PayPal Allows Bypassing Two-Factor Auth with a Button Click

  • Yup, hackers run through leaked email addresses, or target people. If your email is listed in haveibeenpwned.com dumps, scripts are processing the lists.

    Only real basic things you can do, dont use your primary cell/emails as 2FA backup. Amazed theres no company offering security enabled sms enabled numbers via a webpage to plug the sms hole.

    And if you use your primary cell for 2fa, call your carrier and put a no-transfer lock on your account. This is how the bitcoin hacks happen.

    Also, google has titan keys, they ignore them for 2FA also. Kinda mornic.

  • The worst is PayPal for iOS. Even with Face ID turned on, I still have to enter my TOTP code, EVERY time I open the app.