TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

PayPal Denies Providing Payment Information to Twitter Username Hacker

177 pointsby fraqedover 11 years ago

20 comments

ck2over 11 years ago
PayPal is lying or playing dumb and here&#x27;s why:<p>Ask them if the customer service agents can see the last four or if they have to enter them first before the customer&#x27;s records come up.<p>They can see the last four right away.<p>Call paypal and ask them which card you have on file, you cannot remember. The agent can give you last four to identify it.
评论 #7152843 未加载
评论 #7151847 未加载
评论 #7153461 未加载
lipanskiover 11 years ago
In my opinion, the hacker who hijacked this guy&#x27;s Twitter account didn&#x27;t have had ANY interest in explaining how he got to it, besides creating a hoax to confuse and divert attention. Just think about it, in just one email he puts the blame on both GoDaddy, for doing phone validation over unsecure criteria (like credit card numbers), and PayPal (for giving out the last digits of the card number to a complete stranger). There might be some truth to it (GoDaddy&#x27;s phone validation sucks and GoDaddy sucks altogether), but I&#x27;ve read the original HN thread and the majority of comments are directed against GoDaddy or PayPal, rather than the real perpetrator. There are a million ways to hijack someone&#x27;s account - including but not necessary by exploiting flaws of GoDaddy &#x2F; PayPal - but I wouldn&#x27;t trust the hijacker to kindly explain to me how he <i>actually</i> did it.
评论 #7150477 未加载
评论 #7150515 未加载
评论 #7150483 未加载
评论 #7152739 未加载
评论 #7154894 未加载
bushidoover 11 years ago
What&#x27;s interesting is in the original &quot;i got hacked&quot; post[0]. The email from the hacker says that he called paypal and posed as an employee.<p>That may not be tough to do, i.e. if you call a call center, select the wrong department and request an internal transfer, it is quite possible that the person receiving the call would not be able to distinguish between an internal call or a customer call.<p>So if the hacker told them he was Jack from xyz department, who would know the difference, better still, would they log the call at all?<p>The alleged breach could in this situation be quite easy.<p>[0] <a href="https://medium.com/p/24eb09e026dd" rel="nofollow">https:&#x2F;&#x2F;medium.com&#x2F;p&#x2F;24eb09e026dd</a>
评论 #7150910 未加载
评论 #7151295 未加载
评论 #7150878 未加载
评论 #7150699 未加载
评论 #7150915 未加载
ColinWrightover 11 years ago
<p><pre><code> &gt; PayPal Denies Providing Payment Information &gt; to Twitter Username Hacker </code></pre> Well, they would, wouldn&#x27;t they.
评论 #7150262 未加载
评论 #7150187 未加载
parandroidover 11 years ago
Perhaps the cracker is actually employed at PayPal for real? :) This thought amuses me, since it&#x27;s a scenario with no leaks outside the circle of PayPal employees, yet it gives the opportunity to the bad guy to gain the info necessary for the deed.
slack3rover 11 years ago
<a href="http://thenextweb.com/insider/2014/01/30/godaddy-accepts-partial-responsibility-social-engineering-attack-ns-customer-account/" rel="nofollow">http:&#x2F;&#x2F;thenextweb.com&#x2F;insider&#x2F;2014&#x2F;01&#x2F;30&#x2F;godaddy-accepts-par...</a><p>&quot;Our review of the situation reveals that the hacker was already in possession of a large portion of the customer information needed to access the account at the time he contacted GoDaddy. The hacker then socially engineered an employee to provide the remaining information needed to access the customer account. The customer has since regained full access to his GoDaddy account, and we are working with industry partners to help restore services from other providers. We are making necessary changes to employee training to ensure we continue to provide industry-leading security to our customers and stay ahead of evolving hacker techniques.&quot;<p>It&#x27;s likely the attacker obtained credit card info from GoDaddy rather than PayPal.
评论 #7153420 未加载
MattyMcover 11 years ago
Alternatively, if this hacker had a method different than what he&#x2F;she described to obtain the necessary information, it would make sense that he&#x2F;she would describe a false sequence of events in order to throw the account holder off the trail.
RexRollmanover 11 years ago
I am more interested in Twitter&#x27;s response to all of this.
评论 #7150511 未加载
评论 #7150490 未加载
Frostbeardover 11 years ago
All the hacker claims to have obtained from PayPal is the last four digits of the credit card number. Perhaps this failed attempt they mention was them asking the hacker to provide the complete credit card number ending in XXXX as a form of verification?
poizan42over 11 years ago
Well PayPal once flagged a non-existent transaction on my account as suspicious. I had to call them to get it sorted out. The fact that something like that can happen surely doesn&#x27;t help me trust PayPal...
评论 #7153485 未加载
chris_wotover 11 years ago
I&#x27;d be reporting them to the authorities. Then I&#x27;d sue them, and get the recording in discovery.
评论 #7150541 未加载
homersapienover 11 years ago
Why doesn&#x27;t Twitter simply quarantine the handle until some sort of dispute resolution is completed? Oh wait, Twitter doesn&#x27;t &quot;do&quot; customer service, so forget about any sort of common sense solutions.
jontasover 11 years ago
Shouldn&#x27;t it be easy enough for Twitter to just return the handle to the original owner? I guess Twitter has to cover their own ass to a degree, and it is possible the original owner is making up this story and actually sold the Twitter handle (though I suspect this would be against Twitter&#x27;s policies).<p>However, based on what I&#x27;ve read, the people involved, and Occam&#x27;s Razor, I believe the published story. Twitter should transfer ownership of the handle back to Naoki Hiroshima, do the right thing, and get some good press at the same time.
squigs25over 11 years ago
Paypal&#x27;s value lies in it&#x27;s network and it&#x27;s trustworthiness. There is no way in a million years they would divulge a f<i></i>*-up of this magnitude unless there&#x27;s was cold hard proof.<p>But I think there is pretty convincing proof, and I think if anything, this makes them less trustworthy than if they had come out and accepted partial wrong doing.<p>The &quot;hacker&quot; had no incentive to lie; the ace was in his hand.
评论 #7152529 未加载
thehmeover 11 years ago
I am very interested in what comes out of this. When I read Hiroshima&#x27;s blog post, I was getting chills thinking how angry I would be if I could not get into my own accounts thanks to someone taking over them simply by exercising human engineering tactics. Big and small companies need to implement 2-step verification, or better, and never give out information.
dutchbritover 11 years ago
Alternative option, thief has an insider at PayPal, or even worse, works at PayPal.<p>But PayPal is probably just trying to cover their ass.
评论 #7150730 未加载
melindajbover 11 years ago
PayPal records every call, 100% and also all the screen captures of the agent answering the call. So, either they&#x27;re telling the truth, or they&#x27;re lying. Not sure how anyone could tell the difference. but I guarantee you, they listened to the call.<p>I can&#x27;t see why a hacker would actually give his secrets away.
enscrover 11 years ago
I didn&#x27;t expect them to come forth and accept it. If it&#x27;s an employee mistake, and not a standard broken process, they can erase the tracks.
评论 #7150816 未加载
sdaityariover 11 years ago
Now who do we blame?
评论 #7150406 未加载
mpermarover 11 years ago
As if they would say if they were :-)