forums
new posts
donate
UER Store
events
location db
db map
search
members
faq
terms of service
privacy policy
register
login




 1 2 
UER Forum > Journal Index > Av's Bloggy-thing. > Paypal's two-factor authentication has a big hole... (Viewed 5779 times)
Avbrand Blog Commenter 

Comments from the AvBrand Blog


Total Likes: 3 likes




 |  | 
AvBrand Blog Comment: Herb
< Reply # 20 on 3/27/2011 12:54 AM >
Reply with Quote
Posted on Forum:
I just received the newest Paypal security key cards. The screen is blank at all times until you press hard on the "press" button. It totally dissappears after a very short time. Pretty safe in my opinion. Whenever I push it again, a new code number appeared.




Avatar-X 

Alpha Husky


Location: West Coast
Gender: Male
Total Likes: 765 likes


yay!

 |  |  | AvBrand
Re: Paypal's two-factor authentication has a big hole...
< Reply # 21 on 4/5/2011 2:52 PM >
Reply with Quote
Posted on Forum: UER Forum
Awesome. It sounds like they have made some improvements.




huskies - such fluff.
Avbrand Blog Commenter 

Comments from the AvBrand Blog


Total Likes: 3 likes




 |  | 
AvBrand Blog Comment: elfin
< Reply # 22 on 6/11/2011 2:02 PM >
Reply with Quote
Posted on Forum:
Am I still able to get the old version of the security token instead of the card? I would definitely prefer the old version token to the card.




Avbrand Blog Commenter 

Comments from the AvBrand Blog


Total Likes: 3 likes




 |  | 
AvBrand Blog Comment: Bob
< Reply # 23 on 7/27/2011 5:46 PM >
Reply with Quote
Posted on Forum:
I compared ebay's two-factor authentication to paypals.. and ebay's seems to be stronger?

The first reason is if you're unable to enter a code for whatever reason, ebay forces you to enter a code they tell you by phoning your home phone number.

Paypal offers no such feature, and allows you to bypass entering the code using your "secret" questions (which all family/friends know!)

Secondly, paypal leaks the serial number of the device when it asks you to enter the code, ebay doesn't. Isn't this a flaw? Isn't this the seed??? Couldn't this help somebody who knows/reverse engineers the algorithm of this device better guess the codes?

If so, they should replace most of the serial number with X's.. while still allowing multiple device holders to use the correct device.

If you setup to use SMS messaging, it also leaks your mobile telephone number! This makes it really easy for friends/family etc to target the correct phone to steal! The hacker just has to call the number and voila! If they're nearby, they know who to steal from.

Once again, this could be fixed by X'ing out most of the phone digits.

There's also the flaw of when using your serial number/credential ID on multiple websites, the owner of one of those websites could have malicious intent.. and share this value (which seeds the number generator) with hackers who already know your password.. or this person may be the hacker themselves.




Avbrand Blog Commenter 

Comments from the AvBrand Blog


Total Likes: 3 likes




 |  | 
AvBrand Blog Comment: Alex
< Reply # 24 on 4/17/2014 12:28 AM >
Reply with Quote
Posted on Forum:
Hello, I would like to buy 2 yellow and white security tokens like the one in the picture. I tried to buy them directly from PayPal, but they don't have this model anymore. If someone have 2 for me and they are in good condition, please let me know, I am willing to buy them. Thank you! Alex.




Avatar-X 

Alpha Husky


Location: West Coast
Gender: Male
Total Likes: 765 likes


yay!

 |  |  | AvBrand
Re: Paypal's two-factor authentication has a big hole...
< Reply # 25 on 4/27/2014 2:57 PM >
Reply with Quote
Posted on Forum: UER Forum
This is a blog, these tokens are not for sale here. Please contact PayPal.




huskies - such fluff.
UER Forum > Journal Index > Av's Bloggy-thing. > Paypal's two-factor authentication has a big hole... (Viewed 5779 times)
 1 2 


Add a poll to this thread



This thread is in a public category, and can't be made private.



All content and images copyright © 2002-2024 UER.CA and respective creators. Graphical Design by Crossfire.
To contact webmaster, or click to email with problems or other questions about this site: UER CONTACT
View Terms of Service | View Privacy Policy | Server colocation provided by Beanfield
This page was generated for you in 93 milliseconds. Since June 23, 2002, a total of 740942634 pages have been generated.