Skip to main content

PayPal fixed a major problem with its multifactor authentication protection

amazon paypal news office
Ken Wolter
Multifactor authentication has become much more commonplace in recent years, with many experts pointing to the technique as a good method of keeping personal information safe online. However, not all implementations of multifactor authentication are created equal, and it seems that PayPal’s usage didn’t cut the mustard until very recently.

Recently, mobile security consultant Henry Hoggard found himself in a hotel room, needing to make a payment via PayPal. However, there was no phone signal, so he wasn’t able to receive his two-factor authentication token via text message. Hoggard had to think outside of the box.

In the event that a user can’t receive their authentication token, PayPal offers up their security question as an alternative. Upon being given this option, Hoggard quickly discovered a major flaw in the service’s security efforts, according to a report from analyst Graham Cluley.

Hoggard discovered that he could use a proxy to remove certain elements from the post data associated with the security question. By doing so, he could trick PayPal into thinking that he’d answered the question, no matter what he entered into the field, thereby rendering the multifactor authentication protection useless.

Fortunately, Hoggard alerted PayPal to the problem, and the company has now fixed the gap in its security measures. The researcher received a bounty for his part in addressing the issue — and, more importantly, users can be safe in the knowledge that multifactor authentication is being used to its intended effect.

It’s worth noting that an attacker would have needed to know the user’s password in order to actually take advantage of this weakness. That being said, it’s still surprising that such a major online payments service would find this kind of gap in its defenses.

Editors' Recommendations

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
Nvidia could flip the script on the RTX 5090
The Hyte Y40 PC case sitting on a table.

We already know Nvidia is working on its RTX 50-series graphics cards, code-named Blackwell, but the rollout may not go as expected.

According to well-known hardware leaker kopite7kimi, Nvidia plans to launch the RTX 5080 before it launches the RTX 5090. That may not sound like a big deal, but it's a change of pace compared to what we saw in the last generation.

Read more
Best laptop deals: Save on the Dell XPS 14, MacBook Pro 16 and more
The Dell XPS 14 on a white table with the screen open.

While having a desktop computer can be pretty great, laptops offer you a lot of portability, which is especially important if you need something to take with you to work or school. Luckily, there are a lot of choices to pick from, and while the best laptops tend to be quite expensive, there are some pretty great deals that will get you pretty close. There are also a lot of the best laptop brands offering solid budget and mid-range laptops, so even if you're buying on a budget, there's likely a good option for you.

HP Chromebook 14a -- $300, was $370

Read more
The new iPad Pro would be perfect, if only it were a Mac
A person gaming on the M4 iPad Pro and playing Diablo Immortal.

It’s no secret that I’ve been cheering on Apple’s gaming advances over the last year or so. Long-suffering Mac gamers have gone from being the forgotten also-rans of Apple’s ecosystem to feeling on top of the world, all in a very short period of time. But there’s one vital piece missing from the puzzle, and Apple’s new M4 iPad Pros have made it incredibly obvious.

I’ll admit, Mac gamers have been treated well in recent times. Not only have we had phenomenal hardware advancements in the form of the M3 Max chip -- which is a genuine gaming chip so cool and quiet that you’d be fooled into thinking it’s not -- but there’s also been a slate of top-tier games arriving on Apple’s platform, including my beloved Baldur’s Gate 3. It’s a good time to be a Mac gamer.

Read more