7 ms·
What did you expect? VPN is a favorite tool for all sorts of frauds. If your true IP is obscured by a VPN this is just a red flag for PayPal or any other payme
by dmk23 14y ago
What did you expect? VPN is a favorite tool for all sorts of frauds.
If your true IP is obscured by a VPN this is just a red flag for PayPal or any other payment processor. Especially if you happen to share the same IP as someone committing actual fraud - which is very much likely if you are using public proxies. Very few legitimate customers pay over VPN.
Do not use VPNs if you do not want to be flagged or blocked.
EDIT1: In response the comments, no I am not sarcastic at all. The number of legitimate VPN users (among general Internet population, not HN) is miniscule and does not justify the financial risks involved. If you are using VPN you are seen as hiding something and flagging/blocking you from sensitive transactions is an obvious response.
EDIT2: I am talking about public VPNs that can be anonymously abused by anyone - where you'd be likely sharing IPs with criminals. By all indications that's what OP was using if he wanted to hide himself. If you use VPN from work or coffeeshop you'll be identified by some innocuous-looking residential / corporate IPs.
- nkassis 14y ago"Do not use VPNs if you do not want to be flagged or blocked." I hope that was sarcastic. I do understand that legitimate VPN users are probably a small percentage of Paypal total user base and that a large portion of frauders use VPN (I don't know what percentage of VPN users who paypal are trying to commit fraud, could be the majority, I don't know) But using VPN should cause you to get flagged. It has a very legitimate use. A lot of people use them when on the go to protect themselves while on wifi. I use a VPN all the time when I'm not at home (well aside from working at home which I do over vpn). I don't see why I should expose myself to avoid being flagged.
- rhizome 14y agoI don't see why I should expose myself to avoid being flagged. Don't you explain this yourself? If few PP users use VPN and a large portion of fraudsters use VPN, I think we can chalk this one up to cold math despite the is/ought problem.
- untog 14y agoI don't see why I should expose myself to avoid being flagged. Because it isn't worth PayPal's time to cater to you. Seriously, go and use a different provider. I know that sounds incredibly flippant, but it's the reality- PayPal will stop blocking VPNs when it is financially prudent for them to do so. Of all companies, would you expect anything different from PayPal?
- binarycrusader 14y agoThe number of legitimate VPN users (among general Internet population, not HN) is miniscule... VPN usage is increasing, not decreasing, even if as you claim, a "miniscule" group of users are using VPNs it's a dumb move by PayPal. Many corporate environments require the use of VPNs for mobile equipment (laptops, phones, etc.). Now imagine a business that uses PayPal and requires the use of VPNs for all of their PayPal account managers. The argument that most fraudsters use a particular technology so we should ban use of that technology is myopic at best.
- uxp 14y ago> Many corporate environments require the use of VPNs And if they do, you can be sure they aren't going to be using a VPN provider outside of the country to get around geolocation restrictions, or to mask the originating IP. They'll be sending their outside data _into_ a secure intranet, not back out into the general net. Basically, the OPs only mistake isn't using a VPN, it's masking his original location, intentional or not. It's a stupid rule by PayPal, but it's not very surprising that they'd follow a "common patterns of fraud" checklist word for word. Thats what they do.
- dangrossman 14y agoVPN'ing to your office isn't going to get your account flagged. PayPal isn't inspecting network data for signs of tunneling or something. They're banning people that connect from public anonymizing VPN services because they're used for attempted fraud on their service every single day.
- briandear 14y agoAnd you know that how??
- dangrossman 14y agoFirst, by reading the TOS. All VPNs are not prohibited, only anonymizing proxies. Second, by having logged into PayPal through a work VPN without having the account flagged.
- notlisted 14y agoYou're severely mistaken. Using a VPN is a pretty smart move when you access your paypal account in a coffee shop on WiFi. I always use my VPN when I'm logging on to sensitive accounts (FB, Google, bank or corporate network) in public locations (hotels, airports, coffee shops). In fact, my company demands it. I do wonder which VPN the OP used. If he use one of those anonimizing VPNs that is popular with bittorrent downloaders, spammers and the like, then he shouldn't be surprised if Paypal's fraud detection unit was suspicious. Feel we're not getting the whole story here.
- ewillbefull 14y agoWhy use a VPN if you're accessing PayPal over HTTPS?
- agwa 14y ago> Why use a VPN if you're accessing PayPal over HTTPS? There are too many ways things can go wrong even with HTTPS. First, how do you get to PayPal? Do you enter www.paypal.com or https://www.paypal.com https://www.paypal.com? If you do the former you can be sslstrip'd [1]. You can check for the padlock icon (plus the correct domain name in the URL) but what if you forget? All it takes to be pwn'd is forgetting once, and if you're hurrying to get a bid in on eBay you'll probably forget. What if you do go to the HTTPS URL but get a certificate warning? I'm sure most HN users would do the right thing and reject it, but for ordinary users it's probably easier to just have a corporate policy that says "always use the VPN when on the road." And even if you always go to the HTTPS URL and reject invalid certificates, what if the site operator does something stupid like include non-HTTPS content or use session cookies without the secure flag? HSTS is making things much better, but it's not a panacea - you have to have visited the site recently from a trustworthy connection for it to work. I still say VPN is better. [1] http://moxie.org/software/sslstrip/ http://moxie.org/software/sslstrip/
- qu4z-2 14y agoJust to expand slightly: If you type www.paypal.com, click login and then check for the padlock, it may very well show up. https://www.paypa1.com https://www.paypa1.com is a perfectly valid site, and you're accessing it over ssl, after all.
- agwa 14y agoWhat you're saying may be PayPal's reasoning but there needs to be some pushback on that. There are very legitimate uses of VPNs, not for providing anonymity, but for tunneling your way out of hostile networks. Everyone should use a VPN when they travel so they don't have to worry about things like insecure WIFI [1] or hotels injecting ads into web pages [2]. It would be reasonable for PayPal to forbid use of anonymous VPN services, but not VPN services like Cryptoseal (a YC company) or Securetunnel (by the OpenVPN folks) which are meant for legitimate activity. [1] Remember, not all websites uses HTTPS, and even the ones that do might still be insecure (for example, by using non-secure cookies). Plus you have to constantly check to make sure you're accessing the correct HTTPS URLs or you can be sslstrip'd. It's much easier and safer to just use a trustworthy VPN. [2] http://justinsomnia.org/2012/04/hotel-wifi-javascript-injection/ http://justinsomnia.org/2012/04/hotel-wifi-javascript-inject...
- polemic 14y agoSure, but if you're security concious then you're going to notice the lack of SSL. Meanwhile, you've added a VPN provider into the chain. And you still have to keep an eye on the SSL status considering that, hey, maybe they get MITM'ed? If the site is delivered via SSL, I just can't see what a VPN provides other than anonymity, which is not security.
- agwa 14y agoI've gone into more detail on what can go wrong with HTTPS here: https://news.ycombinator.com/item?id=5515967 https://news.ycombinator.com/item?id=5515967 True, you have to trust your VPN provider, but at the end of the day you have to trust someone, including the many certificate authorities on which HTTPS relies. But a good VPN provider is way more trustworthy than the types of networks you encounter when traveling. You should still check for SSL when using a VPN but you don't need to be as vigilant about it. This is beside the point, but VPNs really don't provide anonymity. Many VPN services log and comply with court orders. Some VPN providers claim to not keep logs but you have no way of knowing if that's true. If you need anonymity you use Tor.
- latj 14y agoDo you actually have usage data for some public proxies or just making it up as you go?
- briandear 14y agoSorry, but you obviously have never run a multinational internet company, nor do you seem to know anything about corporate VPNs. Nearly every large corporation in the world uses VPNs for employee computers. The "majority" of VPN users are not people trying to "hide" illicit activity, the majority are highly security conscious or they're road-warriors on questionable hotel connections among a variety of other non-criminal use cases. When we started icouch.me while in Shanghai, China, PayPal flagged my account and constantly locked it even though I jumped through their hoops "proving" our legitimacy and that no transactions (at that time) were actually China-originated. Just the simple fact that I logged on from China caused us to get locked out of our payments for up to weeks at a time (even though they still had no problem collecting the fees from our still-incoming transactions.) Then once I got that nonsense sorted, I started traveling more frequently for the company. So when I arrived in New York City, once again I was locked out of my account for 5 business days for "security" reasons, even though we've never had a single chargeback or any sort of security complaint or issue. Then I worked out of Texas for several weeks and once again, my account was locked. Despite the fact that we had the same US corporate bank account since 2010 (when the company was first founded.) By using a VPN, I was able to ensure my US "presence" to manage our business without PayPal's ridiculously retarded IP-detection security lockouts. I've since told paypal to go suck an egg and we use Stripe for everything. When a company like PayPal can hold my operational funds hostage for weeks at a time with no way to clear it up expeditiously, then they just became thieves. They're making interest off of MY money while I can't access it. If they were "really" worried about security, then they'd block all transactions as well. But no, they have no problem taking money. Interestingly, the credit bureau websites are locked to US only IPs as well. So if you have a subscription to some credit-monitoring service, they'll gladly take your money even if you can't access their services with a non-US IP address. Those folks can all go to hell. It isn't my problem that some russian and nigeria scam artists have a tendency to cause problems. The IP address isn't the issue -- it's the security of their overall application. They're using geo-location as a shorthand for actually doing their job in securing their site. Interestingly, I can access my US Chase bank account, my Simple account, Fidelity Investment account, Stripe from around the world without any sort of of VPN, yet somehow PayPal can't seem to figure out how to get security or customer service right.