Brian Krebs criticises PayPal’s security as authentication flaws exposed

The suggestions were:

Ask for the 2FA code

A code I was sent a long time ago which may well be lost, which is why I'm phoning up to regain access to my account. Otherwise a good idea.

Call him back on his registered phone number

I don't want to give PayPal a phone number they can sell and so they've got a fake number.

Ask for the last x Pay Pal transaction

I don't use PayPal very much but even I can't remember that.

Ask for his last login time/date

I certainly can't remember that!

Mark his account as supervisor changes only with extra verification required

What extra verification?

