By Darren Pauli, 26 Jun 201
PayPal's second factor authentication (2FA) protection can be mitigated through mobile device interfaces that allow fraudsters to steal funds with a victim's username and password, Duo Security researchers say.
The bypass, crimped but not eradicated by client side patches, existed because the PayPal iOS and Android mobile app infrastructure could be tricked into ignoring the existence of 2FA controls in place on users accounts.
The Register/ full read here/ http://www.theregister.co.uk/2014/06/26/paypal_2fa_mobe_flaw_chills_warm_and_fuzzy_security_feeling/
PayPal 2FA mobe flaw chills 'warm and fuzzy' security feeling
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.