7 ms·
Yea, years ago I was in the security space and got to talk to some paypal security folks at a symposium in San Diego. The level of stuff that they have to deal
by brightball 21d ago
Yea, years ago I was in the security space and got to talk to some paypal security folks at a symposium in San Diego. The level of stuff that they have to deal with is so extreme.
It's similar to how people don't like sites blocking entire countries or access from Tor, etc. You might be doing it for privacy...but all the people trying to commit fraud are also using those same channels to hide their identity. The blockades are one piece of a holistic security picture that frustrate the well intentioned users.
- axegon_ 21d agoYet another weak point. My question stands: A user with an OS from 2019 is "secure" and dozens of unpatched CVEs but a literally-last-night-patch OS is not? That's the "stuff they have to deal with"? I was lucky and did not make the mistake of joining a payment provider in 2020 or 2021 (I can't remember). The reality is that European laws are much harsher when it comes to payments and personal data protection and the security team I was being interviewed for was catastrophic(big part of the reason I did the "I accepted another offer already, sorry" card). As for geo fencing or blocking Tor... HAH! As if that's ever stopped anyone with the will. That is the last concern of anyone with a malicious intent. Sure, it stops irritating kids but no one beyond that. The simple fact is that cybersecurity was in an abysmal state before the slopification began and it's infinitely worse now. Paypal is no different given that much of their support has been outsourced to slop machines. Punishing the users that know what they are doing while rewarding the ones that don't is the most counter-productive and detrimental crap anyone could come up with.
- browningstreet 21d ago> That's the "stuff they have to deal with"? No. It's the offensive fraud vector coming from unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector.
- axegon_ 21d ago> unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector. Bullshit! Source: > The reality is that European laws are much harsher when it comes to payments and personal data protection and the security team I was being interviewed for was catastrophic Sounds like someone who wanted to impress the audience with fluffed up claims.
- Zedfragg 20d agoIt's comments like yours that remind me of an important lesson. Just because you argue with vigor and intent, it doesn't make you right. People are offering their opinions, try not being a dick about it. GrapheneOS is a privacy orientated OS which is great. But if the vectors to achieve privacy are the same as used by bad actors, I'd block it too. Get over it, don't like it? Use a different product. Or make a better one.
- brightball 20d agoI don't run their business. Just trying to explain. From what we see above it sounds like the change trips their rootkit detection, which they are probably interpreting as a compromised device. It sounds like you're expecting them to have a perfect security posture that can correctly identify fraud in call cases and only block the real thing. It's more complicated than that and there's typically some type of scoring system involved with numerous triggers that are higher value indicators of potential fraud. If they think the device is compromised, that's probably a high value indicator. This is just me speculating.
- a2ff6eeb0 20d agoYeah, they can track and profile the old os, and feed the data to the risk models. It's not about user security.
- xelxebar 20d agoThis is interesting. You're gesturing at the idea that individual security practices can be at odds with those needed for group security. I'll be pondering on this.
- brightball 19d agoYep. If a security team sees 96% of credit card fraud is coming from users on Tor they are more likely to just block Tor than they are to try to figure out how to safely let the other 4% keep using it.