Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

PayPal probably has good enough fraud detection that easier-but-riskier integration is still a net win for PayPal. (Not so much for the rest of the internet, though...)

Similarly, Google's "No CAPTCHA" (https://news.ycombinator.com/item?id=8693767) lets Google offer a better experience than a traditional CAPTHCA. I'm somewhat surprised that better fraud detection leads to better UX, but it's pretty neat.



It's not just PayPal fraud per se. Leaking user's PayPal email address and password has a lot of other consequences. (Yeah yeah in theory you should use distinct passwords for different sites etc etc)


Yes, but if PayPal's security is good enough, that's everyone else's problem.

(Yes, that's pretty nasty - but is putting a poorly-secured "startup" online really any better?)


To log in paypal account password is enough, user-agent and IP/location can be faked. When you're in you get access to user's transaction history. Ouch.


I just spent 10 minutes navigating the Paypal website trying to activate 2-factor auth on my account. Apparently they don't even offer it, at least for Singapore accounts.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: