TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tell HN: PayPal now allows to bypass 2FA with a SMS login

2 pointsby ivmover 2 years ago
Last week I started receiving SMS with PayPal security codes and then got a notification about someone adding a card to my account and withdrawing $1.5k.<p>2FA was disabled because it doesn&#x27;t work in Safari (including logging in from their iOS app, imagine this), so I blamed myself, turned it on, reported the unauthorized transaction to PayPal… and had $1.5k more withdrawn to a newly added card two days later!<p>Apparently, there is an option of an SMS-based login(!!!) where they send you a 6-digit code that allows for a login without 2FA: https:&#x2F;&#x2F;www.paypal-community.com&#x2F;t5&#x2F;Managing-Account&#x2F;How-do-I-disable-one-time-codes&#x2F;td-p&#x2F;2835147<p>I don&#x27;t know if the SMS gateway to my Chilean number is leaky or if they just brute-forced the code, but here we are. Also, no confirmation is needed to add new cards and make withdrawals even when 2FA is enabled.<p>(Yes, I know keeping money at non-bank payment services isn&#x27;t good, but withdrawing it from there meant a conversion to my local currency which nowadays devalues much faster than USD. Greed got me.)

no comments

no comments