PayPal fights fraud with password key fob

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

Topics

Password, eBay, PayPal

NEWS

eBay is getting ready to offer its PayPal users a password-generating key fob that promises to increase the security of the online payment service.

The device displays a new one-time password in the form of a six-digit code about every 30 seconds. PayPal clients who opt to use the device will enter this password along with their regular credentials when signing into the service. The key fob is meant as another weapon in the battle against data-thieving phishing scams.

"If a fraudulent party somehow got hold of a person's username and password, they still wouldn't be able to get into the account because they don't have the six-digit code," Sara Bettencourt, a PayPal spokeswoman, said by phone on Thursday. "This by no means is a silver bullet that is going to stop fraud. This is just another layer of protection."

The "PayPal Security Key" will cost $5 (£2.56) for personal PayPal accounts, but will be free for business accounts, Bettencourt said. PayPal has been testing the device with employees for a couple of months and plans to start trials with customers in the next month or so, she said. As of 30 September, there were nearly 123 million PayPal accounts, eBay has said.

PayPal users in the US, Germany and Australia will be able to sign up for the trial through a special website, Bettencourt said. "Based on the response, we look forward to eventually rolling it out in other countries," she said.

The password-generating device is based on technology from VeriSign, with which eBay entered into a security partnership in 2005. Such key fobs are also used for added security by large corporations for access to corporate resources, and some banks and brokerage firms offer them to clients with a high net worth. Other companies that supply the password gadgets include RSA and Vasco.

eBay and PayPal are common phishing targets. These prevalent scams typically use fraudulent websites made to look like legitimate sites and spam email to trick people into giving up their personal information such as login names and passwords.

In a recent survey of Google's public blacklist of phishing sites, security researcher Michael Sutton found that nearly half of all the active phishing sites targeted either eBay or PayPal. The Google blacklist is used in Google's Toolbar for Firefox and the Firefox 2.0 browser.

Talkback

The issue with this is that it still doesn't stop a fraudulent site collecting the username and password AND the OTP number. The hacker could then still use this to log into PayPal within the next 30 seconds.

The user would just assume they'd entered something wrong and try again, this time being directed to the real site.

Once the hacker is logged in they can then do what they want.

A stronger solution would have been to add the requirement for the OTP not as an additional log on requirement but whenever a money transfer is made.

1000238202 12 January, 2007 11:28
Reply

If this works the same way as the RSA system which I've used for some time, that cannot happen. If someone tries to log in twice with the same code it is logged as a security problem and log in is denied.

You can only log on using the code once, if the log on fails, you need to wait until the next code shows, and then enter using the latest code.

tribal_tiger 15 January, 2007 08:38
Reply

Can you explain how random passwords generated every 30 seconds, hundreds or even thousands of miles away, can be recognised by PayPal and associated with particular users? What would happen if users generated their own random passwords?

Geoff

194471 15 January, 2007 12:38
Reply

I don't know how this is implemented exactly, but I imagine that PayPal knows the algorithm underlying the pseudo-random number generator in your key fob, and so can correctly predict the pass code that the key fob is generating every 30 seconds.

Chris Rankin 15 January, 2007 13:20
Reply

... and then uses it to login immediately. In the meantime, it puts a "please wait" sign on the screen to keep the user busy for 30 seconds. And if the system forbids multiple simultaneous logins for the same key fob, does that mean that the fraudsters could login before the real owner and lock the real owner out of his/her own account instead?

Chris Rankin 15 January, 2007 13:30
Reply

The algorithms are usually proprietary to the company that produces the keyfobs - Vasco, RSA, etc.

What happens is that the user has to register their keyfob by telling PayPal the serial number on the back, and sometimes syncing it by entering the next one or two numbers that are generated by the fob.

From this point on when a user logs on, PayPal can then use this information to check whether or not the OTP entered by the user matches what its back-end software provided by Vasco, RSA, etc say it should be.

Nick 15 January, 2007 14:50
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

8 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

9 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

10 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

12 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

14 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

15 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

15 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

15 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

16 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

18 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

24 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 day ago by ramwellian on Cloud computing security: no more oxymoron?