secure your paypal before it’s too late

Last week, I blog about the appearance of Paypal Security Challenge (captcha) screen, which shows up on the screen, once I logged in into my Paypal account. I never came across it  before. It’s odd.. The same screen won’t appear again, even though I purposely key in wrong password multiple times using different system. What I’m wondering is, if this screen appears whenever there are repetitive invalid attempts by unauthorized user/bot to access my account,  as pointed out by Eches. Sounds creepy huh?

Back to the CAPTCHA, it is not a new stuff in Paypal. According to the source in Wiki, Paypal has been using it (and some say invent it) since 90s to block an attempt by automated system to access Paypal. However, I’ve no answer on  what kind of form or situation triggering this CAPTCHA

A quick check on my RSS feed spot 2 webmasters on Ghacks and Saifulsham(his brother) who has their Paypal account fund been stolen or used for unauthorized transaction. Fraud can happen to anyone, even without you notice it or provide early signal.  Even after all security measure being taken, to ensure the safety of the account, this kind of thing can still happen when hackers become more creative than ever.

1 commentator in Ghack point me out to Youtube, where there are a lots of how-to-hack-paypal videos. I watch couple of them, including the one on top of the search result. It shows how to update certain paramenter on salespages’s source code to buy stuff on net with 1 cent.  I never tried it (and not gonna tried it), so I’m not sure if it works now. But it give basic impression that fully automated peyment system using Paypal is not that secure, without the involvement of human check.

There are couple of points that I learn from these 2 posts. I bet you know it, but not yet implement it. First and foremost is, don’t ever use your Paypal account (your email) for any registration, regardless with any kind of services. You might also consider to limit the usage of your Paypal email account even for email purpose. Use or create a new email account

Use debit card instead of credit card for your Paypal account. I’m sure many will disagree with this, but please give it some thought. Here is why. In case your account hacked, the damage is minimum to the extent of fund only in your account. You’re not risking losing more money since debit card amount is limited and most of the time, it only has amount whenever you want using it

Be careful when selling your Paypal fund for cash in forum. Your identity is in risk even though you’re registered using different email address. This is especially true if your password is not strong enough, which consist of common personal info such as your name, your nickname, what you like, your website etc. All these infos are crucial for intruder,  in process of guessing your password using automated system, thus gain a control. But you shouldn’t put much worry on this, if your password is strong enough.

Other than that, you might want to consider login into your e-commerce account (such as Paypal) from only your system. Avoid using public computer by any means if possible. You might not aware that public computer could have been installed with keylogger.  It’s not hard to find free keylogger nowadays. There are tonnes of free keylogger available on the net

OK now, it’s turn to listen to Paypal advice (taken from their website)

Website Security

  • Type in the PayPal URL: To safely and securely access the PayPal website or your PayPal account, open a new web browser (e.g., Internet Explorer or Netscape) and type in the following: https://www.paypal.com/

Password Safety

  • Never share your PayPal password: PayPal representatives will never ask you for your password. If you believe someone has learned your password, please change it immediately and contact us.
  • Create a secure password: Choose a password that uses a combination of letters, numbers, and symbols. For example, $coo!place2l!ve or 2Barry5Bonds#1. Avoid choosing obvious words or dates such as a nickname or your birth date.
  • Keep your PayPal password unique: Don’t use the same password for PayPal and other online services such as AOL, eBay, MSN, or Yahoo. Using the same password for multiple websites increases the likelihood that someone could learn your password and gain access to your account.

Email Security

  • Look for a PayPal Greeting: PayPal will never send an email with the greeting “Dear PayPal User” or “Dear PayPal Member.” Real PayPal emails will address you by your first and last name or the business name associated with your PayPal account. If you believe you have received a fraudulent email, please forward the entire email—including the header information—to spoof@paypal.com. We investigate every spoof reported. Please note that the automatic response you get from us may not address you by name.
  • Don’t share personal information via email: We will never ask you to enter your password or financial information in an email or send such information in an email. You should only share information about your account once you have logged in to www.paypal.com/row.
  • Don’t download attachments: PayPal will never send you an attachment or software update to install on your computer.

Use Your Account Wisely

  • Don’t share your account: Don’t use your PayPal account to collect or transfer money for someone else. These types of activity are often conducted as forms of money laundering or mail fraud and may result in significant criminal penalties. If someone contacts you and asks you to transfer money on their behalf, you should deny the request and contact us immediately.
  • Increase your security: Become a Verified PayPal member.
  • Look for legitimate sites: Examine all privacy and security seals before doing business with a particular website and make sure they are legitimate.
  • Related Posts

    RSS feed | Trackback URI

    14 Comments »

    2008-07-11 23:25:00

    nightmare belajar hack. beware always. a lot’s of way they can think to grab the chances. the wrong way now have a case study how to hacking with tutorial in video… creative for illegal way. get ready for secure security from them. be alert always. it’s same like email banking alert to about upgrading their system. once you get in and using without carefully. you going in a nightmare with your saving.

    i don’t understand why we must used same password for all login id that same to.

     
    Comment by KNizam
    2008-07-12 11:26:28

    i have yet to use any paypal so far. hehe :)

     
    Comment by Michael
    2008-07-14 18:09:22

    Thanks for the heads up!!

     
    Comment by azwanhadzree Subscribed to comments via email
    2008-07-16 04:18:18

    i always login from the same notebook.

     
    Comment by topo
    2008-07-16 10:38:57

    aku baru je bercadang nak bukak akaun paypal… tapi macam banyak kes je… ohohoh tunggu la ilmu penuh di dada dulu…

     
    Comment by hank freid
    2008-07-17 08:24:01

    I am also user it. Thanks for you suggestion.

     
    Comment by Jayce
    2008-07-18 11:43:55

    Really need to be careful in this Internet world. :D

     
    Comment by Raymond Chua Subscribed to comments via email
    2008-07-20 14:03:53

    I always feel safe whenever I see the https:// :)

    Comment by titan
    2008-07-22 21:40:34

    i agree with raymond. As long as i see that ’s’, i will feel safe..

     
     
    Comment by Hein Lehmann
    2008-08-02 08:33:43

    I have to do this now. You are right. I should not make any delay.

     
    Comment by cats as pet
    2008-08-05 09:13:49

    Hmm.This type of things I always enjoy a lot.Thanks for sharing.
    Thanks

     
    Comment by Lisa
    2008-08-11 05:38:03

    very informative article, thanks for keeping us on our toes & thinking safely when it comes to the internet. I know there are plenty of weirdos out there that have WAY too much time on there hands & just try & screw up people’s lives.

     
    Comment by Kids Bible Crafts
    2008-08-20 21:03:37

    It sucks that you always have to have your guard up no matter how safe you think the site is. Don’t these people realize they are not hurting the big company they are hurting individuals who work hard for their money. Thanks for the heads up!

     
    2008-11-26 22:21:26

    [...] second security layer to us just yet, so make sure you secured your account [...]

     
    Name (required)
    E-mail (required - never shown publicly)
    URI

    Subscribe to comments via email
    Your Comment (smaller size | larger size)
    You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.