Unfortunately, there are few parameters which are still incompatible with REST API including SOLUTIONTYPE which works only in Classic API. This would prevent any attacker gaining access to an account without the user's cellphone or authenticator app, rendering a back-end security check bypass useless. As such, I was told, there's not really a financial risk of "bank accounts being emptied," as such. CyberNews does not claim to have hacked this 2FA process. "At the moment, [PayPal is] writing it off as something 'out-of-scope' just because it involves stolen credentials." The research team went to great lengths to show me the exploit working. We believe the patch for this issue should be pretty straightforward and we essentially want [PayPal] to take action.". Paypal does have genuine two-factor authentication—you can see its set-up in the image below.

The other vulnerabilities raised by CyberNews in its report included intercepting a check on the registering of a new phone to an account as well as bypassing system checks when money is sent from a new device.

I write about the intersection of geopolitics and cybersecurity, and analyze breaking security and surveillance stories.

That becomes apparent when you login from a new device or location as identified by the IP address of your connection. Because the vulnerabilities found are clearly important in themselves, the confusion has obfuscated the debate. Since this security measure requires a separate device beyond the person's username and password, we used the term 2FA as a reference or similarity. And then Paypal does provide security tools that will ensure this hack cannot impact you.

Opinions expressed by Forbes Contributors are their own. PayPal didn't dismiss the issue when I spoke with them, but told me it was a risk they believed was managed by their system. In essence, it would work with phished credentials just as well as with stolen ones, and it links back to that bypassing of the system checks at the login point of the process. This is normally an SMS one-time code, but it can be a PIN number that's separate from your password, or an authenticator app or even an external security key. CyberNews also questions the extent to which the misunderstanding actually matters, suggesting that not many users have enabled the genuine 2FA, relying instead on the systems checks to look after account security. PayPal will then seek to ensure it's you—they have a successful username and password login, but they will run a system check to look for further assurance that it's you.

CyberNews claims—and the company showed me a demonstration—that it can successfully login to an account using basic credentials on a new computer.

Once in, the company will then run further checks on each transaction that you attempt, again to determine whether to approve or challenge.

Again, CyberNews explained that this had been misunderstood, "this specific quote was a general one, in response to all the six vulnerabilities we discovered.

I am the Founder/CEO of Digital Barriers—developing advanced surveillance solutions for defence, national security and counter-terrorism. And last year the FBI—somewhat controversially—warned that secondary authentication was being spoofed by attackers and only biometrics could be seen as attack-proof. PayPal runs a risk check to determine eligibility for guest checkout.

PayPal didn't dismiss the issue when I spoke with them, but told me it was a risk they believed was managed by their system. Now that we can agree to your definition of 2FA, we'd phrase it differently.", And that's the crux here.

To understand the debate between PayPal and CyberNews, it's critical to understand some of the ways in which PayPal safeguards your account. Their 2FA, which is called 'Authflow' on PayPal, is normally triggered when a user logs into their account from a new device, location or IP address.". CyberNews seems to feel very strongly that the issues should be disclosed and patched, and the team seems very frustrated that they haven't been. For the time being, defeating 2FA requires either a hijack of a victim's mobile device or other authentication medium, or else intercepting one-time codes input by the victim into their system. To be frank, as inconvenient as that might be for the login process, given the current climate of credential theft and large-scale data breaches, 2FA is always a good move.