Tuesday, September 23, 2008

Paypal Security Shilling and Scammers

PAYPAL Security Not as Secure


This week eBay Australia and Paypal have started to ship to all registered (or should that be ex power sellers) ebay users a hardware digital signature key, so that when you log onto ebay or paypal, ebay and paypal will know who you are and that in theory will minimise online fraud problems.

Shillers and Scammers


Presently the use of this online hardware security key is optional and as such the effectiveness of the security key is non existant as I feel most people are already annoyed at ebay australia for not stepping into EBS saga and then paypal renegging on the deals which they indicated would be honoured and paid out. The scammers and shillers are not going to register their hardware key as it is already a pain to ensure your proxy server is up and running in annomymous mode and / or finding a suitable annomymous proxy server to do your ebaying with. with a hardware key tied to your registered address then they will not be able to shill or scam people as the police will know which registered address the person is at.

No more fake ebay ids


Should ebay send out this hardware key (I believe they should) then all those security id's which are returned, then ebay can simply delete them (or NARU them) from their system, reducing the overall number of registered users. and hence reducing the incidence of shilling.

Imperfect Security


With every attempt to increase the security of a system then it does not take long before the system is cracked, however as each hardware key has a unique id on the back, then cracking it will prove to be somehat harder, however security cards have been cracked in the past so the ebay systems could be cracked with sufficient time.

However why waste time in trying to create your own security key, when all you need to do is to have a registered address at a vacant lot not far from where one is living, or even just using post office box, given that ebay do not require 100 points of id in australia.

Online Security


If ebay Australia really wanted to eliminate online fraud then they could simply send a snail mail letter to each and every registered id which then needed to taken to the post office for verification with 100 points of id. However this would
require employing someone to process the new online registrations and ebay does not want to do this as it is an overhead.


it will be interesting to see if/when ebay makes the use of this key compulsory


written by One on One Training

Learn to Blog

No comments: