Hacker News new | ask | show | jobs
by Crosseye_Jack 2495 days ago
It’s still SMS 2FA. What I do is don’t have payment cards saved to the account.

You used to be able to use your PayPal football back in the day (a paypal branded verisign hardware 2FA) or the VIP app but they have slowly been removing that in favour of SMS 2FA to the point where I don’t think you can even add a VIP token if you tried (used to be that you could add one, but they would try their hardest to make you use SMS instead).

If you had it enabled back in the day, it’s still active on your account (both on eBay and PayPal) but you will often find your login in flow disrupted if you still use the “old style” 2FA. (Example on some login pages but not all you are able to login by amending your code to your password. But it’s hit and miss and iirc you can’t use the PayPal app at all if you have 2FA enabled and have to do business via the website.

Note: I’m aware that PayPal and eBay are 2 separate companies now. But for the longest time they acted as one that their application flow feels every similar to each other even still.

1 comments

I was using PayPal on my account, and they didn't have a legit 2FA back then either (now they do, thankfully). Blows my mind that something as crucial and attack-desirable as a payment system wouldn't have a legit 2FA in 2017, even though random places with way less import stuff to lose like Twitch would.