Researcher says PayPal's two-factor authentication is easily beaten
A security feature offered by PayPal to help prevent accounts from being taken over by hackers can be easily circumvented, an Australian security researcher has found. — PayPal users can elect to receive …
Context & Ripple Effects
Security scrutiny of big financial sites is an old beat — a 2007 study found flaws on the websites of major banks — but this disclosure hits a newer target: the second-factor defenses payment platforms added precisely because passwords alone kept failing.
The story travelled unusually far on day one, picked up by Slate, Ars Technica, The Verge, and Help Net Security alongside security blogs, because of where PayPal stood in mid-2014: it had just launched a Galaxy S5 fingerprint-payment app, shipped apps for Samsung wearables, expanded its Pay at Table and Order Ahead services to the UK and Australia, and folded in Braintree. A bypassed second factor undercuts the trust narrative underneath that whole consumer push.
First-order effects
- PayPal users who enabled the two-factor option were getting less protection against account takeover than the feature implied, and PayPal faces immediate pressure to fix the bypass and tell customers what their accounts are actually protected by.
- The finding hands every rival wallet and payment service a talking point: authentication strength, not just checkout convenience, becomes part of the pitch.
Second-order effects
- PayPal's own recent moves — the Galaxy S5 fingerprint app and the Samsung wearable apps — shift from novelty to necessity, since biometric factors are the obvious answer to a broken SMS-style second factor.
- High-profile payment 2FA becomes a standing target for researcher disclosures, raising the reputational cost for any fintech shipping a weak implementation.
Third-order effects
- If weak second factors keep falling in consumer finance, the industry drifts toward stronger factors — biometrics or hardware-backed tokens — and 'we offer two-factor authentication' stops being a sufficient security claim for regulators and banking partners.
- Account-takeover defense consolidates around whoever controls the strongest identity signal, pressuring platforms like PayPal to own authentication end-to-end rather than bolt it on.
The trend: Consumer payment platforms are adding new authentication signals — fingerprints, wearables, tokens — faster than they harden the legacy second factors already protecting hundreds of millions of accounts.