Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: Reported malfunction in paypal Security Key


Top Poster

Status: Offline
Posts: 3757
Date:
Reported malfunction in paypal Security Key





Reported malfunction in paypal Security Key

When eBay rolled out the PayPal Security Key earlier this year, its executives hailed it as an important measure that would make users more secure. And it was. By generating a random, six-digit number every 30 seconds that users needed to authenticate themselves online, the small electronic token provided an additional layer of protection against phishers and other online criminals.

But according to Chris Romero, an IT administrator who has used the Security Key for several months now, a bug could allow phishers and others with bad intent to work around the measure. When accessing his PayPal account from merchant sites and other third-party destinations, he says, his account is validated when he types in any six-digit number, as long as he provides a valid user id and password and answers an accompanying security question.

continues






-- Edited by budnonymous at 22:22, 2007-11-28

__________________

Exposing the sleazery of ebaY and PayPal

 



Top Poster

Status: Offline
Posts: 3757
Date:

PayPal Security Key not as secure as it could be


Earlier this year PayPal introduced a security fob that generates a six-digit code every 30 seconds, meant as an additional layer of protection against online identity thieves. However, one user discovered a bug that makes the key useless in certain situations.

By entering his valid PayPal login and password, answering a security question and entering ANY six-digit number, he can make a purchase. eBay and PayPal have been unable to reproduce the flaw, but Romero stands by his statement, claiming the key doesn't work as advertised. "For someone who's paid money for a Security Key and is thinking their wife or brother can't get into their account because they don't have the key fob ... they're not getting the security that they assume they have."

__________________

Exposing the sleazery of ebaY and PayPal

 



Senior Member

Status: Offline
Posts: 247
Date:

Reported malfunction in paypal Security Key

Not cool!





__________________
“There is a destiny that makes us all brothers: None goes his way alone. What we put into the lives of others, comes back into our own.”--Edwin Markham


Top Poster

Status: Offline
Posts: 3757
Date:

Out of all the security fobs PP had to choose from, they picked the one with the very LOWEST specs!

http://www.signify.net /uploads/How_RSA_Tokens_Compare_to_Vasco.pdf

Hilarious!!!!

 

Image Hosted by ImageShack.us
The model PP chose is the Vasco Digipass Go3 Token,

which has already had published reports about it's vulnerabilities.

(some of which have curiously "evaporated") confused.gif

Digipass Go3 Insecure Encryption Vulnerability



-- Edited by budnonymous at 22:50, 2007-11-28

__________________

Exposing the sleazery of ebaY and PayPal

 



Senior Member

Status: Offline
Posts: 247
Date:


Out of all the security fobs PP had to choose from, they picked the one with the very LOWEST specs!

http://www.signify.net /uploads/How_RSA_Tokens_Compare_to_Vasco.pdf

Hilarious!!!!


Really! lol






__________________
“There is a destiny that makes us all brothers: None goes his way alone. What we put into the lives of others, comes back into our own.”--Edwin Markham


Top Poster

Status: Offline
Posts: 3757
Date:

That image is a screencapture of the digest chart in the pdf document.

That company which made the fob was in some sort of hot water over something recently too.
Their stock took a huge tumble, & their website was 404 or otherwise unavailable for a few days or so, to the best of my recollection.



__________________

Exposing the sleazery of ebaY and PayPal

 

Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us


Create your own FREE Forum
Report Abuse
Powered by ActiveBoard