TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

What’s going on with security at PayPal?

216 pointsby levymetalover 2 years ago

29 comments

oefrhaover 2 years ago
&gt; So I have a complex password and TOPT to protect my account. Forget these, because PayPal’s default method of login is now a one-time code sent via SMS. Yes, the very same medium that is generally considered unsafe for two-factor authentication is used by PayPal as the only factor; bypassing both password and TOPT for what appears to be full access to your account. You cannot disable this method of login, and you cannot remove your phone number from your account.<p>&gt; Tested in Incognito – as soon as you enter an email address to log into PayPal, an SMS is immediately sent and the phone number is revealed.<p>Just tested, can&#x27;t reproduce. I get the standard email =&gt; password =&gt; TOTP flow. Also happened to have logged in yesterday on a new device, so pretty sure nothing changed between the blog post and now, at least not for me.<p>Maybe it&#x27;s something being rolled out to more customers at the moment.
评论 #32615945 未加载
评论 #32617184 未加载
评论 #32618123 未加载
评论 #32617788 未加载
paultopiaover 2 years ago
I have never once given one of these valley payments companies my bank account information, and this sort of garbage is why. If I need to pay something via PayPal, Venmo, or whoever the hell else, I&#x27;ll use a credit card and happily eat a 3% fee for doing so, and that&#x27;s the price I pay to be able to tell Chase or Amex to handle it when some fraudster gets at my info rather than watch my bank account get drained.
评论 #32616283 未加载
评论 #32616284 未加载
评论 #32642353 未加载
评论 #32616306 未加载
m-eeover 2 years ago
The past week I&#x27;ve received two invoices for &quot;bitcoin&quot; in my rarely used paypal account. More deviously, the notes for the invoice contain the phone number to a fake paypal support center run by the scammers. So if you were savvy enough not to pay the invoice they might still steal your info when you call to dispute.<p>There&#x27;s no way to report it through their website, because it&#x27;s not a completed transaction. I didn&#x27;t feel like waiting on hold so I sent a chat message and forwarded the email to phishing@paypal. One invoice still remains in my activity but says &quot;no longer available&quot; when I click on actions.<p>Already had me more paranoid about their security and now this comes out. My account still seems to be password + SMS thankfully.<p>EDIT- I didn&#x27;t know you could even set up TOTP. Last time I used paypal SMS was the only option for 2FA.
评论 #32617262 未加载
rocquaover 2 years ago
I recall PayPal had a maximum password length when I first made my account.<p>Moreover, PayPal is the only financial institution I know that regularly sends emails with a juicy &quot;click here to login&quot; button. All other institutions are trying to teach &quot;don&#x27;t click links in emails that claim to be from us, only phishing mails will contain links&quot;.<p>I think imma close my PayPal.
hedoraover 2 years ago
If true, this is borderline criminal incompetence.<p>However, I can&#x27;t reproduce the issue described in the article.
评论 #32615770 未加载
mimimi31over 2 years ago
I recently created a new PayPal account. Got locked out almost immediately after adding 2FA via TOTP. First login worked, on the second login I just got a message that they were unable to verify it&#x27;s really me. When contacting customer service, I was told that this is a known problem and I should just write them an email so they can remove 2FA from my account and then readd it a few days later myself.<p>When signing up it also told me my provided contact details weren&#x27;t correct because I had a forbidden special character in the password that I typed in the previous form. Took a while to figure that one out.
lokedhsover 2 years ago
After reading the discussion here I decided to delete my paypal account. So I attempted to log in, and it required me to provide a 2FA authentication using SMS. Problem is that I don&#x27;t have access to the registered number anymore.<p>So now I can&#x27;t log in, which prevents me from deleting the account.
评论 #32617230 未加载
评论 #32616917 未加载
评论 #32616838 未加载
WAover 2 years ago
I had the exact same flow: received a SMS instead of asking for my TOTP, despite having enabled it.<p>I think I removed and re-added my Authenticator from PayPal’s settings and now it works again, never sending the SMS.<p>(This was about a year ago.)
throwawybllionover 2 years ago
No strong disagreements with the article, however... It&#x27;s TOTP, not TOPT (a mistake made throughout the article). I am skeptical of the qualifications and much of the basis for complaint.<p>Using anything based on a phone for sole verification is inexcusable in any situation, but is that really the case with PayPal? I have an account with MFA and... I don&#x27;t think that&#x27;s true
评论 #32615975 未加载
httpzover 2 years ago
This exact thing happened to me few months ago. There just wasn&#x27;t a way to disable this One Time Code login either.<p>I doesn&#x27;t seem to be happening right now though.
radicalriddlerover 2 years ago
Wow I had the same SMS yesterday and I actually just ended up completely closing my PayPal account because it seemed so ridiculous
bombcarover 2 years ago
2factor but with the convenience! We’ll invent zero factor!
JohnFenover 2 years ago
I&#x27;ve been getting spammed with these SMS codes. They&#x27;ve been baffling me because I use MFA, and didn&#x27;t understand what mechanism could be sending me random codes. I&#x27;m glad I know now.<p>I hope PayPal fixes this shit soon. Not only is this a serious security problem, but the texts are incredibly annoying.<p>Oddly, I can&#x27;t make it happen myself -- I don&#x27;t get the screen being discussed -- but clearly some criminal somewhere does. Must be limited to certain geographic areas?
JonathanBeuysover 2 years ago
This confuses me about discussions like these on HN:<p>On the one hand, there are so many stories on HN complaining about incompetent and dystopian security practices in the financial industry.<p>And many tips on how to cope with it. Like not giving PayPal your bank account, rather pay 3% to put a credit card between PayPal and your bank account. And to keep your phone number secret to avoid sim swapping and PayPal exposing it.<p>It seems to be a fight between customers who are supposed to try and hide as much data as possible from the companies. Because that data causes a threat to you. And the companies that try to get as much data as possible.<p>On the other hand, cryptographic solutions which put the user in control and do not expose any data to the outside world are frowned upon. To me, it seems the logical solution. I want a private key, that only I know. And to be able to sign transactions with it without exposing any data.<p>If such a solution based on cryptography would be widely used, I would hold a smallish amount of buying power on my &quot;crypto wallet&quot; and use that for day to day transactions. And regularly refill it directly from my bank account.<p>The best of both worlds: For my smallish day-to-day transactions, I am in full control of the security and privacy. And my savings stay on my bank, completely shielded from my day-to-day transactions.<p>Why does everyone on HN hate this approach?
评论 #32616172 未加载
评论 #32616196 未加载
评论 #32616165 未加载
评论 #32616175 未加载
评论 #32616313 未加载
muppetmanover 2 years ago
My wife has been getting a bunch of these today. I still don&#x27;t see what the potential problem is if an attacker has my wife&#x27;s email (which I can imagine has been made public by 100 data breaches etc) and phone number. A bad actor can&#x27;t use those to log into Paypal? You still need to GET the text message code. Is the risk a SIM Swapping attack?
评论 #32615618 未加载
评论 #32615670 未加载
评论 #32615693 未加载
stjohnswartsover 2 years ago
Anything that involves money or things of value I use my yubikey for. If they don&#x27;t provide 2FA via that method I just look elsewhere. If it&#x27;s a magazine or comments section? who cares, use a mozmail temp address.
评论 #32617552 未加载
babyover 2 years ago
Haven’t used paypal in like 10 years. It was such a bad experience bad then that I’ve done everything to avoid using it. Wondering how people are using paypal nowadays
laundermafover 2 years ago
“Guessing the 5 missing digits” isn’t exactly trivial, there are thousands of combinations. In the US you might figure out the area code, but good luck if the person isn’t a local (or if you just entered a random email).<p>Also I don’t see the rest being true. If I only enter my phone number, it still asks for the password. And I can’t reset my password unless I also enter my email address.<p>I do agree though that probably they should just email me instead if I forgot the password.
richbellover 2 years ago
I wonder if PayPal uses Twilio to send these codes.
评论 #32619124 未加载
评论 #32615889 未加载
dreadlordboneover 2 years ago
I just did a test in an incognito window and I don&#x27;t get an SMS message, but just a regular password prompt.
lambdasquirrelover 2 years ago
Believe it or not, PayPal has finally set up security keys and authenticator apps as a 2FA. This must have been recent. I remember trying to do this a year or two ago, after someone cracked my LinkedIn password (but not the 2FA), and 2FA was not available on PayPal at the time.
评论 #32618301 未加载
quickthrower2over 2 years ago
This happened to me. They somehow got my password changed (maybe reset?). But no money taken. Had to call to get it resolved. Now added 2FA.
presto8over 2 years ago
I just tried it on my account (private browsing window) and confirmed that 5 digits of my phone number were revealed.
fmajidover 2 years ago
PayPal’s stubborn refusal to implement U2F tells me all I need to know about their security: it’s pure theater.
kaeructover 2 years ago
I cannot reproduce this on my account. Could it be specific to the US?
tylergetsayover 2 years ago
I received the same text this morning
devoutsalsaover 2 years ago
My recent PayPal experience:<p>- try to pay for rental car in Mexico<p>- transaction declined<p>- get email saying account permanently locked<p>- get 2nd email w&#x2F; link to unblock (says click on unblock notification)<p>- no notification<p>- chatbot asks if I want help, redirects me to help page<p>- help page contains none of the following: unblock, unlock, locked<p>- chatbot asks if I still need help, says I have to call<p>- call link redirects to account home page
评论 #32616045 未加载
评论 #32616386 未加载
yjftsjthsd-hover 2 years ago
&gt; PayPal’s default method of login is now a one-time code sent via SMS<p>&gt; You cannot disable this method of login, and you cannot remove your phone number from your account.<p>Well. I&#x27;m used to thinking poorly of PayPal, but that&#x27;s remarkable. Wonder if someone lost money if they could take PayPal to court on account of what could be argued as negligence? (Or maybe not; IANAL for a reason.)
评论 #32617233 未加载
prvitover 2 years ago
This is silly. Nobody is going to sim swap you to steal your paypal funds, getting the money out is way too difficult.
评论 #32616207 未加载
评论 #32616343 未加载