Security




Security tokenedit

In early 2006, PayPal introduced an optional security key as an additional precaution against fraud. A user account tied to a security key has a modified login process. Account-holders enter their login ID and password as normal but are then prompted to enter a six-digit code provided by a credit card sized hardware security key or a text message sent to the account holder's mobile phone. For convenience, users may append the code generated by the hardware key to their password in the login screen. This way they are not prompted for it on another page. This method is required for some services, such as when using PayPal through the eBay application on iPhone.

This two-factor authentication is intended to make it difficult for an account to be compromised by a malicious third party without access to the physical security key, although it does not prevent the so-called Man in the Browser (MITB) attacks. However, the user (or malicious third party) can alternatively authenticate by providing the credit card or bank account number listed on their account. Thus the PayPal implementation does not offer the security of true two-factor authentication.

MTANedit

It is also possible to use a mobile phone to receive an mTAN (Mobile Transaction Authentication Number) via SMS. Use of a security code that is sent to the account holder's mobile phone is currently free.

Comments

Popular posts from this blog

Digital marketing with PayPal

PayPal

Safety and protection policies