A possible design error let researchers bypass two-factor authentication on a PayPal account Credit: http://pictures.reuters.com/ A PayPal error made it possible to bypass two-factor authentication on a user account, demonstrating what can go wrong in deploying a tricky security mechanism.PayPal has deployed a temporary fix for the problem that was the result of what could have been a design flaw in the authentication flow between the payment service’s mobile app and server.[Raising awareness quickly: The eBay data breach]“There’s certainly a lesson to be learned for people doing two-factor authentication now or planning to in the future,” said Zach Lanier, senior researcher for Duo Security, which assisted the outside researcher, Dan Saltman, who discovered the vulnerability. PayPal’s mobile app does not support two-factor authentication (2FA) while its website does. If an accountholder who opted in for the extra security used the mobile app, then the server would notify the app, which would halt the log in process and notify the user.The researchers found a way to take advantage of this clunky set up by building an app that would trick the mobile app into thinking it was dealing with an account that did not have 2FA enabled. The researchers’ app talked to two separate application-programming interfaces (APIs) on PayPal’s server. One handled the authentication while the other was for money transfers.When the app tried to access a 2FA-enabled account, the app would change the “2fa_enabled” value in the server’s response to “false.” This was enough to have the mobile app ignore the 2FA feature and send the user right to the PayPal account.Duo Security, which sells 2FA technology, has provided details of the bypass on its blog.For cybercriminals to exploit the flaw, they would need to first obtain an accountholder’s username and password through a phishing attack or other scheme.PayPay has deployed a temporary fix that neutralizes the researchers’ app. The mobile app no longer works with 2FA-enabed accounts, and those accountholders will have to continue using the PayPal mobile website.PayPal declined comment, pointing instead to its Wednesday blog that played down the mobile app’s lack of 2FA support. “We have extensive fraud and risk detection models and dedicated security teams that work to help keep our customers’ accounts secure from fraudulent transactions, everyday,” the company said.PayPal is expected to release at then of July a permanent fix that will add 2FA support to the mobile app, Lanier said.[Financial firms and social media remain top phishing targets]“When two-factor authentication is done right and consistently (across services) it provides really great value,” Lanier said. “But if you have one weak link in the chain, like we’ve seen here – perhaps a design oversight – that makes this all for naught.” Related content feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO CSO and CISO C-Suite news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry news UK data regulator warns that data breaches put abuse victims’ lives at risk The UK Information Commissioner’s Office has reprimanded seven organizations in the past 14 months for data breaches affecting victims of domestic abuse. By Michael Hill Sep 28, 2023 3 mins Electronic Health Records Data Breach Government news EchoMark releases watermarking solution to secure private communications, detect insider threats Enterprise-grade software embeds AI-driven, forensic watermarking in emails and documents to pinpoint potential insider risks By Michael Hill Sep 28, 2023 4 mins Communications Security Threat and Vulnerability Management Security Software Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe