Advertisement
Top

PayPal’s Two-Factor Authentication Bypassed

June 26, 2014

Category:

A vulnerability in the authentication flow of the PayPal API web services allowed access to an account protected by PayPals two-factor authentication (2FA) mechanism. 2FA is a supplementary security measure which requires entering an additional code that is generally sent to the owners email address or mobile phone as a short text message. PayPal mobile apps cannot be used to access accounts that have 2FA enabled, but it seems that the log in procedure is still carried out in l…