Reply to post: Re: The problem with entirely online companies....

Brian Krebs criticises PayPal’s security as authentication flaws exposed

DaLo

Re: The problem with entirely online companies....

Why could they not do one of the following:

Ask for the 2FA code

Call him back on his registered phone number

Ask for the last x Pay Pal transaction

Ask for his last login time/date

Mark his account as supervisor changes only with extra verification required

etc etc

Basically things that aren't public record.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

SUBSCRIBE TO OUR WEEKLY TECH NEWSLETTER

Biting the hand that feeds IT © 1998–2021