Sponsored Link
Email This Post Email This Post

PayPal Says It’s Not Impacted By Latest Internet Security Vulnerability

Webmasters and security experts must deal with yet another vulnerability affecting a popular open-source software. Named Covert Redirect, it affects authentication software OpenID and authorization software OAuth, making visitors to websites vulnerable to phishing attacks that try to trick users into revealing private information

VentureBeat says the vulnerability was discovered by Wang Jing, a doctoral student in Singapore.

eBay has not yet responded to our inquiry about a possible impact from the vulnerability. Update: eBay spokesperson Ryan Moore said the OAuth 2.0 and OpenID vulnerabilities have no impact on eBay, and eBay accounts remain secure.

A PayPal spokesperson referred us to a statement from PayPal’s Chief Technology Officer James Barrese:

As always, it’s important to us to keep our customers informed, connected and aware of how we’re addressing any concerns you have with our products or services.

When we heard that security researchers recently discovered a vulnerability in open source login tools OAuth 2.0 and OpenID (which are widely used by many websites and web services, including some offered by PayPal) we moved quickly to determine the impact to our customers. We have carefully investigated this situation and can tell you that this vulnerability has no impact on PayPal and your PayPal accounts remain secure.

We take the responsibility of keeping your financial details protected very seriously at PayPal. When PayPal implemented OAuth2.0/OpenID, we engineered additional security measures to protect our merchants and customers. These measures protect PayPal customers from this specific OAuth2.0/OpenID vulnerability.

We want to reassure you that if your PayPal account is accessed without your permission, PayPal will help you resolve the problem and will cover 100% of any eligible transactions to keep your money secure.

Mashable says it’s not a new problem and quotes a developer who says the problem comes with how certain companies choose to implement OAuth, not with the framework itself. But clearly a type of vulnerability average users should know about in order to protect themselves.

Ina Steiner on EmailIna Steiner on LinkedinIna Steiner on Twitter
Ina Steiner
Ina Steiner
Ina Steiner is co-founder and Editor of EcommerceBytes and has been reporting on ecommerce since 1999. She's a widely cited authority on marketplace selling and is author of "Turn eBay Data Into Dollars" (McGraw-Hill 2006). Her blog was featured in the book, "Blogging Heroes" (Wiley 2008). She is a member of the Online News Association (Sep 2005 - present) and Investigative Reporters and Editors (Mar 2006 - present). Follow her on Twitter at @ecommercebytes and send news tips to ina@ecommercebytes.com. See disclosure at EcommerceBytes.com/disclosure/.