Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,155,588 members, 7,827,202 topics. Date: Tuesday, 14 May 2024 at 08:46 AM

Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude - Business - Nairaland

Nairaland Forum / Nairaland / General / Business / Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude (1124 Views)

Please How Do I Transfer Money Using Paypal / Amazing But True: Nigerians Can Now Make Withdrawals And Payment Using Paypal / Major Oil Firm, MRS, Owes FCMB N6.2bn (2) (3) (4)

(1) (Reply) (Go Down)

Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude by Nobody: 4:29pm On Aug 05, 2014
We always hear to tighten your security online by using two factor authentication, it does make sense unless that two factor authentication is easily bypassed. PC World did a story on a 17 year old Australian who found a way to get around it.

What is disturbing is the fact that Joshua Rogers contacted Paypal on June 5 and PayPal did not fix the flaw. Rogers went public on his own blog which means he will not get a reward that is usually paid by PayPal to security researchers that requires confidentiality until a software vulnerability is fixed. Rogers estimated the reward might be around $3000, although PayPal didn’t give him a figure.


A security feature offered by PayPal to help prevent accounts from being taken over by hackers can be easily circumvented, an Australian security researcher has found.

PayPal users can elect to receive a six-digit passcode via text message in order to access their accounts. The number is entered after a username and password is submitted.

The security feature, known as two-factor authentication, is an option on many online services such as Google and mandatory on many financial services websites for certain kinds of high-risk transactions. Since the code is sent offline or generated by a mobile application, it is much more difficult for hackers to intercept although by no means impossible.

Joshua Rogers, a 17-year-old based in Melbourne, found a way to get access to a PayPal account that has enabled two-factor authentication. He published details of the attack on his blog on Monday after he said PayPal failed to fix the flaw despite being notified on June 5.

By going public with the information, Rogers will forfeit a reward usually paid by PayPal to security researchers that requires confidentiality until a software vulnerability is fixed. Rogers estimated the reward might be around $3000, although PayPal didn’t give him a figure.

“I don’t care about the money, no,” he said via email. “Money isn’t everything in this world.”

The attack requires a hacker to know a person’s eBay and PayPal login credentials, but malicious software programs have long been able to easily harvest those details from compromised computers.

The fault lies in a page on eBay that allows users to link their eBay account with PayPal, which eBay owns. Linking the accounts creates a cookie that makes the PayPal application think the person is logged in, even if a six-digit code has not been entered, Rogers wrote on his blog.

The problem lies specifically in the “=_integrated-registration” function, Rogers wrote, which does not check to see if the victim has two-factor authentication enabled. An attacker could repeatedly gets access to the PayPal account by linking and de-linking the eBay and PayPal accounts of a person, he wrote. He posted a video of the attack on YouTube.

PayPal officials could not be immediately reached for comment.

The payment processor’s two-factor authentication could potentially be defeated in other ways. For example, if a user doesn’t have a way to receive the six-digit code, PayPal allows them to skip it and instead answer two security questions.

Those questions, which include “What’s the name of your first school?” and “What’s the name of the hospital in which you were born?” arguably aren’t difficult ones for a hacker who has been profiling a victim to answer.

But as with many online defenses, companies are often forced to make trade-offs between convenience and security, attempting to strike the right balance between safety and not alienating users locked out of their accounts.

Rogers has a record of finding problems in online services. Last month, he accepted a caution from police rather than face charges for discovering a vulnerability in the website of one of the country’s public transport authorities late last year.

A database flaw within the website of Public Transport Victoria (PTV), which runs the state’s transport system, allowed Rogers to gain access to some 600,000 records, including partial credit card numbers, addresses, emails, passwords, birth dates, phone numbers and senior citizen card numbers. Rogers notified the agency of the problem and did not try to profit from the information, but the incident was still referred to police.

http://www.pcworld.com/article/2461520/paypals-twofactor-authentication-is-easily-beaten-researcher-says.html
Re: Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude by Noah13: 4:49pm On Aug 05, 2014
Even a widely used payment gateway like Paypal has got security flaw. Y'all should really thank this dude for exposing this flaw
Re: Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude by Youngzedd(m): 4:52pm On Aug 05, 2014
This is good.

You will see the way Seun and moderators will send this topic to front page.


I don book space in advance.
Re: Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude by Sleekydee(m): 5:09pm On Aug 05, 2014
lemme book ma space with somtin scary....EBOLA!!!!!!!!!!
Re: Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude by femimike1(m): 5:34pm On Aug 05, 2014
nice 1,.........
Re: Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude by Dhortunn(m): 7:20pm On Aug 05, 2014
Interesting!
Re: Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude by Nobody: 7:46pm On Aug 05, 2014
Hmmm
Re: Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude by fr3do(m): 8:45pm On Aug 05, 2014
Dude is trying
But I owe him no gratitude, if my money miss its paypal's liability.
Re: Everyone Using Paypal Owes This Australian 17 Year Old A Bit Of Gratitude by Nobody: 9:27am On Jan 09, 2015
hmmmmm... no front page yet o

(1) (Reply)

. / Packaging Of Nigerian Food Items For Export / 13 Richest People In Nigeria 2015 And Their Net Worth - Citynews.ng

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 14
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.