y agoI had once contact with Klarna. It required me eight weeks to teach until they accepted the truth - I didn't owed them a cent. Just one of the usual startups around outsourcing, minimum wage and avoiding actual work. Lesson 1: If someone want to sell you something and doesn't want make the bookkeeping itself, avoid them. Lesson 2: In doubt? Cash only.
- altacc 5y agoI can understand avoiding a company due to a bad experience but that sounds like a rather general and rather restrictive conclusion. Did you mean bookeeping specifically, or payment handler, as they are somewhat different things? For small businesses using a payment processor removes a massive barrier to market entry. Many small business hire real world external accountants to do their bookkeeping, so "avoiding actual work", would you avoid them as well? I do some work with the accounting & invoicing teams in our corporation and there is a LOT to take into account that would cripple a startup with only a handful of employees. Bigger companies use services like Klarna not because they can't (often they have other payment methods as well and do their own bookkeeping), it's because customers like to use them and failing to use something like Klarna means their customers will shop elsewhere.
- kgnail 5y agoUsing a real payment processor for credit cards is not a problem. Like it was around 2005, when most merchants had not settled on Klarna and similar. Some merchants sell via Klarna to private customers and via invoice or pre-payment to a proper bank account to business customers. Private customers are second class. No business would deal with this nonsense.
- admissionsguy 5y ago> it's because customers like to use them and failing to use something like Klarna means their customers will shop elsewhere. Also, some customers do not have personnummer and find Klarna to be one of few payments methods that will reliably let them shop online.
- mavster 5y agoI'm just guessing, but... "developer gets a great idea - let's push an update to the API as a GET request so we can cache this on the CDN... forgetting that the JWT token is potentially returned in the call. Now, whoever makes the call first gets their JWT token stored for everyone else to load instead when the API call is made." Ta-da, Klarna.
- growt 5y agoI introduced a similar bug into one of my products in the past (Be honest, who hasn't?). But I'm surprised here because Klarna is a quite mature product and something like this shouldn't really happen at that stage.
- yawaramin 5y agoOh, it can definitely happen even in mature products. One I worked on had pretty much the same issue as Klarna (people seeing others' info) when someone updated a web client library we were using to a new version that subtly changed how it handled concurrency.
- miohtama 5y agoI expect something exactly like this happened. I had a similar bug long time ago. Apache was somehow incorrectly caching the request and the session cookie in the request ended up in a cache. But it happened only about 1/10,000th of the time so it was impossible to figure out the root cause. However, one common source for this kind of bugs is to ”cache any URL ending .pdf as a static file” and then you are in fact serving logged in PDFs like customer invoices that come with the session cookie. I think CloudFlare used to come with a default rule to treat .pdf as a static content. The responses were cached when you hit their ”cache the good stuff” checkbox.
- dminor 5y agoYears ago I added varnish in front of a website to cache image requests, not realizing that if the response included 'set-cookie' that was also cached. We immediately started getting reports of random products appearing in our customers' shopping carts, as people's sessions got merged with random strangers.
- bjornsing 5y agoInteresting that all the screenshots have a (typically) female name, and the reporter seems female. Could be chance of course, but a quite low likelihood if the sampling is truly random... Can’t help thinking what kind of bug could cause that. :)
- nrmitchi 5y ago> quite low likelihood if the sampling is truly random... If you're assuming their user base is 50/50 male/female, which for many apps is not a valid assumption. If I remember how to do math correctly, 50/50 gives 5 random users all being female ~4%. And 80/20 split is closer to 40%.
- bjornsing 5y agoTrue. My implicit assumption was 50/50 or predominantly male, but I could be wrong of course. 4% is a pretty low likelihood though. Far below the level that would warrant further exploration in this kind of situation.
- ipsin 5y agoWhat are the ways you can implement "log in as anyone accidentally"? I'm imagining it was a case of an SQL-based password check where "TRUE OR" got added to the WHERE clause, and the code takes the first result instead of expecting only 0 or 1 row. Are there other easy ways to do this?
- nrmitchi 5y agoFrom a quick glimpse on twitter, people couldn't make changes to any of the accounts they were seeing. This points in the direction of this being a caching bug; you request your homepage, and get the homepage of whichever user was placed in the cache last. Most of the time in these situations it's not an application-code issue (per-se), as much as a "shared global state" issue.
- bellyfullofbac 5y agoIt's not a web system but Mac OS messed it up once: https://objective-see.com/blog/blog_0x24.html https://objective-see.com/blog/blog_0x24.html Caching could be an issue, if they added a cache for a microservice call of /get/user?id=$USER and ignored the id parameter, /get/user?id=ipsin fetches data for the user ipsin, the system sees the next call /get/user?id=bellyfullofbac and thinks, "Wait, I have the results of /get/user in cache" and returns the data for ipsin again...
- chrisandchris 5y agoBesides having the HTTP verb in the URL (GET -> /get/), why would you put the id in the query? Why not just use GET /user/1234 instead of duplicating things by using GET /get/user?id=1234 . What does GET /get/user then even return, all users, no user, ...? Edit: typo
- bellyfullofbac 5y agoIt's just an example...
- ladon86 5y ago1) Caching: a cache is used in front of the API for things like product listings, it uses a pattern match like /api/products/*, and caches routes which match. Someone accidentally configures it to cache /api/*, and thus login responses from /api/session return another recent user session, potentially including the cookie such that subsequent requests are authenticated as that user. 2) Mentioned elsewhere in this thread, a variable with global scope within an application server. This is very possible in node.js, which uses a long-running single thread - if you have a function like handleRequest(), you might inadvertently write to a global variable outside it, and that variable will persist across requests from different users. I've seen this exact bug in a PR - luckily we caught it before production, but if it had slipped through code review and integration tests and actually shipped, the result would have been exactly like the one in the tweet.
- 2rsf 5y agoOnce you logged in once Klarna stores your credentials and then presents you one click buying inside ads in unrelated sites (well Klarna are not doing the advertisements but allow such links). You can then accidentally click the wrong thing and buy without any further confirmation. At least in Sweden you can ask them to request digital ID confirmation for each buy. With the current problem maybe I can buy using someone else's name...
- _nnv7 5y agoI am really really interested in knowing the root cause. I am really concerned by agile, and start-up hipster culture creeping into critical infrastructure companies. There are so many patterns(event driven, CQRS) in recent microservices architecture, which are gaining popularity and people have been using them without realizing the cons and the need for them.
- duxup 5y ago>agile, and start-up hipster culture What does that even mean?
- _nnv7 5y agoLooks like people are really offended by this. Agile lately has been looked at this silver bullet for software engineering. I have worked both in Cisco and some good startups and in my humble opinion having fast paced development and high feature churn rate really is unsuitable for a bank and other infrastructure companies. Also by hipster, I mean that the banks don't have luxury to experiment with latest trends and the cool tools. They have to stick with the old proven methods.
- duxup 5y agoI don't understand your perspective here. Debates about Agile have gone on for ages, that's not a 'lately' thing. I have no idea what 'hipster' has to do with banks and tools... or what you mean by 'old proven methods'.
- tedd4u 5y agoAt a large site I used to work for circa 2011, before everyone had gone fully HTTPS, we received similar panicked reports from users: "I'm logged in as someone else!" Turns out an ISP in the Philippines decided to just ignore `cache-control` and `vary` headers and forcibly started caching logged-in responses along with auth cookies. Bad times. Made it clear to me why the whole web would have to go HTTPS.
- NullPrefix 5y agoYeah but what about the saved traffic? Think of the poor routers that have to do all this transferring job.
- Scoundreller 5y agoReminds me of a primitive web filter at work that blocked me from something. So I look at the URL, add an “s” to http and voila. I think they MITM everything now.
- hundchenkatze 5y agoKlarna has posted a statement here https://www.klarna.com/uk/blog/written-statement-on-app-bug/ https://www.klarna.com/uk/blog/written-statement-on-app-bug/
- dvaun 5y agoIn their statement they deny accessing bank details: > The bug led to random user data being exposed to the wrong user when accessing our user interfaces. It is important to note that the access to data has been entirely random and not showing any data containing card or bank details (obfuscated data was visible). This means that it has been impossible to access a specific user’s data. This is not the experience of the user in the OP: https://twitter.com/esraefe/status/1397843949985931265 https://twitter.com/esraefe/status/1397843949985931265
- hbosch 5y agoI believe it is the case, that when you see your stored payment method is is obfuscated such that it only reveals the last 4-5 digits. Same with bank details as far as I know. However, showing the card issuer/bank + the final 4 or 5 digits of an account or card number is still extremely distressing. There are some services and vectors out there that can be engineered with just that information for sure. Combine that with possibly exposed address, telephone number, and you are in very dangerous territory.
- shkkmo 5y agoIt might be accurate if you are internally discussing PCI compliance. However, to the layperson, "bank details" definitely includes name of bank and last 4 digits of account number. It does come across as deceptive to use that terminology to respond to customer complaints.
- _nnv7 5y agoThey mentioned human error. I could feel bad for the human who error-ed, but I wonder what kind of human error could have this huge impact. It could be something to do with cache configuration.
- henvic 5y agoAs a software engineer, I hate when I add a check for something "that will never happen" but that if happens is awful, and people complain. A classic example: you need to get a user from a session, check against a database, and continue if they're signed in. Then I add a simple if databaseUser.Username != form.Username and people will say "if that happens we've something worse wrong". Geez, something might be wrong and such double checking might provide to be useful. On a smaller scale, bits flip due to cosmic rays and so on. Of course, there must be a limit where we stop, but people are used to actively avoid doing such "silly assertions" even for important steps. ¯\_(ツ)_/¯
- bagacrap 5y agoit's fine to make the check but I hope you don't sweep it under the rug with an early out without at least logging the occurrence
- geofft 5y agoI think there's merit in objecting to "that will never happen" checks in some cases (though, to be clear, I'm not saying the people objecting to your code are thinking about the same thing I am). Specifically, if you have data that is loaded from some other source, your extra safety check might be checking data that's loaded from the same source, in a way where if something did go wrong, it went wrong in both places you're checking. In this case, it seems pretty unlikely that Klarna's bug was that they ran "SELECT * FROM users WHERE Username = 'joeuser'" and they got back a row where Username != 'joeuser'. I don't think there's a recorded case of that ever happening with databases. However, it seems much more likely that Klarna's bug was in HTTP caching or something, that results were returned for the wrong user. Then there's no opportunity to see databaseUser.Username != form.Username: that check would have indicated that things are correct, but the username being passed into this code was wrong in the first place. That sort of problem definitely happens in the wild - see the "Kenneth" story elsewhere in these comments, or off the top of my head https://blog.zulip.com/2021/03/20/zulip-cloud-security-incident/ https://blog.zulip.com/2021/03/20/zulip-cloud-security-incid... from two months ago. And if it is, somehow, a database bug, why do you trust the database at that point? What if the database returns part of one row and part of another? What if it returns the username you sent in because of some optimization to avoid copying data, but thanks to a bug (or a cosmic ray) it reads in the rest of the data from an unrelated row? In the unlikely but not totally impossible case that you need to protect yourself against this, validating the username isn't enough; you'd better sign the entire database row and validate the signature before trying to use any of the data that's been returned. (And come up with some reason why you trust your own app code more than the database.) The problem with such "silly assertions" is that they make you feel like you've added test coverage, when the thing you're testing is something like a database that is extensively tested by its vendor and by everyone else using the database, and there are other seams in your code which are much more likely to break. Meanwhile, they make the code longer and harder to read, which prevents readers of the code from easily identifying what those seams are. (And by slowing down the API endpoint that talks to the database, it motivates other developers to try to put some caching in front of that endpoint, which may actually cause this sort of problem!)
- WaitWaitWha 5y agofrom this event... game idea: create a social media site - allow postings, conversations, threads, etc. Every quarter (or some other period), there is "reconning". You are placed into a complete stranger's account, and now you have to continue it for a week (or some other short period). Whoever can maintain the quality of the account, in the direction as the original owner, wins a banana (or kumquat, something good but not expensive for anyone). After reconning period, owner returns and judges. None-participation is default no-win.
- paxys 5y agoHaving at least authenticated sections of your site use HTTPS was standard well before 2011.
- oxplot 5y agoThat only protects the user's password. The auth cookie will be sent in all subsequent requests in plain text. EDIT: that's how firesheep (https://en.wikipedia.org/wiki/Firesheep https://en.wikipedia.org/wiki/Firesheep) hijacked sessions for e.g.
- nly 5y agoThat's not true. Cookies can have a 'secure' attribute which tells the browser to send them only over TLS
- eli 5y agoin 2011?
- shkkmo 5y agoYes
- chc 5y agoBut that just makes your login not work if the rest of your site is HTTP, doesn't it?
- shkkmo 5y agoYou should not show authenticated pages without HTTPS
- oxplot 5y agoA secure cookie would be of no use for a site whose only secure page is the login page, which is what the parent post I replied to was talking about.
- dkersten 5y agoHere's their official statement: https://www.klarna.com/uk/blog/written-statement-on-app-bug/ https://www.klarna.com/uk/blog/written-statement-on-app-bug/ Although I dunno about "According to GDPR standards, only non-sensitive data was exposed." since in the twitter thread someone said: This is definitely not a test environment. I was called by someone who was logged in to my account and saw all my personal data including bank details, Klarna card etc. And while I'm told the bank details are obfuscated (I don't use Klarna, I dunno), I would consider the phone number to be a clear breach of my privacy under GDPR. Although, the twitter account that said that has 0 followers, so maybe its not true. I dunno. I know someone who works for Klarna and he told me: "Full investigation will take time. There's a LOT of engineers working on this. Only confirmation I have currently is that the firstname was visible." Going by the screenshots, first name and account balance. Doesn't seem that bad from a GDPR point of view. Still bad, of course, but not suuuper sensitive. EDIT: Nevermind: https://twitter.com/esraefe/status/1397843949985931265 https://twitter.com/esraefe/status/1397843949985931265
- skeeter2020 5y agoAnd this is both maddening AND make the problem worse (from the CEO): "We are truly sorry for any inconvenience..."
- dkersten 5y agoOof, yes, its not about inconvenience...
- _u 5y agoI can remember something similar happening on Facebook back in 2013-2014 (when I was a kid). I went on this app called 'Video Chat Rounds' and when I left the app, I got signed in to a random Facebook account.
- shaan7 5y agoHa, one time I was debugging an issue that only happened to a particular user. Lazy as I was, I hardcoded his auth token in the code "just to test". Having found the bug quickly, I was excited and did not realize I checked-in the auth token too. Bypassed reviews, pushed to prod and then reports started coming in "Hey, users are saying they are all logged in to this random guy's account". Lessons learned the hard way ;)
- lupire 5y agoDid you compensate the victim of your personal and corporate negligence?
- deleted 5y ago[deleted]
- passerby1 5y agoJust out of curiosity. Is it a bad question for some reason or why is it downvoted?
- greycol 5y agoI didn't downvote it but the tone does seem quite adversarial to me. You could ask "what was the fallout?", "Did the client get compensated?", or "did you make procedural changes afterwards?" without being as confrontational. Less people will post about their mistakes if they know they're going to be lambasted for them. We can learn from these mistakes if they're shared or they can be a timely reminder of stakes if we're slipping into complacency. So we probably don't want to discourage such posts (especially since it's rarer for people to want to talk about failures that successes).
- sharken 5y agoTime for a blameless postmortem https://www.atlassian.com/incident-management/postmortem/blameless https://www.atlassian.com/incident-management/postmortem/bla... Or perhaps not https://techbeacon.com/app-dev-testing/blameless-postmortems-dont-work-heres-what-does https://techbeacon.com/app-dev-testing/blameless-postmortems...
- foobarbazetc 5y agoI’m pretty sure this (or something like it) happens at least once to every major site. The stuff of nightmares.
- klarnaenginner 5y agoIs that a really surprise to you guys? Just look for the old klarna news, this is not the first time and won’t be the last time. There is no security on internet, just get used to it, if you use klarna.
- Seattle3503 5y agoI've seen this happen when Cloudflare caching is misconfigured.
- m3kw9 5y agoFree advertising
- mirceapreotu 5y agoCache invalidation issue. Classic
- tibiahurried 5y agoThe new guy that stores user information in the servlet. I have seen this before.
- OJFord 5y agoI think this would make quite an interesting exercise for whatever it is one works on oneself; that is, what's the minimum, most innocuous patch that causes this behaviour? I bet it's not as much as people railing against it would like to think. I'm partly thinking of this because I fixed a (way less critical) bug today that boiled down to a (x - y) * z = 0 query that should've just been (x - y) = 0. But it was hidden by the whole expression being named, and that then seeming correct, it not being obvious that `z` could be 0 (or was involved at all) and as a result unwanted results would be included where x != y. Probably the most obvious one is different IDs - have two fk columns that sound a bit similar and it's easy to come a cropper, getting 'random' records that correspond to a given ID but that's for the wrong table...
- kenniskrag 5y ago> getting 'random' records that correspond to a given ID but that's for the wrong table... That's why I use GUID instead of integers. If you get a result, it was the right column.
- OJFord 5y agoGood point, we do for new things, but of course when I hit it it was with an old table and was a problem.. sod's law. (Though arguably it's just harder to notice the effects of it happening with a GUID and it could have too.)
- anontrot 5y agoContext in global variables
- p2detar 5y agoWe still haven’t got our money back for a purchase paid via Klarna. Apparently they wired the money to another bank account but under my partner’s name. After 3 support calls and several emails, we just gave up. Fortunately it was just €12. This was so frustrating that we now avoid paying with Klarna whenever possible.