A Five-year-old Could Have Bypassed PayPal’s Account Authentication

A Five-year-old Could Have Bypassed PayPal’s Account Authentication

It is very troubling to realize one could access someone’s financial account without answering the security questions. The most commonly used online payment methods are not necessarily the safest option. PayPal, while globally used among consumers and retailers, is such an example. There is a newly discovered authentication bug which allows hackers to bypass PayPal’s 2FA security. Not the news most people were looking forward to, but third-party service providers are inherently insecure. While it is good to see PayPal take these authentication bug submissions to heart, although they should....


Related News

What We Learned About PayPal’s Crypto Strategy This Week

Insights from PayPal’s first quarterly earnings report since launching crypto services.

Ledger Hardware Wallet Integrates U2F Authentication

Update: This article was based on Ledger's post on Medium.com, which insinuates that Ledger will integrate full FIDO features. We've been told that this is not true, however. Ledger says they will add U2F authentication, but not biometric. We apologize for the error. The next generation of Ledger, a smartchip-based Bitcoin hardware wallet similar to Trezor, will be compatible with the authentication features of Fido Alliance – namely external dongles and fingerprint readers. Ledger says they will employ Fido Alliance's Second Factor (U2F) and Passwordless (UAF) authentication types. “[It]....

Why PayPal’s Venmo is Beating Bitcoin in P2P Payments

Bitcoin.com spoke with a Wall Street trader on why PayPal’s centralized P2P payment system Venmo is preferred among his circle over Bitcoin to uncover what is preventing the cryptocurrency from breaking into the mainstream. It appears that the never ending stream of Bitcoin eulogies is not slowing down anytime soon, as the world’s first decentralized....

Hackers exploit MFA flaw to steal from 6,000 Coinbase customers — report

Malicious actors reportedly took advantage of Coinbase’s SMS account recovery process to gain access to user funds. Cryptocurrency exchange Coinbase has reportedly suffered another security breach after attackers were able to bypass the company’s multi-factor authentication, or MFA, feature in a coordinated campaign earlier this year. The attackers stole cryptocurrency from 6,000 accounts, though the monetary value of the theft wasn’t disclosed, according to a report from Bleeping Computer. Earlier this week, Coinbase reportedly notified affected customers that the theft occurred between....

eBay Merchant to Sue PayPal for its Anti-Bitcoin Policies

PayPal is known for being antagonistic towards Bitcoin. The company is known to “sever business relationships” with people who sell Bitcoin products (specifically miners) on eBay, the company that owns PayPal. It doesn’t really seem fair for PayPal to block people from selling Bitcoin mining gear. After all, Bitcoin miners are just specialised computers, and there’s nothing illegal or prohibited in eBay’s terms of service about selling computers. But since Bitcoin threaten’s PayPal’s entire business, it seems a logical (though anti-competitive) move on PayPal’s part. However, one eBay....