11 ms·
PayPal Allows Bypassing Two-Factor Authentication with a Button Click
- jonny_eh 4y agoI didn't even make it halfway through the article before I logged into Paypal and removed my payment info. Strangely though, when I logged in I wasn't prompted to use a one-time code.
- TedDoesntTalk 4y agoI have to PayPal accounts, one personal and one business. Neither have the login option mentioned in the article. It could be in A/B testing at the moment.
- deleted 4y ago[deleted]
- paulpauper 4y agoMaybe it cross refences with the IP of past logins. So it would not work from a different area.
- SanjayMehta 4y agoThe article makes it clear that there's a login button which lets you login with an OTP over SMS. So if your phone is stolen or your SIM has been cloned, a crook could get into your PayPal account.
- insanitybit 4y agoNah, I haven't logged in in quite a few months and I got the OTP prompt.
- insanitybit 4y agoUnfortunately, it seems that Paypal requires a phone number regardless of 2FA method, and there is indeed no way to disable this insane feature. Seems like maybe a good idea for a class action lawsuit? I'm not sure what to do about that. A company shouldn't be able to do this and still meet compliance obligations. I'll have to delete my account, unfortunately. edit: 1. I didn't give Paypal my phone number so that they could use it for this. I gave it to them for banking purposes only. I wonder if this constitutes a GDPR violation? 2. I wonder if contacting their auditors would do anything. 3. Maybe email some of the politicians who care about this stuff - Ron Wyden, Elizabeth Warren?
- KingOfCoders 4y agoKey thing to understand is that auditors are paid by the company + often have side business with the company.
- insanitybit 4y agoYep, I have gone through SOC2 for a company I run, definitely aware. The idea is just to add pressure.
- hutattedonmyarm 4y agoPayPal frequently texts me an additional code either after I plugged in my OTP 2FA code or instead of it. Their 2FA implementation is… creative
- trollied 4y agoA class action lawsuit because you don't like the way that a private company, one that you are not forced to use, has designed functionality? Bit of a stretch...
- wizzwizz4 4y agoGDPR Article 5, 1(b): > Personal data shall be: […] collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
- thayne 4y agoSo it would have to come from someone in the EU.
- insanitybit 4y ago
- switch007 4y agoThis was a good reminder that I’ve been meaning to close my PayPal account for a while. It was a suspiciously easy process
- tcmb 4y agoI'm not seeing the 'login with an OTP' option that TFA complains about, also not in a private tab. I was using the fake elonmusk address from the article and also tried over a VPN pretending to come from the US (I'm actually located in the EU). Also, I don't like the condescending tone of the article, implying that everyone at Paypal is a moron who has no idea what they're doing.
- insanitybit 4y agoDo you have a mobile phone number associated with your account? I'm assuming it's not a US number - perhaps they only do this for those.
- tcmb 4y agoYes, I have a non-US number in my account, so that could be a reason, too.
- tgsovlerkhgsel 4y agoI suspect in the EU they don't do that due to the PSD2 requirement to have two-factor.
- algesten 4y agoI'm in the EU and don't see this option. Maybe the EU rules is protecting us?
- akdor1154 4y agoWhat's harder, finding the phone number of a PayPal board member, or cloning it? Either way, that's probably the quickest way to get this addressed, unfortunate you'll need to commit a felony to do it.
- jsjohnst 4y ago> finding the phone number of a PayPal board member, or cloning it You don’t need to clone it, you just change the SMSC registration to reroute delivery to the screen of your choice. If you have access, it’s trivially simple to do, but I believe it’s harder to buy your way into access these days because of some high profile news articles about the method in the past.
- bubblethink 4y agoThis has been reported before, and in my experience, it's a sales funnel/conversion thing. You will likely not see this if you go to paypal.com. Rather, this will show up when you click on the 'buy with paypal' button on a third party site. It is pretty stupid, but I also blame the general population equally. People are just so bad with any type of password management, 2FA stuff, or general web hygiene that companies resort to stupid shit like this. This is also made worse from a few different angles. In places like the US, most users use an iphone and have no idea about the differences between SMS or imessage or what any of the moving pieces are. They just know something is a 'text'. On the other hand, in places like India, the government has crippled everything to such an extent that you cannot function without SMS based 2FA. We'll be stuck with SMS based logins and 2FA for a very long time.
- magic_hamster 4y agoThis reads a bit like an alarmist scare. The only real complaint the author has, despite linking it several times, is that SMS is hackable. This is true to some extent, as SIM cloning isn't a straight forward hack and is largely based on social engineering. Still it doesn't really matter for two reasons. First, common attackers are opportunistic and they are unlikely to know your phone number. Even if they did, it would take skill and effort to clone your SIM. For this to happen you need to be targeted as an individual and that's a different scenario from random PayPal attacks. Second, PayPal aren't stupid, and they have to be aware of SIM cloning. They also have data that we don't. Looking at their data and the probability of an attacker carrying out SIM cloning, they must have decided the cost of probable cases is acceptable if and when these attacks take place. Or that it's fairly rare to actually happen. Besides, this option isn't available to all users, so there might be more going on than we realize. I understand the author is upset that they can't set a single TFA channel to be used exclusively. But I think the real gripe here is that the author feels loss of control rather than a massive security issue.
- b112 4y agoSecond, PayPal aren't stupid I presume you have loads of verifiable data, to prove this? Or is this a logical fallacy? EG, appeal to authority? Corps of all sizes do very, very stupid things.
- mackrevinack 4y agopaypal's security has always perplexed me a bit. last time i check a few years ago they still limit you to a 20 character password, which is annoying because i would rather use a passphrase so its quicker to type in but i wouldn't be comfortable using only 20 characters for something like a bank. for comparison, instagram at the time allowed 250 characters
- cyberia23424 4y agoThis seems way too unsecure. Could a bad actor exploit this with a massive list of emails and random codes? Even when you have like 5 tries from 1000000 combinations, someone's likely to get hacked with this...
- pshirshov 4y agoOf course it's possible. Very long time ago someone abused a referral program of a taxi service by registering multiple accounts just by random-guessing the code. They had badly written rate limiters so a list of 10k proxies, good broadband and a java threadpool were enough to get thousands of free rides in a couple of days.
- oktoberpaard 4y ago> most new iPhones and Android phones by default will display the actual contents of your messages on the lock screen On iPhones by default the contents are only shown after your face is recognized by FaceID. That being said, I don’t like to have one factor authentication tied to my phone number, especially not when I’ve enabled two factor authentication in the settings. I guess the logic behind this decision is that they see your password as the weakest link, so for them 2FA is not so much about having a second factor, but about not being able to use the password as the only factor.
- Havoc 4y agoIn the UK there is currently a string of people getting cleaned out 100% after having their wallet and phone stolen at gyms and its suspected this - 2FA visible on locked phone - is the main issue
- zoover2020 4y agoAny more details on that? Sounds interesting from a tech perspective
- Havoc 4y agoThey're cracking open gym lockers, grabbing phone and bank cards, using knowledge of the bank name, person name and access to the SMS OTP visible on phone to relink a fresh cellphone banking app. That's the speculation anyway & there are some gaps in the theory. But yeah basically they're gaining access to the entire bank a/c and doing thousands of damage instead of usual credit card stuff which is obv protected legally
- CTOSian 4y agoIt is the shite way the Paypal and I think Amazon does this : they put the code at the start of the SMS, other OTP providers sent it in the middle/end of the SMS, so even if someone set the display of text messages as 'enabled' on the locked screen , they are truncated and you can't see the code (but not in the case of Paypal)- you need to unlock the screen to read the full text YMMV as some SMS apps display it full.
- kkfx 4y agoI do not hate passwords but those who hate them and push with such excuse the mandatory use of smartphones. I do HATE those who state a crappy Android/iOS OTP app is safer than an offline hardware token just because thanks to their app they also ask for permission for extra stuff like accessing phone location history, contacts etc all with plausible excuses (that's happen in most EU countries with banks crapplications) and so on. ANYTHING tied to closed-source connected platforms can't be secure. That's is.
- b112 4y agoI find it absurd, that after I login, or buy something, they send me an email saying: -- Since we recognize this device, you’ll continue to stay logged in, so you can skip typing your password during certain activities such as check out. -- What?! And there is no opt out, except for you to set a cookie saying you don't want that. Hello?! How will I have a cookie for that at $random.place? They literally care nothing about security.
- fenesiistvan 4y agoI have the exact opposite experience. I always click on the "Trust this browser" button, but have to 2FA auth again after 2 minute. Another annoying thing: switching back to English language every time (my OS and browser is English, they are using geoip instead)
- b112 4y agoOnce you have market dominance, I guess you just need to barely get the job done, to stay in vogue.
- npc12345 4y ago
- orangepanda 4y agoReminds me of how on Stripe’s dashboard I keep getting prompted for a password; I can just click cancel and everything continues working fine. Anyone knows what’s up with that?
- Havoc 4y agoThat's pretty wild. I've seen mechanisms on some sites like my energy provider...but I doubt the crooks feel like paying my energy bills so whatever
- supernova87a 4y agoI am similarly annoyed by Bank of America. They allow you to enroll a Yubikey for login, making it seem like they have a high level of security. But then on the login screen they moronically offer a one click bypass of it, asking if you want to login by SMS instead. What's the fucking point of a Yubikey then!?
- noahtallen 4y agoYeah… are there any banks that have actually good security? Seems like they’re all surprisingly terribly out of date. Similarly, Amazon does not offer a way to remove SMS from your account once it’s added, even after setting up another OTP method.
- criddell 4y agoFrom the bank's point of view, it's good enough security. My wife and I had money stolen from our Wells Fargo checking account and I had a bunch of questions for them. Somebody from higher up eventually called me and when I got to the point about asking why the password was limited to 12 characters (they should be storing a hash and not the password) she told me to stop worrying about it because I'm not responsible for fraud. > Amazon does not offer a way to remove SMS from your account once it’s added Even if you no longer have that phone?
- genocidicbunny 4y ago> she told me to stop worrying about it because I'm not responsible for fraud. I'd start asking to be reimbursed for the time I have to waste on dealing with the fraud then.
- thayne 4y agoFor chase the only option for 2FA is SMS.
- supernova87a 4y agoAnd even the login problems aside, I'm even more galled by the fact that our system of bank checking accounts allows anyone to fat finger mistakenly debit (ACH) money from your account, and it's up to you to discover and get that reversed. I know all the historical reasons, etc. but this is still ridiculous to me. All the security in the world, and I still have to worry whether my brokerage funds are missing some each month.
- TonyTrapp 4y agoAsk HN: Is anyone else seeing a steep increase in CAPTCHA and SMS verification prompts on PayPal lately? Yesterday alone I was sent two SMSes and had to solve at least one CAPTCHA. All from the same machine that I always use. It's really getting to a point where I rather use an alternative payment service when it's possible to do so. Edit: Oh and everytime that happens I get a mail that there is a login with a new device from "dusseldorf nw de". No, I don't live in Düsseldorf, not even close. The fact that they misspell the name and that their GeoIP is reliably off doesn't inspire any more confidence.
- manmal 4y agoYes, I’m having the same issue. I thought it’s due to my recent accidental access with a VPN.
- yoaviram 4y ago> The only recourse in the meantime is to close your PayPal account. Except PayPal does not monitor the only email address it lists on its own website, the one designated for the purpose of sending them data deletion or access requests: https://twitter.com/ConsciousDigit/status/1587824741766889477?t=j1OOiJSB1Tg9x_SC5DkMwA&s=19 https://twitter.com/ConsciousDigit/status/158782474176688947... (Source: my nonprofit runs YourDigitalRights.org where we make it easy to send the likes of PayPal data deletion request under the GDPR / CCPA etc)
- andyjohnson0 4y agoOn my phone (Android, Moto Edge) the contents of text messages are hidden on the lock screen. I'm pretty certain that this is the default behaviour in recent versions of Android that I've seen. So, at least for me, anyone who stole my phone for the purpose of hacking my paypal account would still need my fingerprint or unlock pattern. Someone with a non-smart phone will have a different experience though. And yeah, sms is a poor choice from a technical pov but i can see why they did it for a mass-market service.
- justinclift 4y ago> anyone who stole my phone for the purpose of hacking my paypal account would still need my fingerprint Wouldn't your phone be covered in your fingerprints? Plenty of easy ways to pick up fingerprints from things like that. eg sticky tape + lead pencil, etc.
- ChoGGi 4y agoI've got an older phone so my fingerprint scanner is on the back. The finger I use for that is different from the screen one. But yeah thanks PayPal
- justinclift 4y ago> The finger I use for that is different from the screen one. So... you don't hold your phone with your other fingers? ;)
- FinnKuhn 4y agoNot sure if it is the default, but you can definitely have it set up this way on iPhone to an I would recommend you do.
- fatneckbeardz 4y agoi have yubikey (usb hardware dongle) for paypal and it doesnt have this one-time option? cannot reproduce bug
- witrak 4y agoStrangely, half of the discussion concentrates on the arguments for and against the alleged (in)security of the PayPal solution in general cases while obviously the solution quality can be decided in a specific context. At the same time nearly nobody addressed the real source of PayPal's stupidity: the fact the "feature" can't be permanently disabled.
- ergonaught 4y agoPayPal has been doing a number of thoughtless things in this area recently. They are determined that my devices are “trusted”, despite the owner of those devices not trusting them at all. They are continually trying to persuade me to stop using my passwords and such. I mean it’s only direct access to withdraw funds from my bank account, why would that need to be secure, amirite? Mystifying.
- amluto 4y agoSadly there’s another system that really should know better with terrible 2FA policies: Amazon AWS. The mechanism for protecting an AWS root account is not quite as bad as PayPal, but it’s not much better. AWS should offer the ability to enroll multiple second factor devices and to configure a policy for what subsets of them can log in. But they don’t even come close, and their actual capabilities are far worse than, say, Gmail or GitHub.
- insanitybit 4y agoThe thing is that the root account at least falls back to an email, not your phone. But yeah it's insane that they don't allow multiple 2FA tokens to be registered.
- amluto 4y agoThe email fallback is of rather dubious value if your email is hosted in AWS or uses Route53.
- insanitybit 4y agoI'm not sure I understand, can you elaborate?
- Aaron2222 4y agoIf the domain of the root account's email address has it's DNS or email handled under that AWS account, then any IAM user that has access to that could intercept the email and use that to gain access to the root account.
- insanitybit 4y agoSo you set up an AWS account with some email xyz@example.com and then you transferred that domain to be managed in that same account? That sounds like a niche and terrible idea tbh, why would you dot hat?
- andyjohnson0 4y agoHaving just added a yubikey as a PayPal 2FA device it niw appears that PayPal only supports one key. Not great.
- yumswiss 4y agoI guess there is a trade off here of having strong security but then users being completely locked out or falling back to SMS which defeats the purpose of stronger auth like Yubikeys. There should at least be an option to disable SMS for auth. Another option is to call up your telco and ask them to only port a number if you are physically present and verified in a store. This wouldn’t protect against an insider at the telco, but at least common threats.
- bheadmaster 4y agoI'm glad I've never used PayPal, and I probably never will. Their decision just seem to go from bad to worse.