I had a rather unpleasant experience with PayPal lately where someone transferred all the money from my account. PayPal was not very forthcoming and I do not know until today how this was possible. One of the first things that I did after this experience was to order a PayPal Security Key. I was contacted by VeriSign, the creators of those security keys, just a few days later and they send me a key as well.
The VeriSign Identity Protection device can be used to add another layer of security to the login process. The PayPal Security Key mentions only eBay and PayPal and I’m not sure if it works with the other websites and services that the VeriSign Identity Protection key works with.
The key is a little device that displays a six digit security code when a button is pressed. That code is active for 30 seconds after which it disappears again. The device has to be activated on the website that you want to use it for by entering the serial number of the device and two six digit codes.

Once a device has been linked to an account it has to be used to log into the account by pressing the button and entering the six digit code after the password on that website or by entering the login credentials normally and the six digit code on the next page where it is requested before the user can proceed.
The real benefit of this key is obviously that an attacker who is getting hold of your login credentials cannot login into the account if he does not have access to the active six digit code.
PayPal seems to heavily subsidize the key. If you order the security key at PayPal you receive a blueish-gray device for roughly 5€ while the VeriSign key is delivered in dark red for the price of $30. As I said I’m not sure if the PayPal key works with other services as well.

The VeriSign website offers two additional devices. One is the so called VIP Security Card (for $48), a credit-card sized device that seems to offer the same functionality and the SanDisk U3 TrustedSignins
which works with SanDisk U3 devices but does not seem to come with additional charges.
This is definitely a step into the right direction and I strongly suggest to everyone using eBay and PayPal regularly to get one of those security devices to add another layer of protection to their account.
Like such posts? Get updates via RSS NEWS FEED. Love Ghacks? Find out how you can help!
Related Posts
17 Users Commented In This Post
Subscribe To This Post Comment Rss Or TrackBack URL