Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

It is necessary to have purpose. -- Alice #1, "I, Mudd", stardate 4513.3


computers / comp.misc / PayPal do not understand security

SubjectAuthor
* PayPal do not understand securitySylvia Else
+* Re: PayPal do not understand securityRichard Kettlewell
|`- Re: PayPal do not understand securityDan Espen
`* Re: PayPal do not understand securityAdrian Caspersz
 `* Re: PayPal do not understand securityAdrian Caspersz
  `* Re: PayPal do not understand securityRich
   `- Re: PayPal do not understand securityBob Eager

1
PayPal do not understand security

<je4aseFprbhU1@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=1534&group=comp.misc#1534

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: syl...@email.invalid (Sylvia Else)
Newsgroups: comp.misc
Subject: PayPal do not understand security
Date: Thu, 12 May 2022 21:54:53 +1000
Lines: 46
Message-ID: <je4aseFprbhU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net m9simEHdWcTOPOKV7/lWKwQyECSuHFPSZVyO3Dnwu5mdP2fHa+
Cancel-Lock: sha1:tbgz9QfKuLH+EXBGQzpxHaZarPs=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.9.0
Content-Language: en-GB
 by: Sylvia Else - Thu, 12 May 2022 11:54 UTC

I asked that all methods of resetting my password be disabled, since I
am not going to forget it, and I view the various reset methods as being
highly insecure.

Here's their reply:

------------------------------------------------

Hi Miss Sylvia. This is XXXXX. Thank you for contacting us.

Due to security reason and for the safety of all our PayPal customers,
the option to disable all methods of password recovery can not be granted.

There are occasions in which hackers were able to get the passwords of
the customers. So our customers need to change their passwords to stop
hackers from accessing their accounts; to prevent their accounts from
being compromised.

I know that this may be annoying. But the safety and the security of our
PayPal customers are our top priority. which is why disabling the
password recovery method can never be removed (sic).

It's not the matter of memorising the password indefinitely but the high
probability of any stranger in accessing their passwords. No matter how
complicated the password is, there are some hackers who used advanced
methods that enable them to still figure the customer's passwords.

That's why a number of institutions and individuals change their
passwords from time-to-time and that kept their PayPal accounts safe and
secured for a very long time.

Hoping for your understanding. Thank you for contacting PayPal.
-----------------------------------------------

So sending a SMS code via a third party they don't control is secure?
Ditto an email?

I'm not aware of any computationally feasible way to get a matching
password for a salted SHA-256 representation of a reasonably long random
sequence of characters.

In any case, if a hacker manages to obtain a password by whatever means,
they are going to make use of it immediately, so changing passwords is
unhelpful.

Sylvia.

Re: PayPal do not understand security

<87tu9vx8k7.fsf@LkoBDZeT.terraraq.uk>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=1535&group=comp.misc#1535

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.nntp4.net!nntp.terraraq.uk!.POSTED.nntp.terraraq.uk!not-for-mail
From: inva...@invalid.invalid (Richard Kettlewell)
Newsgroups: comp.misc
Subject: Re: PayPal do not understand security
Date: Thu, 12 May 2022 13:02:48 +0100
Organization: terraraq NNTP server
Message-ID: <87tu9vx8k7.fsf@LkoBDZeT.terraraq.uk>
References: <je4aseFprbhU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Injection-Info: mantic.terraraq.uk; posting-host="nntp.terraraq.uk:2a00:1098:0:86:1000:3f:0:2";
logging-data="55112"; mail-complaints-to="usenet@mantic.terraraq.uk"
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux)
Cancel-Lock: sha1:NPLtzJ5qaw+ScBVCOG8mZv4Z//4=
X-Face: h[Hh-7npe<<b4/eW[]sat,I3O`t8A`(ej.H!F4\8|;ih)`7{@:A~/j1}gTt4e7-n*F?.Rl^
F<\{jehn7.KrO{!7=:(@J~]<.[{>v9!1<qZY,{EJxg6?Er4Y7Ng2\Ft>Z&W?r\c.!4DXH5PWpga"ha
+r0NzP?vnz:e/knOY)PI-
X-Boydie: NO
 by: Richard Kettlewell - Thu, 12 May 2022 12:02 UTC

Sylvia Else <sylvia@email.invalid> writes:
> I asked that all methods of resetting my password be disabled, since I
> am not going to forget it, and I view the various reset methods as
> being highly insecure.

They are not going to change their authentication system for your niche
use case.

> I'm not aware of any computationally feasible way to get a matching
> password for a salted SHA-256 representation of a reasonably long
> random sequence of characters.

Depends how many rounds of SHA256 are used.

But there is plenty of residual risk even after adequately securing the
backend password storage. An attacker may install a keylogger on the
victim’s computer (or some other form of compromise). They may fool the
user into typing into attacker-controlled web page (i.e. by phishing).

--
https://www.greenend.org.uk/rjk/

Re: PayPal do not understand security

<t5jb7e$ikt$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=1536&group=comp.misc#1536

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: dan1es...@gmail.com (Dan Espen)
Newsgroups: comp.misc
Subject: Re: PayPal do not understand security
Date: Thu, 12 May 2022 12:05:02 -0400
Organization: A noiseless patient Spider
Lines: 18
Message-ID: <t5jb7e$ikt$1@dont-email.me>
References: <je4aseFprbhU1@mid.individual.net>
<87tu9vx8k7.fsf@LkoBDZeT.terraraq.uk>
MIME-Version: 1.0
Content-Type: text/plain
Injection-Info: reader02.eternal-september.org; posting-host="014e07aa70a5452fea8cef444f1adb8d";
logging-data="19101"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/lX8wIOhqeGrZIC5AdeyTVebtPyv2QeP8="
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux)
Cancel-Lock: sha1:0RTBgHTPGa2k25F4nUZk+atfY0s=
 by: Dan Espen - Thu, 12 May 2022 16:05 UTC

Richard Kettlewell <invalid@invalid.invalid> writes:

> Sylvia Else <sylvia@email.invalid> writes:
>> I asked that all methods of resetting my password be disabled, since I
>> am not going to forget it, and I view the various reset methods as
>> being highly insecure.
>
> They are not going to change their authentication system for your niche
> use case.

Agree.

I doubt their software has the ability to create passwords that can't
change. The whole idea sounds like a mis-feature.

--
Dan Espen

Re: PayPal do not understand security

<je4qgrFsp7eU1@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=1537&group=comp.misc#1537

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: ema...@here.invalid (Adrian Caspersz)
Newsgroups: comp.misc
Subject: Re: PayPal do not understand security
Date: Thu, 12 May 2022 17:21:46 +0100
Organization: Keep Usenet Text Newsgroups Alive!!
Lines: 37
Message-ID: <je4qgrFsp7eU1@mid.individual.net>
References: <je4aseFprbhU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 1coz8bsn2ntF2yd4dP3X0AY1q/Z+W2yhQoM+0AilS0GIPjx2i7
Cancel-Lock: sha1:YPKz2pnTVILvMgILj6r+Yc50fhQ=
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.8.0
Content-Language: en-GB
In-Reply-To: <je4aseFprbhU1@mid.individual.net>
 by: Adrian Caspersz - Thu, 12 May 2022 16:21 UTC

On 12/05/2022 12:54, Sylvia Else wrote:
> I asked that all methods of resetting my password be disabled, since I
> am not going to forget it, and I view the various reset methods as being
> highly insecure.
>
> Here's their reply:
>
> ------------------------------------------------
>
> Hi Miss Sylvia. This is XXXXX. Thank you for contacting us.
>
> Due to security reason and for the safety of all our PayPal customers,
> the option to disable all methods of password recovery can not be granted.
>
> There are occasions in which hackers were able to get the passwords of
> the customers. So our customers need to change their passwords to stop
> hackers from accessing their accounts; to prevent their accounts from
> being compromised.
>
> I know that this may be annoying. But the safety and the security of our
> PayPal customers are our top priority. which is why disabling the
> password recovery method can never be removed (sic). >

Do you need to use PayPal then?

When setting up some accounts, for password recovery purposes other
entities allow you to download a set of codes that can be printed to be
securely kept sellotaped under the dog's feeding bowl.

These _only_ can be used to get back into the account.

However, print it out. Give it to the dog to eat, and then you'll have
your secure account.

--
Adrian C

Re: PayPal do not understand security

<je53grFue3tU1@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=1538&group=comp.misc#1538

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: ema...@here.invalid (Adrian Caspersz)
Newsgroups: comp.misc
Subject: Re: PayPal do not understand security
Date: Thu, 12 May 2022 19:55:23 +0100
Organization: Keep Usenet Text Newsgroups Alive!!
Lines: 19
Message-ID: <je53grFue3tU1@mid.individual.net>
References: <je4aseFprbhU1@mid.individual.net>
<je4qgrFsp7eU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net sXpqT2vt7qrujT5raeN9TgxHxu73Dx9vcseeNyg5m6q96S87mE
Cancel-Lock: sha1:qxB8UVSm0MWz7lLHjIny2OhBY8c=
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.8.0
Content-Language: en-GB
In-Reply-To: <je4qgrFsp7eU1@mid.individual.net>
 by: Adrian Caspersz - Thu, 12 May 2022 18:55 UTC

On 12/05/2022 17:21, Adrian Caspersz wrote:

>
> These _only_ can be used to get back into the account.
>
> However, print it out. Give it to the dog to eat, and then you'll have
> your secure account.
>

Ah, I see Paypal are asking for answers for two previously chosen questions.

Be creative, don't have to be so truthful. Give them the name ya first
pet as 'Donald Trump' and ya first school as 'School of Life'.

Or use a long string of random characters in ya answers and give the
poor sod on the phone a hard time rekeying them.

--
Adrian C

Re: PayPal do not understand security

<t5jlr0$vg$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=1539&group=comp.misc#1539

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: ric...@example.invalid (Rich)
Newsgroups: comp.misc
Subject: Re: PayPal do not understand security
Date: Thu, 12 May 2022 19:06:08 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 45
Message-ID: <t5jlr0$vg$1@dont-email.me>
References: <je4aseFprbhU1@mid.individual.net> <je4qgrFsp7eU1@mid.individual.net> <je53grFue3tU1@mid.individual.net>
Injection-Date: Thu, 12 May 2022 19:06:08 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="410cb9fe1bd5bd7ff94697c3fa1cc321";
logging-data="1008"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/80e2zgdDkU9fquey1oYYZ"
User-Agent: tin/2.0.1-20111224 ("Achenvoir") (UNIX) (Linux/3.10.17 (x86_64))
Cancel-Lock: sha1:uvd80x/jE+2jxyNjFOWwsWEVu6c=
 by: Rich - Thu, 12 May 2022 19:06 UTC

Adrian Caspersz <email@here.invalid> wrote:
> On 12/05/2022 17:21, Adrian Caspersz wrote:
>
>>
>> These _only_ can be used to get back into the account.
>>
>> However, print it out. Give it to the dog to eat, and then you'll have
>> your secure account.
>>
>
> Ah, I see Paypal are asking for answers for two previously chosen questions.
>
> Be creative, don't have to be so truthful.

This is the part that trips many up with the "recovery questions".
They take the questions too literal.

> Give them the name ya first pet as 'Donald Trump' and ya first school
> as 'School of Life'.
>
> Or use a long string of random characters in ya answers and give the
> poor sod on the phone a hard time rekeying them.

I've seen reports (sorry, no longer remember what blog/site for
citations) that when calling and talking to customer service reps, that
attackers can get the service rep to "bypass" the "long string of random
characters" by telling the rep something like: "I just banged out a
bunch of random keys" and the service rep. accepts that as an answer.
So better to use a random assemblage of words, then at least you might
be protected from someone sweet-talking their way past a customer
service rep.

What I do for those questions, for sites that demand them, is this:

$ sort --random-sort --random-source=/dev/urandom /usr/dict/words | head -5 | tr $'\n' " " ; echo
cottonseed suction architect supplants highways

And then "cottonseed suction architect supplants highways" goes in the
field, and in the notes box in my password manager for the site's
entry, so later, if needed, I have a record of what was used. Adjust
size given to "head" for number of words desired.

Hopefully someone sweet-talking with "just mashed random keys" won't be
allowed past by the service rep. And hopefully by being real words,
the rep. will insist on the attacker repeating the actual words.

Re: PayPal do not understand security

<je5im4Fhj33U4@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=1540&group=comp.misc#1540

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: news0...@eager.cx (Bob Eager)
Newsgroups: comp.misc
Subject: Re: PayPal do not understand security
Date: 12 May 2022 23:14:12 GMT
Lines: 12
Message-ID: <je5im4Fhj33U4@mid.individual.net>
References: <je4aseFprbhU1@mid.individual.net>
<je4qgrFsp7eU1@mid.individual.net> <je53grFue3tU1@mid.individual.net>
<t5jlr0$vg$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net 4/Iupc41QhE5kC0NxB3J1AxverzwWgBIx6X9uzRFRle0TUN3qD
Cancel-Lock: sha1:UUrK0mq+Ud2hxq05hHhkZbB74F4=
User-Agent: Pan/0.145 (Duplicitous mercenary valetism; d7e168a
git.gnome.org/pan2)
 by: Bob Eager - Thu, 12 May 2022 23:14 UTC

On Thu, 12 May 2022 19:06:08 +0000, Rich wrote:

> $ sort --random-sort --random-source=/dev/urandom /usr/dict/words | head
> -5 | tr $'\n' " " ; echo cottonseed suction architect supplants highways

I use dicewords (the improved list) and a set of casino dice.

--
Using UNIX since v6 (1975)...

Use the BIG mirror service in the UK:
http://www.mirrorservice.org

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor