A teenager has found a way to bypass PayPal’s 2FA security measures

TECHi's Author Jesseb Shiloh
Opposing Author Theguardian Read Source Article
Last Updated
TECHi's Take
Jesseb Shiloh
Jesseb Shiloh
  • Words 114
  • Estimated Read 1 min

A teenage whitehat hacker said he has found a simple way that attackers can bypass the two-factor authentication system PayPal uses to protect user accounts. The circumvention requires little more than spoofing a browser cookie set when users link their eBay and PayPal accounts, according to Joshua Rogers, a 17-year-old living in Melbourne, Australia. Once the cookie—which is tied to a function PayPal identifies as “=_integrated-registration”—is active in a user’s browsing session, the two-factor authentication is circumvented, Rogers reported. That means attackers who somehow acquire someone else’s login credentials would be able to log in without having to enter the one-time passcode sent to the account holder’s mobile phone.

Theguardian

Theguardian

  • Words 270
  • Estimated Read 2 min
Read Article

A security researcher has discovered a way to bypass Paypal’s two factor authentication (2FA) security authentication and hack into an account. “On the 5th of June, 2014, I found a complete bypass for Paypal’s 2FA service, in which anybody would be able to access a Paypal account that has 2FA setup, by only logging in through a ‘special’ Paypal page,” said security expert Joshua in his most recent “Just Another Security Blog” post. After warning Paypal about the bug several times, Rogers claims he has only now made his findings public after Paypal has ignored them. “On the 5 August, I have decided to release this publicly, because despite two months given, it still hasn’t been fixed,” he added. The bug was uncovered when Rogers looked into the way in which Paypal works with eBay to link your eBay account to your Paypal account, and when you sell something on eBay, the fees automatically come out of your Paypal account. When setting this up, you’re asked for your Paypal login to link the two accounts and when you are redirected to the login page, the URL contains “=_integrated-registration”. “Doing a quick Google search for this shows that it isn’t used for anything other than eBay; thus it is setup purely for Paypal and eBay,” explained Rogers. “Once you’re actually logged in, a cookie is set with your details, and you’re redirected to a page to confirm the details of the process. And this is where the exploit lays. Now just load Paypal, and you are logged in, and don’t need to re-enter your login.”

Source

NOTE: TECHi Two-Takes are the stories we have chosen from the web along with a little bit of our opinion in a paragraph. Please check the original story in the Source Button below.

Balanced Perspective

TECHi weighs both sides before reaching a conclusion.

TECHi’s editorial take above outlines the reasoning that supports this position.

More Two Takes from Theguardian

Spotify collaborates with global music giants to create ethical AI technologies
Spotify collaborates with global music giants to create ethical AI technologies

Spotify is forging a significant collaboration with the major players in the global music industry, Sony, Universal, and Warner, to…

Donkey Kong Comeback Smashes Expectations
Donkey Kong Comeback Smashes Expectations

Donkey Kong Bananza signifies one thrilling transformation on the part of Nintendo and veterans. It is a new release after…

Trump Administration Reportedly Plans to Cut 2,145 NASA Employees
Trump Administration Reportedly Plans to Cut 2,145 NASA Employees

The news that the Trump administration wishes to reduce the number of NASA workers by over two thousand is a…

Google Ordered to Pay $314.6M to Android Users
Google Ordered to Pay $314.6M to Android Users

This is actually a pretty big revelation. Google wasn't just spying on users, it was making them pay for the…