TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Bypass PayPal's Two-Factor Authentication

112 点作者 seanponeil将近 11 年前

10 条评论

ashishgandhi将近 11 年前
I&#x27;m glad this was found independently and reported. While I was at PayPal I had started email threads about it but nothing was done. I am sure I was not the only one there who &quot;discovered&quot; this. For instance, even if you have 2FA you can add PayPal to Uber as if you never had 2FA.<p>The other big issue with their 2FA authentication is that it really isn&#x27;t two factor. You can say you don&#x27;t have the token and instead can answer security questions. Two factor is supposed to be something you know plus something you have. &quot;Falling back&quot; to security questions is basically just relying on things you know.
评论 #7942786 未加载
评论 #7943402 未加载
评论 #7943210 未加载
rdl将近 11 年前
Based on this timeline, I don&#x27;t understand why Duo didn&#x27;t go public on 2014-04-28 when PayPal began being weasely about their bug bounty program. This probably would be better for users for two reasons: one, in the past 2 months, this bug may have been exploited in the wild, and two, it would make it easier for users to make informed decisions about which payments providers to use in the future (as well as which 2fa providers are technically competent).
评论 #7942748 未加载
评论 #7943520 未加载
anujnayar将近 11 年前
Hey guys - its Anuj from PayPal. I just published a blog post that explains what we are doing to address this. <a href="https://www.paypal-community.com/t5/PayPal-Forward/Working-with-the-Security-Community/ba-p/828224" rel="nofollow">https:&#x2F;&#x2F;www.paypal-community.com&#x2F;t5&#x2F;PayPal-Forward&#x2F;Working-w...</a>
prohor将近 11 年前
A bigger problem for me is that two-factor authentication for PayPal is available only in few countries (US, UK and Germany I think). I tried to get a token but no chance; not even software with mobile app. When contacting support I was considered as a freak probably - they completely didn&#x27;t what is the problem without 2FA. I really don&#x27;t get it, why being global they limit 2FA to a few countries.
评论 #7942863 未加载
Rapzid将近 11 年前
You never trust the client; this is amateur hour shit TBH. How could a company like PayPal let something like this through? SURELY there were employees raising hell before it ever hit the app stores?
评论 #7943529 未加载
评论 #7943956 未加载
nooron将近 11 年前
It&#x27;s interesting to watch corporations expose one another&#x27;s vulnerabilities in a public way. It seems like this was done pretty fairly, giving PayPal ample time to address the bug-- so I guess that&#x27;s neat.
评论 #7942604 未加载
therealmarv将近 11 年前
I also do not like the two factor authentification from PayPal. Sometimes the SMS takes ages before it arrives (I waited more than 10 minutes here in Germany). And it is absolutely not possible to pay in eBay with Paypal and 2FA when using mobile browser or eBay Android app. I wished they use solutions like Google Authenticator for their 2FA.
VMG将近 11 年前
I don&#x27;t know if this is common knowledge but PayPal lets you log in with your CC number instead of the auth token sent via text message. I know because the text messages often do not arrive at all for me, even after repeated requests.<p>It &quot;only&quot; works one time though, the second time you&#x27;re asked the dreaded &quot;security question&quot;
driverdan将近 11 年前
Three months??? It took a major global payment processor three months to fix an issue as big as this?<p>And people wonder why I&#x27;m constantly telling them to stop using PayPal.
M4v3R将近 11 年前
It&#x27;s not suprising that Duo Security is interested in exposing this flaw in their 2FA flow, since their product is a somewhat better 2FA solution. I&#x27;ve evaluated their solution for my project, but ultimately settled with MePIN which offered similar security at lower price.
评论 #7942562 未加载