Binary Revolution Forums: Paypal Pin system - Binary Revolution Forums

Jump to content

Welcome to Binary Revolution Forums

Welcome to the Binary Revolution Forums! You are a guest and are welcome to browse our 7 public forums at the top of the list without registering. All other forums are restricted to registered users only and will give you an "unauthorized" message if you try to browse them. However, if you Register or Sign In (ABSOLUTELY FREE and PRIVATE) you will be able to access many more sections of the site that are reserved for registered members and have lots of other benefits such as bypassing those annoying ads.

  • NO ADS! All of the ads are for GUESTS ONLY!
  • The annoying guest message (this very one) at the top of every page will go away.
  • Access our private messaging system to communicate with other users.
  • Start new topics and reply to others instead of just reading.
  • Subscribe to topics and forums to get automatic updates on watched threads.
  • Add/view events to our community calendar.
  • Customize your profile and see your statistics.
  • Change your preferences such as choosing layouts and tweaking your settings.
  • Contribute your site to our database of links.
  • Access our Gallery and all of its features (instead of just viewing thumbnails) including uploading images of your own.
  • Build up your reputation using our reputation controls.
  • Once again: NO ADS! All of the ads are for GUESTS ONLY! It is all free so Register Now!
Guest Message © 2010 DevFuse
*** SKIN BUG NOTICE *** The recent upgrade of the forums caused our custom skin to be fux0red. The forums work fine, but the gallery is pretty fugly right now. The blog is also funktified as well but it is still usable. We are working on getting the skin upgraded and fixed so bear with us.

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Paypal Pin system Rate Topic: -----

#1 User is offline   phyburn 

  • Gibson Hacker
  • Icon
  • View blog
  • Group: Members
  • Posts: 86
  • Joined: 27-May 05
Reputation: 0
Neutral

Posted 16 October 2007 - 03:38 AM

So ive been waiting for this for awhile now, paypal's new PIN system. You pretty much pay 5$ USD and they ship you a nice pretty number generator by verisign. So now instead of just typing in your user name and password you now also have to type in a 6 digit number that is generated by your little LCD screen you got for five dollars.

Now my question is, what are the attack vectors here? I can't see many since the number is changing every 30 seconds or so. The only thing I could see is somehow solve the algorithm that's producing the 6 "random" numbers. Any ideas?

btw, I purchased one today so ill prob have it by the end of the week, ill post pics when I get them!


Cheers.

LINKS:
https://www.paypal.c...rityKey-outside
https://www.paypalob...ritykey_us.html (demo)
0

#2 User is offline   McGrewSecurity 

  • SUPR3M3 31337 Mack Daddy P1MP
  • Icon
  • View blog
  • Group: Agents of the Revolution
  • Posts: 338
  • Joined: 09-May 07
  • Location:Starkville, MS
Reputation: 0
Neutral

Posted 16 October 2007 - 09:43 AM

View Postphyburn, on Oct 16 2007, 03:38 AM, said:

Now my question is, what are the attack vectors here? I can't see many since the number is changing every 30 seconds or so. The only thing I could see is somehow solve the algorithm that's producing the 6 "random" numbers. Any ideas?


I'm pretty sure these are rebranded SecureIDs: http://en.wikipedia.org/wiki/SecurID

You can check the links from there for technical information on how it works, and a few papers on cryptanalysis of them. I haven't read any of the papers, but I presume it'd be a matter of figuring out a unique "seed" number or password that is used to set off the number generator along its way. I guess the idea would be to find it based on a set of generated numbers and times. It must be pretty difficult to do so, or the attacks must be very impractical, though, as I haven't heard of anyone successfully breaking it, or any discussion of why they should not be used because of insecurities.
0

#3 User is offline   riscphree 

  • Dangerous free thinker
  • Icon
  • View blog
  • Group: Members
  • Posts: 1,936
  • Joined: 27-September 03
Reputation: -2
Neutral

Posted 16 October 2007 - 12:21 PM

I've got one for my paypal account.

Quote

So now instead of just typing in your user name and password you now also have to type in a 6 digit number that is generated by your little LCD screen you got for five dollars.


You need to provide your username AND password AND PIN number from the device. Not just the PIN number.

It is just a rebranded Verisign Secure ID thing. Verisign has EXCELLENT documentation on how this thing works. Even how the generation of the PIN number is done.
0

#4 User is offline   phyburn 

  • Gibson Hacker
  • Icon
  • View blog
  • Group: Members
  • Posts: 86
  • Joined: 27-May 05
Reputation: 0
Neutral

Posted 16 October 2007 - 05:11 PM

View Postriscphree, on Oct 16 2007, 10:21 AM, said:

I've got one for my paypal account.

Quote

So now instead of just typing in your user name and password you now also have to type in a 6 digit number that is generated by your little LCD screen you got for five dollars.


You need to provide your username AND password AND PIN number from the device. Not just the PIN number.

It is just a rebranded Verisign Secure ID thing. Verisign has EXCELLENT documentation on how this thing works. Even how the generation of the PIN number is done.


I said you ALSO have to type in the PIN =p

Do you have links to any of these documents?
0

#5 User is offline   thej3w 

  • T0tal n00b
  • Icon
  • View blog
  • Group: Members
  • Posts: 0
  • Joined: 24-February 04
  • Location:Chicago
Reputation: 0
Neutral

Posted 16 October 2007 - 08:32 PM

You can even set it up for use with your OpenID.

http://www.solo-tech...id-integration/
0

#6 User is offline   riscphree 

  • Dangerous free thinker
  • Icon
  • View blog
  • Group: Members
  • Posts: 1,936
  • Joined: 27-September 03
Reputation: -2
Neutral

Posted 16 October 2007 - 09:38 PM

You can find docs on the system here:

http://www.verisign....entication.html

Quote

I said you ALSO have to type in the PIN =p


Sorry, I read your post too fast.
0

#7 User is offline   trem 

  • The phorce is with me!
  • Icon
  • View blog
  • View gallery
  • Group: Members
  • Posts: 72
  • Joined: 13-June 05
  • Location:Awesome Bill From Dawsonville
Reputation: -1
Neutral

Posted 17 October 2007 - 06:49 AM

One of my instructors used to do security for a bank, I guess they use something similar to this.
0

#8 User is offline   djfred 

  • Will I break 10 posts?
  • Icon
  • View blog
  • Group: Members
  • Posts: 9
  • Joined: 29-August 06
  • Gender:Male
Reputation: 0
Neutral

Posted 25 October 2007 - 07:26 PM

I got one back when paypal started there Beta its a really nice feature.

Apple (MAC) has something similar for there REPS.
It generates an ID # with Letters if I'm not mistaking.
Same concept.

0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic


  • Time Now: Mar 13 2010 12:08 PM