3 ms·
A million dollars and a public paypal email address (check the screenshot). I really hope he has a secure password.
by mcobrien 15y ago
A million dollars and a public paypal email address (check the screenshot). I really hope he has a secure password.
- redthrowaway 15y agoI'm more concerned about his having a secure, patched server and his website having no vulnerabilities. Non-idiotic passwords are hard to guess; SQL injection is easy.
- dangrossman 15y agoEven if someone else were to log into his PayPal account, there's no damage they could do. They can't withdraw his money to another bank account; adding a bank account takes 3-4 days while you wait for PayPal to deposit some money which you confirm the amount of to prove ownership. All the 'hacker' could do is send the money to another PayPal account, which is trivially reversible as long as someone notices in less than 3-4 business days, before the receiving account can complete a withdrawal to a pre-confirmed bank account. That's all assuming the account isn't immediately locked. If you log into a PayPal account from a different computer and far away location, they'll usually lock the account until you call in to say that's you and not a hacker doing so. At the end of the day, PayPal's core business is fraud detection, not payments. Anyone can do payments; they're just a software layer on top of two Wells Fargo and Chase merchant accounts. Your PayPal account e-mail address should be considered public knowledge as soon as you put up a PayPal button. It's given out with every transaction and, if you don't use PayPal's encrypted button generator, it's in plain text in the payment form or URL.