Mobile & Wireless

Podcast: Zach Lanier on PayPal Two-Factor Authentication Bypass

<p><img src="/sites/default/files/imagecache/slider/SecurityConversations-Podcast.jpg" alt="Security Conversations Podcast" title="Podcast: Zach Lanier on PayPal Two-Factor Authentication Bypass" width="225" height="141" style="float: right; margin: 5px 10px;" /></p>

Zach Lanier, senior security researcher at Duo Security, talks to Ryan Naraine about a gaping hole in the way two-factor authentication is implemented in the PayPal mobile app (iOS and Android). Because of this bypass, an attacker with a PayPal user’s username and password, even if it is a two-factor-enabled account, can access the account and transfer money — all without two-factor being enforced.

Related: PayPal Two-Factor Authentication Bypassed

Related Content

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version