Author Topic: PayPal mistakes own email for phishing attack  (Read 8076 times)

da_ewok

  • Action Group
  • Knight of the RT
  • *****
  • Posts: 1742
    • It Ain't Always My Life!
PayPal mistakes own email for phishing attack
« on: December 05, 2009, 10:10:50 AM »
'You're right, it does look suspicious'

By John Leyden • Get more from this author

Posted in Crime, 4th December 2009 13:32 GMT

Free whitepaper – Secure and managed file transfer in the era of regulatory compliance

Banks and financial institutions are fond of lecturing customers about the perils of phishing emails, the bogus messages that attempt to trick marks into handing over their login credentials to fraudulent sites. Yet many undo this good work by sending out emails themselves that invite users to click on a link and log into their account rather than going a safer route and telling users to use bookmarked versions of their site.

The problems of the former approach are neatly illustrated by a blog posting by Randy Abrams, a former Microsoft staffer who is now director of technical education at anti-virus firm Eset. Abrams complained about the inclusion of a link in an email from PayPal as it looked rather too much like a phishing email.

PayPal support staffers responded not by noting that Abrams may have a point, which it would consider, but by treating its own email - which it acknowledged was "suspicious-looking" - as a phishing attack.

"Not even PayPal support can tell the difference between a legitimate PayPal email and a phishing attack," Abrams notes.

PayPal is one of the most phished brands on the internet, a back-handed tribute to the eBay subsidiary's success in the online payment market, so it would do well to listen to Abrams' advice not to include links to login pages in genuine communiques. Many banks make exactly the same security faux pas, as many Reg correspondents over the years will attest, and also need to revise their procedures. ®

Courtesy of "The Register" http://www.theregister.co.uk/2009/12/04/paypal_phishing_false_alarm/
"I've just been in a bad mood for 40 years"

http://www.marysvillecookbook.com/ $7,800 **Raised as at 22nd March 2013**
Photos by Enigma - Iphone cases too! :D http://www.redbubble.com/people/photosbyenigma

cueperkins

  • Guest
Re: PayPal mistakes own email for phishing attack
« Reply #1 on: December 05, 2009, 10:22:37 AM »
The exact same thing happened with my previous Anti Virus provider....they assumed a debit authority because I'd paid my bill the year before with a credit card.....no approval from me to do so.....then when they found the credit card in question had been closed.....the sent me an email, telling me to click on a link and update those details online?....like dreamin  !!!!

I rang the company and they confirmed it was a legitimate email, and I asked them what they didn't comprehend about phishing emails asking the exact same thing?  i.e. just click on the link and give your CC details to god knows who?....still dreamin......

American company of course, so they just didn't 'get it'......and I changed to another anti virus that did 'get it'....lol.  Dumb

Woops nearly forgot.....Hi Wokkie.... :welcomedesk:

da_ewok

  • Action Group
  • Knight of the RT
  • *****
  • Posts: 1742
    • It Ain't Always My Life!
Re: PayPal mistakes own email for phishing attack
« Reply #2 on: December 05, 2009, 10:28:11 AM »
I thought you would like that - just shows how stupid Paypal really can be :(

Add to that the fact that Paypal are in bed with eBay and that eBay are trying to 'lose' direct debit payments in AU, let's not worry about the USA market. ONLY the AU market here

We are not dumb, even though Paypal/EBay think we are - we can see collusion even they won't
"I've just been in a bad mood for 40 years"

http://www.marysvillecookbook.com/ $7,800 **Raised as at 22nd March 2013**
Photos by Enigma - Iphone cases too! :D http://www.redbubble.com/people/photosbyenigma

*CountessA*

  • Administrator
  • Knight of the RT
  • *****
  • Posts: 35157
Re: PayPal mistakes own email for phishing attack
« Reply #3 on: December 05, 2009, 10:43:04 AM »
Ewok, you have made a connection I had not previously considered. The incidence of genuine emails from PayPal looking and functioning rather like phishing emails, PayPal's discouragement of debit payments... but I'm not quite sure I see the connection between "direct debit" (payment authority) and PayPal/eBay.
"No man is an Iland, intire of it selfe; every man is ...a part of the maine; ...any mans death diminishes me, because I am involved in Mankinde"

da_ewok

  • Action Group
  • Knight of the RT
  • *****
  • Posts: 1742
    • It Ain't Always My Life!
Re: PayPal mistakes own email for phishing attack
« Reply #4 on: December 05, 2009, 10:51:02 AM »
Quote
(1)I thought you would like that - just shows how stupid Paypal really can be

(2)Add to that the fact that Paypal are in bed with eBay and that eBay are trying to 'lose' direct debit payments in AU, let's not worry about the USA market. ONLY the AU market here

(3)We are not dumb, even though Paypal/EBay think we are - we can see collusion even they won't

Answers:-
(1) Paypal are stupid - we are constantly being told NOT to click links contained with emails, even Paypal advise us as far - yet they send links in their emails - THEY ARE STUPID

(2) Paypal/Ebay are the same company - regardless of the structure - they have tried endlessly to hide the DD payment facility, not send the payment information, make the AU site PP only. We have the proof of that arguement in the ACC fight. So yes they are trying to 'lose DD facility and make it not readily available to AU users

(3) Even though EB/PP deny any sort of financial benefit from the seller owning the payment company, there is self-interest to ensure that paypal becomes the preferred option - Without a paypal account - you can not sell anything on ebay - therefore they have already excluded some sections of the market and are happy to continue doing so until it becomes 'economically' unviable to provide Direct Debit and thus it's PAYPAL ONLY - It could take 10 years but IT WILL HAPPEN

Paypal have already admitted that their profits have increased and that is purely because of ebay - nothing else
"I've just been in a bad mood for 40 years"

http://www.marysvillecookbook.com/ $7,800 **Raised as at 22nd March 2013**
Photos by Enigma - Iphone cases too! :D http://www.redbubble.com/people/photosbyenigma

cueperkins

  • Guest
Re: PayPal mistakes own email for phishing attack
« Reply #5 on: December 05, 2009, 10:57:46 AM »
As usual Wokkie....Spot On.... :applause: :applause: :applause:

gr8-expectations

  • Guest
Re: PayPal mistakes own email for phishing attack
« Reply #6 on: December 05, 2009, 11:01:41 AM »
Quote
(1)I thought you would like that - just shows how stupid Paypal really can be

(2)Add to that the fact that Paypal are in bed with eBay and that eBay are trying to 'lose' direct debit payments in AU, let's not worry about the USA market. ONLY the AU market here

(3)We are not dumb, even though Paypal/EBay think we are - we can see collusion even they won't

Answers:-
(1) Paypal are stupid - we are constantly being told NOT to click links contained with emails, even Paypal advise us as far - yet they send links in their emails - THEY ARE STUPID

(2) Paypal/Ebay are the same company - regardless of the structure - they have tried endlessly to hide the DD payment facility, not send the payment information, make the AU site PP only. We have the proof of that arguement in the ACC fight. So yes they are trying to 'lose DD facility and make it not readily available to AU users

(3) Even though EB/PP deny any sort of financial benefit from the seller owning the payment company, there is self-interest to ensure that paypal becomes the preferred option - Without a paypal account - you can not sell anything on ebay - therefore they have already excluded some sections of the market and are happy to continue doing so until it becomes 'economically' unviable to provide Direct Debit and thus it's PAYPAL ONLY - It could take 10 years but IT WILL HAPPEN

Paypal have already admitted that their profits have increased and that is purely because of ebay - nothing else

great posts all of them wokkie and bang on, even when you DO have your bank details showing as i do, quite often they dont show up and customers have the message you and go through "war and peace" to get them, it sucks and where is Paymate on the au ebay site? No sign of it, far better and more relaible/secure service and aussie owned

da_ewok

  • Action Group
  • Knight of the RT
  • *****
  • Posts: 1742
    • It Ain't Always My Life!
Re: PayPal mistakes own email for phishing attack
« Reply #7 on: December 05, 2009, 11:03:43 AM »
**Waves** Hi gr-8

I made reference to the Payment information not being readily available under point 2

Quote
(2) Paypal/Ebay are the same company - regardless of the structure - they have tried endlessly to hide the DD payment facility, not send the payment information, make the AU site PP only. We have the proof of that arguement in the ACC fight. So yes they are trying to 'lose DD facility and make it not readily available to AU users
"I've just been in a bad mood for 40 years"

http://www.marysvillecookbook.com/ $7,800 **Raised as at 22nd March 2013**
Photos by Enigma - Iphone cases too! :D http://www.redbubble.com/people/photosbyenigma

gr8-expectations

  • Guest
Re: PayPal mistakes own email for phishing attack
« Reply #8 on: December 05, 2009, 11:03:56 AM »
this is about the only site where there is any proper scrutiny of them in oz, or as regular about it as this site allowing members to freely have their say, sad indictment of the mainstream media aalthough i know there are some good news sites that do a very good job on one off type issues

imagine if this site were NOT here = no voice at all for the average seller/buyer, all would be buried and hidden

cueperkins

  • Guest
Re: PayPal mistakes own email for phishing attack
« Reply #9 on: December 05, 2009, 11:05:11 AM »
I'm one of those who refused to be extorted into using a payment system I don't trust after selling and buying on ebay as a collector for 7.5 years.....I feel distinctly discriminated against.....who doesn't?...I absolutely won't sign up to that pirate payment system until it signs the EFT code...plain and simple....I like consumer protection....who doesn't?.

The thing that people don't seem to realise is that the issue with ACCC was on behalf of competition in the EFT marketplace, not the online auction/bin marketplace.......This is where the sellers really have to start making a big noise because clearly Ebay is doing everything in it's power to deter the use of bank deposit, and manipulating the marketplace to their own advantage...it's called Misuse of Market Power, (Them being a monopoly and all that) but who's lookin right?......

What the sellers need to be doing is banding together to lodge a united complaint against Ebay's: 1)contract deterring competition, 2) misuse of marketpower 3) manipulation of small business via a contract that affords traders no negotiation power, and 4) anticompetitive conduct both in the EFT marketplace and the online Auction/BIN marketplace.....  

Until traders on Ebay start making a BIG noise with ACCC, it's unlikely anything will change.....but then regulators like AUSTRAC seem to have their eye on the ball...lol....

gr8-expectations

  • Guest
Re: PayPal mistakes own email for phishing attack
« Reply #10 on: December 05, 2009, 11:05:24 AM »
yes wokkie they hide it in all sorts of ways, thats my biggest beef with the accc and  and asic for not holding them accountable, surely its "deceptive and misleading conduct' under that section of the tpa?

gr8-expectations

  • Guest
Re: PayPal mistakes own email for phishing attack
« Reply #11 on: December 05, 2009, 11:07:17 AM »
i have said it many times cupie but a "class action" a significant sized one is the ONLY way ebay/preypal will sit up and take notice

and those sorts of actions are success fee driven in terms of lawyers its just a matter of enough people being angry enough and not too complacent to do it, the worst enemy here is complacency

cueperkins

  • Guest
Re: PayPal mistakes own email for phishing attack
« Reply #12 on: December 05, 2009, 11:08:59 AM »
I think it's that but more 'Misuse of Market Power' GR8

cueperkins

  • Guest
Re: PayPal mistakes own email for phishing attack
« Reply #13 on: December 05, 2009, 11:09:45 AM »
i have said it many times cupie but a "class action" a significant sized one is the ONLY way ebay/preypal will sit up and take notice

and those sorts of actions are success fee driven in terms of lawyers its just a matter of enough people being angry enough and not too complacent to do it, the worst enemy here is complacency

Class actions are expensive and damages hard to prove.....TPA however, is supposed to protect small business from this type of predatory manipulation.....and it's free.....

da_ewok

  • Action Group
  • Knight of the RT
  • *****
  • Posts: 1742
    • It Ain't Always My Life!
Re: PayPal mistakes own email for phishing attack
« Reply #14 on: December 05, 2009, 11:11:36 AM »
i have said it many times cupie but a "class action" a significant sized one is the ONLY way ebay/preypal will sit up and take notice

and those sorts of actions are success fee driven in terms of lawyers its just a matter of enough people being angry enough and not too complacent to do it, the worst enemy here is complacency

Correct and no-one wants to work together - ebay have done a fine job of destroying any community feeling - that is why they shut forum - to stop that sort of networking and thus remove the contact and hope things will go quiet

There is a saying for it - but I can't recall off the top of my head
"I've just been in a bad mood for 40 years"

http://www.marysvillecookbook.com/ $7,800 **Raised as at 22nd March 2013**
Photos by Enigma - Iphone cases too! :D http://www.redbubble.com/people/photosbyenigma

*CountessA*

  • Administrator
  • Knight of the RT
  • *****
  • Posts: 35157
Re: PayPal mistakes own email for phishing attack
« Reply #15 on: December 05, 2009, 11:22:14 AM »
"Break the connections and the resistance fails".

My reply: "Break the connections and we will build our own."
"No man is an Iland, intire of it selfe; every man is ...a part of the maine; ...any mans death diminishes me, because I am involved in Mankinde"

HellWest'nCrooked

  • Knight of the RT
  • *****
  • Posts: 4778
Re: PayPal mistakes own email for phishing attack
« Reply #16 on: December 05, 2009, 11:54:36 AM »


"divide and conquer"  wokkie????
Ain't no rhyme or reason
No complicated meaning

da_ewok

  • Action Group
  • Knight of the RT
  • *****
  • Posts: 1742
    • It Ain't Always My Life!
Re: PayPal mistakes own email for phishing attack
« Reply #17 on: December 05, 2009, 12:00:46 PM »
That's it - Divide and Conquer - that is exactly what Ebay are hoping to do by shutting down the forums

Thank-you! ;D
"I've just been in a bad mood for 40 years"

http://www.marysvillecookbook.com/ $7,800 **Raised as at 22nd March 2013**
Photos by Enigma - Iphone cases too! :D http://www.redbubble.com/people/photosbyenigma