Order your PayPal Security Key now!

Add an extra level of security when you log in with the PayPal Security Key. We protect your account with one of the highest levels of online security available. Now you can add even more protection with the PayPal Security Key.

Submitted:
10 days ago, made popular 10 days 7 hours 52 minutes ago
Submitter:
keiths keiths   (news: submissions, diggs, comments)
Topic:
News » Technology » Security
Source:
www.paypal.com
Bury It:
Turn Profanity Filter On
  1. mikev by mikev on 2/09/07
    + 76 diggs bury this digg this
    So I guess for an extra 5 bucks paypal can securely fuck you over?
    1. + 69 diggs bury this digg this
      So paypal protects you from criminals... who's going to protect you from paypal?
    2. + 9 diggs bury this digg this
      What is this? Corporate spam? PayPal taking over Digg? Are they the new sponsor of diggnation or simply trying to screw us over again?

      My advise - want to keep your money safe? Keep'em away from PayPal. No security keys required.
    3. + 127 diggs bury this digg this
      I continue to be appalled at the gross ignorance and prejudice of the digg readership. I don't know if "user-driven" news sites will ultimately end up succeeding or not, but if they don't, this will surely be one of the reasons.

      Anyhow, these security keys are RSA security tokens that PayPal agreed to buy from Verisign back when they purchased the Verisign Payments division. Part of the deal included an agreement to purchase a million of these. And, they are not being cheap by making you pay $5. These keys typically cost around $100 each. PayPal is basically massively subsidizing them to anyone who wants one because the number one reason a PayPal account gets compromised is because the user is stupid enough to either pick an insecure password, write their password down somewhere, click on a link to a phishing site, or otherwise allow someone else to find out what it is. With two-factor authentication, you have to steal the guy's "key" (in the physical manner of stealing car keys) as well as prove that you know the password. This is PayPal paying ~$95 per account (they probably got a volume discount but it's still in the mid-to-high double-digits) to make them much harder to compromise. Every account that is protected in this fashion is therefore able to be much more favorably treated by their real-time fraud models (because it's therefore much more likely that any "weird" activity on the account is just the user doing something wacky, rather than the account having been stolen), enabling them to be much more accurate in fraud detection, resulting in fewer false positives, and therefore decreasing the number of customers who accidentally get screwed over.

      In short, this is PayPal paying a lot of money to keep users safe and protect YOUR money.
    4. [below viewing threshold, show comment] - 16 diggs
    5. [below viewing threshold, show comment] - 14 diggs
    6. + 16 diggs bury this digg this
      @ywong137

      I don't think there's any dispute in the security of the RSA SecurID system. I work with these things daily, and they would be painful to hack. I think what everyone here is bitching about is the company providing the tokens. Paypal could easily take the (large) fortune they are making from their bloated fees and provide there for free to every user that isn't a free sign-up, rather than making you pay an additional $5 over and above the charges they already pay.
    7. + 14 diggs bury this digg this
      This is just a standard 2 factor authentication token, similar to RSA SecurID. Now here's one of the problems with it... if you get it, and your account gets hacked, Paypal is going to claim there is no way in hell that someone could hack it and you'd never see your money.

      The problem is, it's still not 100% secure. Phishers can still run their phishing site to collect credentials, they just have to monitor it while it's running and use those credentials that you provide within 30 seconds (actually an average of 15 seconds). Paypal could make it harder by requiring you to enter a new password every time you do something related to payments or account changes, but a crafty attacker could still get past it with a little bit of skill and probably a bit of luck.

      I actually have two sweet solutions for this little problem, but the whole startup thing just isn't something I can do financially right now. Someone wanna give me a few million to get going? :) It would actually probably be significantly less, but there are some equipment and coding costs involved.
    8. + 13 diggs bury this digg this
      "These keys typically cost around $100 each. PayPal is basically massively subsidizing them "

      Crap they do. Sure a single pre-production hand made demo costs $100 each... A million of them ought not cost more than thirty cents, a dollar each if you're a bad negotiator.

      I have one of these keys already, one of my banks, HSBC, just automagically mailed them out to all customers in Australia. No need to request, no charge, no fees, it just arrived in the mail one day.
    9. + 22 diggs bury this digg this
      A search on Froogle turns up the lowest price of $20 for one of these tokens from a volume retailer. So it's not a dollar or 30 cents. $20/each is a pretty good million dollar deal volume price, I'd say.

      Also, PayPal IS providing them for free - to users with a business account. You know, the people from whom PayPal actually makes any money. For Personal accounts, $5 doesn't sound like too much to ask from users of a free service, as PayPal is paying for the credit card processing fees on payments made by most Personal accounts.
    10. - 2 diggs bury this digg this
      "$20/each is a pretty good million dollar deal volume price, I'd say."

      You're kidding, right? Which negotiating school didn't you go to? $20 each for a million tokens is a GREAT price, for the seller, they'd be laughing their guts up and partying for a week once they got the signed order from you for that much!!!

      Like I said... thirty cents each, a dollar if you're a bad negotiatior. Take it or leave it.
    11. [below viewing threshold, show comment] - 5 diggs
    12. vorex by vorex on 2/10/07
      + 6 diggs bury this digg this
      @ WikiEasy

      A real bank makes a lot more volume of money from their fees then paypal, did paypal ever charge you $27 for being in the negative? did paypal spot you half a million to buy a house?

      No way, they will cost more to produce then your estimates. Even if your estimates were correct, theres a lot more costs for paypal:

      Freight to Warehouse
      Warehouse Storage
      Payroll for Warehouse workers and security
      The cost of integrating this system into their site (many hours of coding, R&D, and QA)
      Training all their help desk employees about these new keys
      Lastly the postage to you

      Thats all I can think of atm, but I'm sure there are more costs then that involved. Why whine over $5? It will make PayPal a hell of a whole lot more secure. I ordered one for my personal account and they sent me a free one for my business account.
    13. TomP by TomP on 2/10/07
      + 0 diggs bury this digg this
      The Security Key is currently not available. Please try again later.

      :(
    14. + 2 diggs bury this digg this
      To guys above, with all due respect, PayPal's overheads are minute compared to banks, so banks have to claw back money for their services some how.

      PayPal should be able to get a good deal on these security keys, but what the going rate is dependent on what is required and where they get them from. I personally dont know how much they go for, but from what I know, froogle isnt the best place to get an idea of real market prices. Firstly you goto the supplier(s) get a price and then knock them down, if you don't then this is definatley not good business practice. Also to secure future business you shouldnt charge your existing customers for a security key, these should be provided for free, especially if they use their account on regular basis.

      In addition and just out of curiosity, how do you go into minus(the red) on a PayPal account??
    15. + 11 diggs bury this digg this
      "PayPal sucks" comments are exactly what I want to read. NOT. Leave a thoughtful comment it you take the time to comment. Here's my 2 cents:
      -No one is forcing you to use PayPal, so don't use it if you don't want to.
      -I'd gladly pay the $5.00 for this added layer of protection. I pay $3.95 for a fucking latte.
      -Pfishing is a serious threat. It's easy to make a "mistake" just *once* and log in to a fake PayPal site (like I almost did). Thank god for Firefox's automatic password/username completion. When the boxes weren't completed automatically for me, I really had to work to see that it was a Pfishing site. (And Firefox and GMail didn't identify the site as suspicions)
      -As a business who has thousands of dollars in my PayPal account AND who has employees who aren't as tech savvy as me - this is a godsend.
      -Why don't I go somewhere else? Like google checkout? Google checkout uses my bank account, unlike PayPals Money Market. I get no interest in my business checking account and like 1.2% in my savings account. I average 4% in the PayPal MM.

    16. ajck by ajck on 2/10/07
      - 2 diggs bury this digg this
      @signal15:
      > I actually have two sweet solutions for this little problem

      Let's talk. (seriously). ajck-1234 at usa dot net
      (You have no contact details on your profile)
    17. sippi by sippi on 2/10/07
      + 0 diggs bury this digg this
      I normally wouldn't pay five bucks for this, but it is just another measure to help people from accessing my account. Yeah PAYPAL sucks, but there are not many other options, so I consider this insurance to keep shady people out. $5 is cheap compared to the cost of trying to get your identity or your money back.
  2. klawz by klawz on 2/09/07
    [below viewing threshold, show comment] - 16 diggs
    1. + 0 diggs bury this digg this
      Mine was free. Business accounts rock.
    2. + 6 diggs bury this digg this
      @klawz: You're complaining about spending $5 on an expensive device. Who exactly is the cheap one?
    3. - 3 diggs bury this digg this
      "Mine was free. Business accounts rock."

      Yeah, but braggers suck.
  3. [below viewing threshold, show comment] - 9 diggs
  4. + 13 diggs bury this digg this
    How much do you want to bet that getting this will add about fifty new reasons for PayPal to lock/close your account for no good reason? To hell with PayPal...
  5. + 18 diggs bury this digg this
    visa/mastercard should be doing this themselves. in todays world, why cant everyone accept credit cards?
    1. + 12 diggs bury this digg this
      Because the infrastructure sucks.

      Having my own merchant account (which does allow me to accept payments from anyone with a Visa, MasterCard, AMEX, etc), I can definately say that they live in the dark ages of fax, telephone calls, and "real" paper work. Something like emailing with a digital signature is well beyond the current infrastructure.

      While this is a great ideal, it simply is just hard to change a multi billion dollar industry while still supporting the millions of customers with credit card swipe machines that require a dedicated phone line.
  6. [below viewing threshold, show comment] - 8 diggs
    1. [below viewing threshold, show comment] - 10 diggs
    2. + 7 diggs bury this digg this
      And how do people pay you via your BoA card, moron?
    3. + 1 digg bury this digg this
      I was hoping that your comment would finish with "And this could be YOUR for the low low price of 3 installments of $19.99. Call Now!"
  7. - 3 diggs bury this digg this
    it is only a one time fee, overall I think it is a great addition it you are overly paranoid about hackers. It is probably going to appeal to only the people who know nothing about the internet and security. LOL, of course this little code will do nothing if some stupid employee loses a laptop with account information. Honestly that is your biggest security hole, the employees and the human factor! This will protect you from your human factor (at least to some degree, but not from their mistakes.
  8. + 17 diggs bury this digg this
    Why does everyone hate PayPal so much?

    I might get one of these things.
    1. + 30 diggs bury this digg this
      no joke, i've used paypal for years with nothing bad to report...
    2. + 11 diggs bury this digg this
    3. + 1 digg bury this digg this
      I've had bad experiences but the good still outweighs the bad for me.
    4. - 4 diggs bury this digg this
      http://www.paypalsucks.com/
      Read some of the stories.Don't just look at the link. Go there and read.
    5. + 6 diggs bury this digg this
      Because they are thieves, grossly (some would say intentionally) disorganized and torture to have to work with. Especially as a merchant. I know, we've been burned by them in the past. Unfortunately, we have no choice but to accept them as a method of payment. Perhaps one of the best examples, however, of how they work was seen when Something Awful raised over $27,000 in emergency donations, in 24 hours, for the Red Cross to aid in the Hurricane Katrina recovery effort. PayPal seized that money and then tried to get them to redirect the funds to another charity.

      PayPal's approach to handling a merchant problem is to freeze their account, often without warning. This has the resultant effect of preventing the merchant from accepting payment. In other words, PayPal puts them out of business. The net is rife with horror stories (http://www.paypalsucks.com) and the number of merchants who have had problems is unacceptably high.

      Links:

      http://www.somethingawful.com/d/news/paypal-fiasco-summary.php

      http://www.somethingawful.com/d/news/further-proof-paypal.php

    6. + 3 diggs bury this digg this
      I second that. Been using it for 4 years now without a problem.
    7. + 5 diggs bury this digg this
      This is what I've found: for a customer who uses them anywhere from 1-50 times a year for eBay purchases and other small payments of $500 or under, PayPal is just fine. They will charge your credit card or debit your bank account and pay the payee successfully. I have used them for years, paying for things and receiving a few bucks here and there. I have not had problems.

      For a merchant who wants to accept payments and may have thousands of dollars in their account at once, Using PayPal to accept payments may not be the best decision. Many people have no complaints about them, but they do have problems which have caused sites like www.paypalsucks.com to start operating.
    8. + 1 digg bury this digg this
      People have EXCELLENT reason to hate PayPal, they use bull tactics, its as simple as that. While they never have screwed with my small business, I know they could and being a small business without expensive legal resources, I can't do much as their contracts HEAVILY favor them.

      The answer for us who haven't been screwed though isn't to not use them, it's to no RELY on them entirely. Sure, I make more money accepting PayPal as a payment source, however having my own merchant account, I'd say 95%+ of my sales go through MY BANK, not PayPal's.

      If PayPal closed my account would I be pissed? Hell yeah. Would I be out of business? Far from it.
    9. - 3 diggs bury this digg this
      I get paypal fishing emails and I dont even use paypal
      I dont even have an account with ebay/paypal
      So spammers are stupid people
      Fishing emails are random since they just send till they find a paypal user
  9. gizim by gizim on 2/10/07
    [below viewing threshold, show comment] - 12 diggs
    1. [below viewing threshold, show comment] - 6 diggs
  10. fr0ng by fr0ng on 2/10/07
    [below viewing threshold, show comment] - 6 diggs
    1. + 2 diggs bury this digg this
      You're confusing monopoly with popularity.
  11. [below viewing threshold, show comment] - 6 diggs
  12. [below viewing threshold, show comment] - 9 diggs
    1. + 7 diggs bury this digg this
      Why would PayPal be taking over digg?
      Do sites have to be sponsors of diggnation to get a story on the front page?
  13. - 2 diggs bury this digg this
    where can i read up on how these things work?
    1. + 0 diggs bury this digg this
      these keys are used by many organisations for outside secure access. I don't see why people are thinking this is such a bad idea.
    2. + 7 diggs bury this digg this
      Whatever you do, DO NOT go to https://www.paypal.com and look there.
      That would be the last place that would have information about these.
      I would avoid Google at all costs, they're useless in cases like this too.
    3. + 2 diggs bury this digg this
      darmichar: Paypal doesn't really say much about how it works, other than from the most basic description.

      I'm more curious from a technical perspective. They generate a new key every 30 sec, but do you need to set them to the current date/time so the key they generate is valid, or would any key generated on the correct day/hour work (to compensate for clock drift).

      Anyone know?
    4. - 4 diggs bury this digg this
      I use two similar devices from http://www.securecomputing.com to access corporate VPNs for work, and one for my local bank's online banking site. I imagine this PayPal one works similarly, though I cannot claim to offer any insight as to how the damn things actually work.
    5. + 3 diggs bury this digg this
      Let me rephrase.. paypals site's faq provides only the following explanation of how they work:

      How does the Security Key work?
      The Security Key creates the account access code by using a complex algorithm that’s unique to your device. When you enter that code after you log in with your user ID and password, our secure servers can verify your identity. This helps prevent unauthorized users from logging in to your PayPal account.

      Oh, *NOW* i see. a "complex algorithm" is used, and once I type it in, (after also providing both my username and password) thier servers can tell it's me (which they could do before with just my username and password) *rolls eyes*

      Look, I think I asked a reasonable question here. What search term or terms can i used to read more about how these random number devices (or whever they are called - see I dont know, that's why im asking) work?

      In other words, How does the server know the numerical value i am typing in is the correct one?

      In other words, what is this type of encryption called?

      What happens when the battery dies?
    6. + 13 diggs bury this digg this
      OK, the quick explanation is that there is a clock inside of the fob that is hashed with the serial number for the fob, as well as some other numbers that are stored in the firmware of the fob. The resulting hash has 'mod 1000000 applied to it, and the resulting number is displayed as six digits.

      When you 'register' or 'activate' your fob, you will be asked to enter three different sets of 6 numbers that the fob generates. (more or less) This makes sure that the fob and the computer that is doing the authentication are working with the same time reference. As they drift later on the server will adjust an offset for your account to 'adjust' the time on the server when calculating the hash to compare against your fob's hash.

      You may also have to confirm the serial number for the fob. You will have to enter a password of some sort, which will probably be different from your existing paypal password (recommended) but which I don't know if it is compared.

      In all likelihood you will be asked to provide some information that they can use to confirm you are you in the unlikely event that you need to report that your fob is damaged, destroyed or has disappeared.

      When you go to a site that you need to authenticate to paypal at, you will either enter the password you created above, with the number from the fob as a prefix or suffix to your password, or possibly entered into a separate field of the authentication page. The contents are then sent off to paypal in some way, who compares the results of what it calculates, with what you entered (also comparing for 30 seconds forward and backwards of 'now') and either sends a yeah or a neigh to the system asking if you are 'you'.

      The primary 'down' side to this is that in many cases some number of failures to authenticate result in locking the account. There are others, including attacks to reverse calculate the information used by the fob to generate the string of numbers being displayed, etc.

      As Darmichar suggests, there are other resources available. But if you want to treat my discourse as authoritative, I've got no problem with that. Not sure that someone else won't have a problem, but then why would either of us be concerned about that?

      [edit] You don't get to 'set' anything on the fob. It has a clock that is set via contacts at the factory, and drift is handled within the server you authenticate to.
    7. - 4 diggs bury this digg this
      The paypal website says you have to activate the security key system by entering in two consecutive keys generated by the device ( you have to wait the 30secs for the 2nd key of course ). Then every time you log into the site you press a button to get the next key which paypal expects. I dont think that a new key is actually generated every 30secs, though it is possible if that is how often you log in. So it works by keeping in sync the number of times you log into the site, and the number of time you press the button on the security key. If it gets out of sync, then you may have to reactive the access key by entering in 2 consecutive numbers. Thats how i think it works, though i unfortunately had no hand in designing the system.
    8. + 6 diggs bury this digg this
      "Thats how i think it works"

      Nah, it's not. The end user can push the button like crazy all the time, and it won't stuff up the authentication. It's time based, with some compensation for drift... The auth system checks back and forth 30 seconds if the 'now' number isn't right, and makes a note of what it found. Over a bunch of subsequent authentications, a picture of how the clock in the token is drifting can be built up, and keep it working fine even if it is on the drift.

      "It has a clock that is set via contacts at the factory"

      You got me interested, so I peeled the serial number label off the back of my fob just now. There's six little holes - two rows of three - in the plastic body, and if you catch the right light you can see a matching six gold contacts on a board a few millimetres down the holes. That's the contacts alright :-)
    9. + 3 diggs bury this digg this
      Actually, this is not encryption at all. It is a form of a random number generator. Provide some seed information to a random number generator, specifically some number that changes (a timestamp for example) a number that is unique to the device (a serial number) possibly some other numbers to reduce the likelihood that you will give a phisher the serial number for your fob and they figure out what time your fob thinks it is from a few displayed numbers. Use that information as a seed on both the fob and the authentication server, and both should end up generating the same number.

      The algorithm may be as simple as multiply the timestamp date by the timestamp time, then take that number to the exponent of the serial number of the fob, divide the result by this number, and multiply it by another number, now display the least significant 6 digits. That sort of an algorithm may seem 'complex' to some people.

      When the battery dies the fob doesn't display any further numbers. You call up paypal, let them know the condition of the fob, and they ship you a new one. The battery in the constant display SecureID fobs has an average lifetime of about 3 years. Along with the serial number, the fob should be tagged with an expiration date which should arrive before the battery fails. Something like a credit card, the company handling the authentication for paypal should be shipping you a replacement fob on or before the date.

      The button you press on the fob to display the current number provides two things. First it increases the battery life by turning off the display when you don't need a number. It also prevents someone from seeing a long series of sequential results which could reduce the security of the random number generator being used.

      If I know your password and your account name, then if you are not using a fob for security, paypal will consider me to be you if I give them that information. If you are using a fob, and have no problem keeping track of it, then it is less likely that paypal will be willing to consider me to be you, if I can't give them the right 6 digit number. If I can give them the right number, and your account name, but not your password, then again they are unlikely to think I am you. However if I compromise your fob, and have your password and account information, I am back to being you as far as paypal is concerned.

      If you lose your fob, it's a good idea to report it missing right away. Just as it is a good idea to work with them if you suspect your account information has been compromised. If you have a history of loosing things, then this form of authentication may not be for you.
    10. + 3 diggs bury this digg this
      @rusty01010:

      >> Actually, this is not encryption at all. It is a form of a random number generator.

      I have to disagree with both of these characterizations. Random number generation is not what you are after, with a device like this. You want it to be very predictable (such that the results can be duplicated at the other end). The numbers are far from random.

      One goal is to have them be predictable (i.e. duplicatable by the server). The other is to make it *appear* random - unpredictable - (so that someone with the same information set (like "what time it is") cannot figure out the generation key, even though the RSA algorithm is well documented.

      By using encryption techniques, the device generates a 6-digit number which is predictable by someone else who has all the same information that you have (which is: current time, serial number of the device, encryption algorithm).

      You said >> The algorithm may be as simple as multiply the timestamp date by the timestamp time, then take that number to the exponent of the serial number of the fob, divide the result by this number, and multiply it by another number, now display the least significant 6 digits.

      Yes, encryption is just simple math.
    11. + 1 digg bury this digg this
      I think that is dependent upon your idea of encryption. I don't happen to consider a hash function to be encryption. It is related to encryption, but is a one way function to generate a non-unique number. With a million fobs out there, it's a given that at any given half minute, at least two of them will be displaying the same number. Presumably the next 30 second interval any two that had a matching number.

      A function like that can be used to authenticate who you are, or to generate a number that can be encrypted with your private key to providea signature for the information that you start with, but on it's own you can not generate the source material from the result. The timestamp in question may be 11 digits, or more. Though it may compress to a smaller number if you use a bitmapped data type to store the time. The serial number on the back of my SecureID fob is 8 digits. To the best of my knowledge there is no way to reverse the displayed 6 digits to the serial number. However given the serial number as part of the account, you can validate that the person providing some set of digits is likely to be the one who the account belongs to.

      Encryption, as I understnd the concept, is the alteration of the source material to hide it's content from potential observers as it is being transfered from one location to another. It may be accomplished via eiter encoding on encyphering, the difference being that encoding may be used to send a very long pre-aranged message between two entities with something as simple as a single bit being flipped in a file that seems otherwise inoctuous. Encyphering is applied to either each character, or blocks of bits directly from the source material. Morse Code is an example of a cypher. A page and word number for a book that maps to an instruction or pre-arranged message is an example of a code.

      making a 6 digit hash of the serial number of a fob and the current time, is not encryption as I understand it. If you understand it to be encryption, well OK, that's your understanding. I'll tend to disagree.
    12. + 1 digg bury this digg this
      @rusty0101:

      You make some good points. But, as you said, I understand this hash function to be encryption. Especially as invented by RSA - who made and patented the initial SecurIDs (http://en.wikipedia.org/wiki/Securid ) which this looks identical to in functionality. SecurID uses the RSA patented encryption algorithm to achieve its hash.

      Wikipedia's page on hash functions says: "Because of the variety of applications for hash functions (details below), they are often tailored to the application. For example, cryptographic hash functions assume the existence of an adversary who can deliberately try to find inputs with the same hash value. A well designed cryptographic hash function is a "one-way" operation: there is no practical way to calculate a particular data input that will result in a desired hash value, so it is also very difficult to forge. Functions intended for cryptographic hashing, such as MD5, are commonly used as stock hash functions." http://en.wikipedia.org/wiki/Hash_function

      Clearly this definition of a hash function eludes to encryption (referring to cryptographic hash). So at least I don't appear to be alone in thinking that hashes are a form of encryption.

      Hash functions may not yield results which are decryptable to the original "message", but they do take a message and manipulate it so as to conceal that message. And that, to me, sounds like a form of encryption. (Especially since they sometimes use encryption algorithms to do the hash, as SecurID does, as SHA-1 does, etc.)
  14. [below viewing threshold, show comment] - 8 diggs
    1. + 10 diggs bury this digg this
      Uh, video or it didn't happen. I know Paypal is *seriously* evil, but even for them this sounds too "conspiracy theory' for my liking
    2. + 2 diggs bury this digg this
      That was a joke, right? ....right?
  15. - 4 diggs bury this digg this
    I love it when spam hits the front page of digg. Wonder how much keiths gets paid.
  16. - 3 diggs bury this digg this
    Wow guys don't digg this stupid crap.
  17. + 0 diggs bury this digg this
    www.paypalsucks.com is just guerrilla marketing for a competing service. i wouldn't doubt that this post and all the comments are also a part of the ad.
  18. - 4 diggs bury this digg this
    YOUR paypal account gets compromised because YOU are stupid, dont make it easy.
  19. + 3 diggs bury this digg this
    keith makes big bucks from his blog

    http://www.problogger.net/archives/2007/02/08/how-i-make-money-from-blogs-my-top-earners/

    this is perhaps one way in which he makes a little more.
    1. + 1 digg bury this digg this
      What are you talking about. I even tried to avoid things like this by linking straight to PayPal's site. There were tons of blogs reporting this but I even cut out the middle man and apparently I'm spamming.

      Yea I'm sure PayPal is going to pay some one to advertise a service that is limited to a certain amount of people.

      I'm sorry but people on this website are retarded if they think this is spam. This is really good information for people with a PayPal account. I ordered one (for free) as soon as I saw the news.
    2. + 1 digg bury this digg this
      Oh yea, that's not even my blog. Not only that but I don't have a blog. I do have a website with news but it's a gaming website.
  20. + 4 diggs bury this digg this
    I am interested in getting one of these (i use Paypal and have an interest in security anyway) but couldn't get to the page to order one(it says "The Security Key is currently not available. Please try again later."). Is it only available in the US? (i am in England)
    1. + 3 diggs bury this digg this
      PayPal's UK and European operations are legally a seperate entity (due to the UK being part of all the EU bullshit - and having to pay large amount of taxes to the largely unelected corrupt Brussels tax pigs to syphon off to regenerate the EU's new eastern European members, after the fat cats, have gotten a little fatter).

      As I understand it, sometimes they might wish to try something out in the US before applying it in the UK or Europe, and sometimes legal issues get in the way.
    2. + 3 diggs bury this digg this
      Yeah same problem here with a Swedish account. Damnit.
  21. + 0 diggs bury this digg this
    Look here: http://www.aboutpaypal.org/ and here: http://www.paypalwarning.com/ and here: http://www.paypalsucks.com/

    These are totally bogus sites designed to bate people into using and equally crappy service. They all link to the same "alternative". transfer funds your bank account and daily or get a real merchant account like a big boy.
  22. + 3 diggs bury this digg this
    BTW, i don't agree with charging customers for "extra security" that's total BS. that's like if you went to bank of america and they asked you to pay extra to have your money in the vault instead of in their sock drawer like all the other peons.
    1. + 5 diggs bury this digg this
      Paypal charges the nominal fee to make sure that the folks who order them actually use them. This is a beta program and they want to get data. If you're willing to pay $5 for it, then you are more likely to use than someone who just got it for free.
    2. + 2 diggs bury this digg this
      right, diverting the cost of security onto the customer. do you need an RSA fob for your online banking?
  23. + 2 diggs bury this digg this
    I have done over 200 transactions on paypal with no problems. I think for the VAST majority of people who use them , they are great. Its a very vocal minority who have had problems. Also from a lot of these people who posts their "Stories" you never hear the WHOLE story. People just like to blindly believe because everyone wants to ban together to hate on a large corporate entity. Its in vogue. I'm not saying that people don't have their problems with PayPal, but all these haters who just hate for the hell of it without any PERSONAL experience ...i mean thats just stupid. This RSA key is a step in the right direction to make things truly secure. More companies need to do this.
    1. + 1 digg bury this digg this
      You're wrong. It is not a vocal minority and the number of cases that occur without being blogged about is very high. We had a bad experience with PayPal where they assessed a $2 fee against our account but never bothered to tell us about it. Since the account is used to receive payment and not to purchase items, we transfer the money out of the account as soon as it comes in. PayPal couldn't collect the fee (which was for a non-existant transaction) and froze the account.

      Turns out that the fee was billed in error - it was meant for a different merchant. Problem is, it took SIX months to get them to the point where they would admit it and unlock the account. During that time, we could not accept PayPal payments. Fortunately for us, our need for PayPal is few and far between. However, had this happen to a small retail store or EBay merchant, it would have put them out of business.

      The number of occurances for this type of problem is very high. I have spoken with a lot of merchants who have had problems. It's always encouraging to see someone like yourself that has had a good number of transactions without a problem but there are just too many other folks that can't make the same claim as you.
    2. + 3 diggs bury this digg this
      Ryosen: There's something missing here. Why was PayPal unable to take $2 out of your checking account?
    3. + 0 diggs bury this digg this
      Because they never tried. Their billing system created a fee against our account but never billed for it, never attempted to collect it. It merely created a line item, said it was overdue by three months, and froze the account. It then took six months to get the error corrected and the account unlocked. The bank account that the PayPal account was associated with had sufficient funds.
  24. + 0 diggs bury this digg this
    I really don't know too much about the "anti-PayPal" mentality. I'm sure there are reasons for it, but I've not done the research to have an opinion. Out of curiosity, what is considered the leading PayPal contender? Have there been any recent start-ups trying to "do it better" than PayPal?
    1. Remmy by Remmy on 2/10/07
      + 3 diggs bury this digg this
      Alternatives are out there, but support by merchants is very low. With Google stepping into the market however, it's likely that PayPal will have a reputable contender. And we all know that competition is good for the consumer.
    2. - 1 digg bury this digg this
      @ mindtattoo

      [sarcasm]
      Oh, gee...I didn't know I could use a credit card to *accept customer payments*
      For crying out loud...
      [/sarcasm]
  25. - 2 diggs bury this digg this
    US only by the looks, fucking typical.
    1. egze by egze on 2/10/07
      + 4 diggs bury this digg this
      No, I can also order it in Germany
    2. + 1 digg bury this digg this
      Well, I can't order it in Austria :(
  26. - 4 diggs bury this digg this
    Paypal. Meh. Just another wanna be trying to copy the Credit Card scam like business model online. Getting mighty sick of them spamming me despite multiple requests to 'cease and desist'. Just because I have an eBay account doesn't give them the right to harrass me! I'll admit to signing up to Paypal US about 7 years ago. Despite never using it they saw fit to give my private information to later formed Palpal AU without my authorisation. They can go to hell.
    As for $100 of value for $5. Bullshit. Processing time is as cheap as chips. If anything these companies should be paying us for everytime millions of people get their processing time used to decrypt things that only protect their interests. DRM especially.
    Security is a cost of business. Not a consumer extra. Despite the fact paypal is pathetic. They're also under servicing. Wish them every failure. They deserve it
  27. + 2 diggs bury this digg this
    Do any of you make any money?

    $5 is not a lot of money to keep your account more secure.

    Hell, I'd spend way more!
  28. + 1 digg bury this digg this
    Does this protect you from Paypal? No? I'll stick with Moneybookers then.

    Mr. P Brown never did call...
  29. + 4 diggs bury this digg this
    This sounds like a great deal. More online sites should be offering this type of service. I have several online financial accounts and only ETrade offers similiar keys and it's $25. For $5 to have extra security is a deal and I hope this catches on and -every- financial online account offers these at a cheap price.

    Thank you Paypal.
  30. + 1 digg bury this digg this
    heh, i remember when my dad had to use one of those to login to the Boing network from home
  31. - 1 digg bury this digg this
    The Security Key is currently not available. Please try again later.
  32. + 2 diggs bury this digg this
    anyone know if you can use one fob with multiple accounts from different vendors? I'd hate to have to keep track of 5 of these things in a few years.
    1. + 0 diggs bury this digg this
      > anyone know if you can use one fob with multiple accounts from different vendors?

      It doesn't sound like these fobs are doing public-key crypto, but I don't suppose there's any reason they couldn't. If they did, then you could hand out the public key to multiple sites and give them all the ability to verify the codes.
    2. + 1 digg bury this digg this
      I really don't think so. That would mean the algorithm is exactly the same.
  33. - 4 diggs bury this digg this
    pay pal sucks
  34. + 4 diggs bury this digg this
    Needless to say, you should NEVER enter your username and password after clicking on a link like this. A successful phishing attack only needs one small slip up. This link looks ok, but you never know.

    Just because you're paranoid, it doesn't mean nobody's after you.
  35. + 1 digg bury this digg this
    lame that it is free for business users but not premier.
  36. + 1 digg bury this digg this
    I've been using this sort of 'key' for awhile now... my bank issued them some years ago for all their internet banking customers (Lloyds T.S.B.). The only snag is trying to remember where i left the damn thing the next time I come to use it.
  37. - 2 diggs bury this digg this
    in for one..
  38. + 1 digg bury this digg this
    123456 - That is not a very secure security key :p
  39. + 6 diggs bury this digg this
    Beautiful. Paypal tries to help with phishing scams and what have you, and the large douchebag majority that is digg calls it a ripoff, scam, etc.

    People: get a fucking clue. A one-time $5.00 fee is insiginificant in the scheme of things. Sure, some banks give these things out for free, but Paypal isn't a bank and they do not rake in the fees that banks do.

    I've got a solution for all you whiners and know-nothings out here: you don't like Paypal, then don't do business with them. Don't weigh in with opinions on issues you know nothing about, either: it makes you look stupid, and annoys the rest of us.
    1. - 2 diggs bury this digg this
      Don't do business with pay pal. My exact sentiments. I'd much rather save using an truly open market and risk paying by direct deposit and risk a few loses. Much better than having every transaction hiked up by hidden merchant fees. It's my belief and it's how I act !
  40. - 1 digg bury this digg this
    Dear All Of You Holier Than Thou Jackasses Who Are Braying About "PayPal Doesn't Suck If You're Secure And Don't Compromise Yourself And The Vocal Minority Is Comprised Of Idiots Who Don't Understand Security Blah Blah",

    Fuck yourselves. Once you have to deal with the nightmare that is PayPal "security", you'll understand just how arbitrary their system is and why anything - ANYTHING - they implement can and will be used for evil.

    As a very simple example: Can you please account for all of the receipts for everything you've ever purchased? No? Then don't bother selling stuff on eBay! Because when PayPal decides to flag your account for "suspicious activity" you'd better have PROOF that that three year old drill press really is yours! Even if you DO ultimately find proof, you'll still have to wait 6 months to get your money back.

    Fuck PayPal.
    Fuck PayPal apologists.
    1. + 2 diggs bury this digg this
      Really? I bought a used snowboard on Ebay for $100. Two weeks pass - nothing. I email the guy - nothing. I finally filed with PayPal and had my money back in around a week I believe. There was never any response from the guy or any contact. I love their security.

      I've also dealt with Discover who has locked my card while I'm at the mall because apparently I made my purchases to quickly. -security that?

      Oh, and yes - I do have a receipt of everything I've bought online as a proof of purchase. Just as I save Credit Card receipts from BnM stores. It only takes 5 seconds to print the page out and throw in a nice filing folder that you can just keep in a closet or somewhere.
    2. + 1 digg bury this digg this
      I've used PayPal for 6 years, not one problem.
  41. - 2 diggs bury this digg this
    PayPal sucks. Ass.

    They don't give a rat's ass about security. If you guys knew how many dollars are just written off by these douchebags for tax purposes, you'd understand why they really could care less.

    PS this "security key" is nothing but RSA's widely deployed SecureID with a PayPal logo on it.
  42. + 4 diggs bury this digg this
    Blah blah blah STFU.

    PayPal isn't great but give them a break - $5?! What's the problem with that?!

    You cheap bastards.
  43. + 5 diggs bury this digg this
    This is not an RSA SecurID(tm) token, it's a VeriSign token.

    Disclosure: I work for RSA.
    1. DrMac by DrMac on 2/10/07
      + 2 diggs bury this digg this
  44. + 2 diggs bury this digg this
    I have used PayPal for years. I've got a PayPal debit card as well. I get 5% on money I keep in my PayPal account, AND they give me 1.5% cashback on everything I buy with the card as long as I put it through as a credit transaction. I have never had any issues with them, my account has always been accurate. Also, when sending funds overseas they are WAY less expensive than the likes of Western Union - and neither I, nor the recipient has to go find the nearest store to get their money. OK, western Union is perhaps the only way to go to transfer cash, but their rates are horrendous, particularly compared to PayPal.

    Also if you're starting out selling stuff online, PayPal is so easy to set up, none of that messing around with Merchant Account set ups, which can be really expensive for a small operation or start up, and take ages to pay you your funds too.

    As a web developer, I've set up both PayPal and regular Merchant accounts, and PayPal is way easier - not jsut coding wise, but the actual loops and hoops one has to jump through to get a Merchant account set up working at times.

    My kudos go to PayPal for making an inexpensive range of services securely available for the masses.

    Finally, no, I don't have any connection with PayPal, other than as a satisfied customer.
    1. + 0 diggs bury this digg this
      Amen, brother. I've been a customer for quite a few years now - and I couldn't be any happier with them. Managing my account is so easy and the conveniences of buying online and quickly running through Checkout can't be beat. I love PayPal
  45. [below viewing threshold, show comment] - 5 diggs
    1. + 2 diggs bury this digg this
      I don't think of it as spam because there is no other easy way to find out about this program. It's information.
    2. Remmy by Remmy on 2/10/07
      + 1 digg bury this digg this
      "This is SPAM, pure and simple."
      "- Keith; keithbarrett.com"

      Pot to Kettle: "What did you call me?"
    3. + 0 diggs bury this digg this
      hahah you bitch about this being spam, and then you spam your blog on the comment.
    4. + 2 diggs bury this digg this
      What exactly is spam about this? How is PayPal making money off this deal? I really doubt people are going to sign up for PayPal and start using it just because they have a new security key.

      Like I said before, this is good information for people to know who already have a PayPal account. All the security you can get to protect yourself is good.
  46. + 0 diggs bury this digg this
    You can go in the red with PayPal if you have a PayPal debit card. Go to a gas station. Swipe card at pump, check pay by credit option. Card will put a $1 hold on your PayPal account. Assuming there is no money in your PayPal account, you go into the red, simply by filling the gas tank. However, although PayPal won't charge you for the overdraft, I'm pretty sure they'll soon terminate your account if you don't pay it back fairly quickly (by re-funding from your bank account, or other credit card etc), or if you keep doing it on a regular basis.
    1. + 1 digg bury this digg this
      That's why you don't buy stuff on a debit card unless you have enough money. Dur?

      The point of a debit card is to take money THAT YOU HAVE.
  47. DeFex by DeFex on 2/10/07
    - 1 digg bury this digg this
    please note This is for USA only
    hint for other people in the world.
    don't use "password" as your password :)
  48. + 0 diggs bury this digg this
    That's cool, they are free for business accounts, I can never have too much security :)
  49. - 1 digg bury this digg this
    Not available in the UK. Losers.
  50. - 1 digg bury this digg this
    considering how much the paypal fees are, on top of eBay getting their cut, these should be free. I'm sure i have paid for them many times over by now.
  51. + 0 diggs bury this digg this
    Why has this story been dugg to the first page, I dugg this story a whole day before this one was posted??

    The submitter keiths basically stole my title too, I doubt digg did not tell him it was a duplicate story.

    http://digg.com/hardware/Order_Paypal_Security_Key_Now

    As of right now this duplicate story was posted 23h 12m ago while mine was posted 1 day and 23h ago.

    Burying this story since it is a duplicate.

    1. + 1 digg bury this digg this
      Yeah, it happens. Luckily, ranks don't exist anymore so the incentive to be a douche has been lowered.
    2. + 1 digg bury this digg this
      I thought this info was pretty good and needed to be on the front page. I probably saw your story and saw it didn't have many diggs and submitted it again. It's really not my fault, it's the way digg works, if you don't have a ton of friends it's very hard to get stories on the front page. And it's not really gaming. There's so many stories being submitted that most people don't even read stories with just a few diggs. Quite honestly digg needs to figure something out about this problem because it's way bigger then any other problems digg has.
    3. + 1 digg bury this digg this
      You could have dugg my story, then all of your friends would have seen what you dugg and dugg the story if the liked it. Your argument is flawed.

      Maybe you really are making comission like others state.
    4. + 1 digg bury this digg this
      It's not flawed. Friends don't normally digg their friends diggs, just what they submit. Again, tell me how I'm making commission of off something that PayPal is making no money on? Also you saying that I make commission makes no sense because you submitted the same story. So I guess I could say maybe you're making commission too? Who's the flawed one?
    5. + 1 digg bury this digg this
      I submitted the story, thus you could not get your commission unless you submitted it yourself.
      I submitted the regular link: http://www.paypal.com/securitykey
      You submitted this: http://www.paypal.com/cgi-bin/webscr?cmd=xpt/cps/securitycenter/general/PPSecurityKey-outside
      Why would you use that long link?
  52. + 2 diggs bury this digg this
    "The Security Key is currently not available. Please try again later.", but then again, I'm in Canada - sittin' in my igloo - pass the back bacon...
    1. + 1 digg bury this digg this
      It is a beta and it went live sometime Thursday morning, so I imagine it can end at anytime.
  53. - 1 digg bury this digg this
    Ok so, I just ordered mine for free...with my business account. Why do I have a business account? Well....one day I decided I'd just apply for one and make up some fake credentials, and that's how easily I got one. So for all those bitching about $5.....it's very simple to get one for free, stop complaining.
  54. + 0 diggs bury this digg this
    Tried to order one, but it seems it is not available to Norwegians yet
  55. + 0 diggs bury this digg this
    To everyone who says they keys are gone... I just got one a few seconds ago (with a non-business account). Maybe they're only giving them to select people? I have no idea why I'd be one of them.
  56. + 0 diggs bury this digg this
    So, according to the RSA cipher, prime numbers P and Q multiplied get N, which is your public key. But why can the private key only be six digits? that seems rather easy to hack if you ask me
    1. + 1 digg bury this digg this
      Read other comments. bcullman asked how it works, and he received plausible answers.
  57. + 1 digg bury this digg this
    According to PayPals flash movie i am 100% covered from fraudulent use of my account, so why would i pay 5 dollars? Just so i dont have to click the dispute console buttons?
  58. + 1 digg bury this digg this
    I ordered one, and didn't have a problem.

Add a Comment

Join digg for free to comment on this story. Have an account already? Login to comment.