<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; paypal security</title>
	<atom:link href="http://www.ghacks.net/tag/paypal-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 23:31:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>PayPal Login</title>
		<link>http://www.ghacks.net/2009/11/09/paypal-login/</link>
		<comments>http://www.ghacks.net/2009/11/09/paypal-login/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 22:45:07 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[paypal login]]></category>
		<category><![CDATA[paypal login page]]></category>
		<category><![CDATA[paypal security]]></category>
		<category><![CDATA[paypal security key]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=18322</guid>
		<description><![CDATA[PayPal is a widely used financial service that allows people from all over the world to transfer money to other PayPal users by simply specifying an email address the money should be send to. It has become even more popular in recent years with the eBay tie-in which practically made PayPal the preferred payment method [...]]]></description>
			<content:encoded><![CDATA[<p>PayPal is a widely used financial service that allows people from all over the world to transfer money to other PayPal users by simply specifying an email address the money should be send to. It has become even more popular in recent years with the eBay tie-in which practically made PayPal the preferred payment method for many eBay users. A financial service that popular is a priority target for worms, phishing attacks, trojans and other kinds of attacks that try to steal PayPal login information in order to transfer money from the PayPal account to another one.</p>
<p>PayPal recently began to sell a so called PayPal Security Key to protect PayPal users from phishing attacks. The system works by protecting the login to the account not only with a username and password but also a security key that is generated on the fly on an external device. Attackers who are able to steal PayPal login information would need physical access to the security key to be able to log into the account at a later time.</p>
<p><span id="more-18322"></span><img src="http://www.ghacks.net/wp-content/uploads/2009/11/paypal_login-500x425.jpg" alt="paypal login" title="paypal login" width="500" height="425" class="alignnone size-medium wp-image-18323" /></p>
<p>It is not a 100% perfect solution as attackers are still able to circumvent the security key if they have additional information related to the PayPal user&#8217;s account. It still is a viable protection in most cases. PayPal is hosting a <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_security-center-outside">security center</a> on their website that is informing and educating users about security risks and how to reduce them and prevent attacks.</p>
<p>Probably the best way of fighting most attacks and all phishing attacks is to always open the PayPal website <a href="https://www.paypal.com/">directly</a> instead of clicking on links that are supposed to lead there. Another security method is to use a password manager to store the PayPal login information. Many password managers, such as Last Pass, can fill out the login form and log in the user automatically in configured accounts. This can be a very effective method of detecting fake websites as the password manager will not fill out the login information automatically on these websites.</p>

	Tags: <a href="http://www.ghacks.net/tag/paypal/" title="paypal" rel="tag">paypal</a>, <a href="http://www.ghacks.net/tag/paypal-login/" title="paypal login" rel="tag">paypal login</a>, <a href="http://www.ghacks.net/tag/paypal-login-page/" title="paypal login page" rel="tag">paypal login page</a>, <a href="http://www.ghacks.net/tag/paypal-security/" title="paypal security" rel="tag">paypal security</a>, <a href="http://www.ghacks.net/tag/paypal-security-key/" title="paypal security key" rel="tag">paypal security key</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/11/24/paypal-now-offering-mobile-security-key/" title="PayPal Now Offering Mobile Security Key (November 24, 2008)">PayPal Now Offering Mobile Security Key</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/07/17/update-on-my-paypal-story/" title="Update on my PayPal Story (July 17, 2008)">Update on my PayPal Story</a> (8)</li>
	<li><a href="http://www.ghacks.net/2008/07/19/protect-paypal-accounts-with-verisign-identity-protection-devices/" title="Protect PayPal Accounts With VeriSign Identity Protection Devices (July 19, 2008)">Protect PayPal Accounts With VeriSign Identity Protection Devices</a> (19)</li>
	<li><a href="http://www.ghacks.net/2008/07/02/unauthorized-payment-done-with-my-paypal-account/" title="Unauthorized Payment Done With My PayPal Account (July 2, 2008)">Unauthorized Payment Done With My PayPal Account</a> (50)</li>
	<li><a href="http://www.ghacks.net/2006/06/29/send-a-fax-to-unsubscribe-from-paypals-newsletter/" title="Send a Fax to unsubscribe from paypals newsletter (June 29, 2006)">Send a Fax to unsubscribe from paypals newsletter</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/11/09/paypal-login/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PayPal Now Offering Mobile Security Key</title>
		<link>http://www.ghacks.net/2008/11/24/paypal-now-offering-mobile-security-key/</link>
		<comments>http://www.ghacks.net/2008/11/24/paypal-now-offering-mobile-security-key/#comments</comments>
		<pubDate>Mon, 24 Nov 2008 18:14:49 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[paypal security]]></category>
		<category><![CDATA[paypal security key]]></category>
		<category><![CDATA[paypal tips]]></category>
		<category><![CDATA[security key]]></category>
		<category><![CDATA[sms security key]]></category>
		<category><![CDATA[VeriSign]]></category>
		<category><![CDATA[verisign identity protect]]></category>
		<category><![CDATA[verisign security key]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8510</guid>
		<description><![CDATA[VeriSign send me a free PayPal Security Key after I mentioned that an unauthorized payment was done from my PayPal account. The security key acts as a new layer of defense. It has to be entered during login to complete the login.
The key is an electronic device that generates a six digit key every 30 [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ghacks.net/2008/07/19/protect-paypal-accounts-with-verisign-identity-protection-devices/">VeriSign</a> send me a free PayPal Security Key after I mentioned that an unauthorized payment was done from my PayPal account. The security key acts as a new layer of defense. It has to be entered during login to complete the login.</p>
<p>The key is an electronic device that generates a six digit key every 30 seconds. That key is needed to login into PayPal. The device can be ordered from within the PayPal interface or from VeriSign directly. It works at all websites that make use of the key including eBay and PayPal.</p>
<p>PayPal has introduced the mobile security key recently. It makes use of the same principle with the difference that the security key is generated by an official server and send to the user&#8217;s cell phone instead.</p>
<p><span id="more-8510"></span>This offers a few advantages like increased mobility and no waiting time till the device arrives. It does however mean that the user is charged for every SMS send by his cell phone provider. Merchants who log into PayPal several times a day might want to use the hardware solution primarily to save costs.</p>
<p>Users who want to order a mobile security key can do that once they are logged into PayPal. The option becomes available after the <a href="http://www.connectedinternet.co.uk/2009/11/08/paypal-login-page-and-other-safety-tips/">PayPal login</a>. A click on the Security link in the top right corner of the website will load a new page with a link named Security Key.</p>
<p>A click on that link will display two options: To order a security key device or a SMS security key.</p>

	Tags: <a href="http://www.ghacks.net/tag/paypal/" title="paypal" rel="tag">paypal</a>, <a href="http://www.ghacks.net/tag/paypal-security/" title="paypal security" rel="tag">paypal security</a>, <a href="http://www.ghacks.net/tag/paypal-security-key/" title="paypal security key" rel="tag">paypal security key</a>, <a href="http://www.ghacks.net/tag/paypal-tips/" title="paypal tips" rel="tag">paypal tips</a>, <a href="http://www.ghacks.net/tag/security-key/" title="security key" rel="tag">security key</a>, <a href="http://www.ghacks.net/tag/sms-security-key/" title="sms security key" rel="tag">sms security key</a>, <a href="http://www.ghacks.net/tag/verisign/" title="VeriSign" rel="tag">VeriSign</a>, <a href="http://www.ghacks.net/tag/verisign-identity-protect/" title="verisign identity protect" rel="tag">verisign identity protect</a>, <a href="http://www.ghacks.net/tag/verisign-security-key/" title="verisign security key" rel="tag">verisign security key</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/07/19/protect-paypal-accounts-with-verisign-identity-protection-devices/" title="Protect PayPal Accounts With VeriSign Identity Protection Devices (July 19, 2008)">Protect PayPal Accounts With VeriSign Identity Protection Devices</a> (19)</li>
	<li><a href="http://www.ghacks.net/2008/07/17/update-on-my-paypal-story/" title="Update on my PayPal Story (July 17, 2008)">Update on my PayPal Story</a> (8)</li>
	<li><a href="http://www.ghacks.net/2009/11/09/paypal-login/" title="PayPal Login (November 9, 2009)">PayPal Login</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/07/02/unauthorized-payment-done-with-my-paypal-account/" title="Unauthorized Payment Done With My PayPal Account (July 2, 2008)">Unauthorized Payment Done With My PayPal Account</a> (50)</li>
	<li><a href="http://www.ghacks.net/2006/06/29/send-a-fax-to-unsubscribe-from-paypals-newsletter/" title="Send a Fax to unsubscribe from paypals newsletter (June 29, 2006)">Send a Fax to unsubscribe from paypals newsletter</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/11/24/paypal-now-offering-mobile-security-key/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Update on my PayPal Story</title>
		<link>http://www.ghacks.net/2008/07/17/update-on-my-paypal-story/</link>
		<comments>http://www.ghacks.net/2008/07/17/update-on-my-paypal-story/#comments</comments>
		<pubDate>Thu, 17 Jul 2008 09:03:36 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[paypal payment]]></category>
		<category><![CDATA[paypal security]]></category>
		<category><![CDATA[The Tech Herald]]></category>
		<category><![CDATA[unauthorized payment]]></category>
		<category><![CDATA[VeriSign]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=5373</guid>
		<description><![CDATA[I noticed in the beginning of July that someone else transferred most of the money that had been in my PayPal account to an online hoster to buy six month access to an virtual server. That was quite shocking and you can read up on theUnauthorized Payment Done With My PayPal Account story. I got [...]]]></description>
			<content:encoded><![CDATA[<p>I noticed in the beginning of July that someone else transferred most of the money that had been in my PayPal account to an online hoster to buy six month access to an virtual server. That was quite shocking and you can read up on the<a href="http://www.ghacks.net/2008/07/02/unauthorized-payment-done-with-my-paypal-account/">Unauthorized Payment Done With My PayPal Account</a> story. I got the money back the same day because the merchant was nice enough to post a full refund of the money after I submitted a dispute on the PayPal website.</p>
<p>The analysis of my computer did not turn up anything that could have been used to grab my PayPal credentials and make the transfer and I did scan it with a multitude of scanners.</p>
<p>The support line at PayPal was not helpful at all and could not even tell me if I was the only one that has logged into my own PayPal account recently claiming that it was against their privacy policy to disclose such data. That was <strong>very</strong> unfortunate because it would have helped me tremendously to know if someone logged into my account to make the payment.</p>
<p><span id="more-5373"></span>I was contacted at the same day by Steve Ragan from <a href="http://www.thetechherald.com/article.php/200827/1391">The Tech Herald</a> who published an interview about the case on the website. That interview seemed to have sparked the interest of PayPal because I was shortly after contacted by their CISO who wanted to transfer my case to a specialized team, he called it <strong>unusual e-crimes investigations team</strong>. That was a pleasant surprise and I had hopes that I would finally find out how the money was transferred.</p>
<p>Unfortunately though I have not heard back yet and I&#8217;m not sure if I ever will. I know that some big companies are rather slow when working on cases but it has been two weeks and no reply since.</p>
<p>Last but not least Steve contacted me again telling me that the guys at <a href="http://www.verisign.com/">VeriSign</a> would like to send me one of those PayPal Security Key after they have heard the story which is really nice of them. Unfortunately though I have ordered one already which has not arrived yet. It&#8217;s also been two weeks since then and I&#8217;m beginning to see a pattern here. So VeriSign nice, PayPal not so nice. I will keep you updated if I&#8217;m ever contacted again by PayPal about this matter.</p>
<p><strong>Update:</strong></p>
<p>I received both the PayPal Security Key and the VeriSign ID Protection key shortly after finishing the article. Will write about those soon.</p>

	Tags: <a href="http://www.ghacks.net/tag/paypal/" title="paypal" rel="tag">paypal</a>, <a href="http://www.ghacks.net/tag/paypal-payment/" title="paypal payment" rel="tag">paypal payment</a>, <a href="http://www.ghacks.net/tag/paypal-security/" title="paypal security" rel="tag">paypal security</a>, <a href="http://www.ghacks.net/tag/the-tech-herald/" title="The Tech Herald" rel="tag">The Tech Herald</a>, <a href="http://www.ghacks.net/tag/unauthorized-payment/" title="unauthorized payment" rel="tag">unauthorized payment</a>, <a href="http://www.ghacks.net/tag/verisign/" title="VeriSign" rel="tag">VeriSign</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/07/02/unauthorized-payment-done-with-my-paypal-account/" title="Unauthorized Payment Done With My PayPal Account (July 2, 2008)">Unauthorized Payment Done With My PayPal Account</a> (50)</li>
	<li><a href="http://www.ghacks.net/2008/11/24/paypal-now-offering-mobile-security-key/" title="PayPal Now Offering Mobile Security Key (November 24, 2008)">PayPal Now Offering Mobile Security Key</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/07/19/protect-paypal-accounts-with-verisign-identity-protection-devices/" title="Protect PayPal Accounts With VeriSign Identity Protection Devices (July 19, 2008)">Protect PayPal Accounts With VeriSign Identity Protection Devices</a> (19)</li>
	<li><a href="http://www.ghacks.net/2009/11/09/paypal-login/" title="PayPal Login (November 9, 2009)">PayPal Login</a> (1)</li>
	<li><a href="http://www.ghacks.net/2006/06/29/send-a-fax-to-unsubscribe-from-paypals-newsletter/" title="Send a Fax to unsubscribe from paypals newsletter (June 29, 2006)">Send a Fax to unsubscribe from paypals newsletter</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/07/17/update-on-my-paypal-story/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>
