[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Apple 2 ebay 3rd party checkout, security risk?
"John" <zzzjoki@yahoo.com> wrote in message 1179181871.066246.285580@q75g2000hsh.googlegroups.com">news:1179181871.066246.285580@q75g2000hsh.googlegroups.com...
> On May 14, 2:41 pm, "Michael J. Mahon" <mjma...@aol.com> wrote:
>> John wrote:
>> > OK, this is a stretch to relate to Apple 2, but many foks here use
>> > ebay to make Apple 2 purchases.
>>
>> > Some ebay vendors direct Apple 2 users only to Paypal through 3rd
>> > party checkouts pages (you go to their sites, fill out a bunch of
>> > market_junk, and eventually they direct you back to Paypal).
>>
>> > Is this a security risk? Why? A vendor could send you to a phising
>> > site. I think this is possible, and some vendors come from places
>> > which are not so friendly.
>>
>> > One of the main reasons I liked Paypal, from a user perspective, is
>> > that they insulate you from the vendor. 3rd parth checkout *seems* to
>> > defeat that insulation, deliberately, in a way which benefits vendors
>> > only.
>>
>> > Thoughts?
>>
>> > Who would be good to talk to about this? I was thinking of magazines
>> > or papers or something. I called CERT hoping they could direct me.
>>
>> > (I have talked to Paypal about this twice, at least.)
>>
>> I haven't encountered this behavior, nor have I encountered a seller
>> who took PayPal who was not happy with getting paid by going straight
>> to PayPal.
>>
>> If there are such sellers, then don't patronize them.
>>
>> -michael
>
> Here's another small twist ... this last vendor advertised Paypal no
> differently than any other seller (on their ebay posting). When I
> proceeded to checkout there was no clear alternative. The ONLY
> (almost ..) way was through their page. Even when they gave me an
> email address Paypal would not let that transaction proceed. It said
> something like "this vendor only allows checkout through their web
> site ....(paraphrased)"
There are third-party seller management sites that are tightly (and I do mean tightly) integrated into both eBay and PayPal and are very much technically intertwined in the eBay server system.
>
> A Paypal agent said to ask the vendor to make a "Money Request" for
> the auction amount. That did work, or at least I didn't have to go
> through their marketing web site.
>
> Do you think this is excessive paranoia? I've heard of malicious Java
> scripts messing up IE without recent patches. I think it could change
> the DNS settings even.
And you're using unpatched IE because????
>
> It seems hypocritical for Paypal to emphasize security and then turn
> around and encourage risky behavior when it makes them a little more
> coin.
>
The seller is actually being very responsible by using these services which are vetted through eBay. You have to pass a lot of stringent requirements to make a public site using the APIs in question and all of your buyer protection features of PayPal are preserved whenever you use any kind of enabled site. The site shouldn't be asking for ANY kind of financial information and the checkout process requires that you redirect to PayPal and log in there to authorize the payment.
If you are truly paranoid about your DNS setting getting hacked then you should get off the internet NOW because you are at a much higher risk of picking up a virus that targets eBay users by simply browsing a listing than you are by going through a licensed eBay partner's checkout site.