Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think this is the worst part of the event.

PayPal is the most annoying service I use because it asks for 2FA for every damn action. So how could they take that action? Surely if they logged in they left breadcrumbs?

The post is mildly infuriating because it doesn’t even try to answer very important that question.



They provide a possible reason, that being mobile number spoofing and calling the call center


This might be an option you turned on? I don't experience 2FA for paypal... But I'll probably go fix that today.


I'm pretty sure it's part of "the algorithm". I don't get 2FA prompts every time, but ever so often for it to be annoying - especially since I am then thrown back to the login prompt which dares to tell me that the password from my password manager was wrong. No, it wasn't wrong, your system apparently just cannot handle going from a password prompt to 2FA and then realizing that the correct password was already entered! I asked lots of people around me and they don't have this issue, so I guess it's kinda random who is treated how.


It is apparently very inconsistent.

My own experience with using PayPal usually (as in: almost always) goes like this:

I get a PayPal popup that says something like "You're already logged in! One moment," and then once that goes away I push the whatever button corresponds to "Yeah, sure -- pay it."

It's generally a one-button operation for me, and has been for years.

I wonder what the differentiation is.


Agreed on the yikes here - this should be a high priority issue from paypal's side to address.

This seems like a HUGE loophole


Eh, I'm sure PayPal could see how it happened but the relatively low level support person wouldn't have access to such information.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: