[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Apple 2 ebay 3rd party checkout, security risk?



On May 14, 7:43 pm, "Payton Byrd" <plb...@bellsouth.no.spam.net>
wrote:
> "John" <zzzj...@yahoo.com> wrote in message1179181871.066246.285580@q75g2000hsh.googlegroups.com">news:1179181871.066246.285580@q75g2000hsh.googlegroups.com...
> > On May 14, 2:41 pm, "Michael J. Mahon" <mjma...@aol.com> wrote:
> >> John wrote:
> >> > OK, this is a stretch to relate to Apple 2, but many foks here use
> >> > ebay to make Apple 2 purchases.
>
> >> > Some ebay vendors direct Apple 2 users only to Paypal through 3rd
> >> > party checkouts pages (you go to their sites, fill out a bunch of
> >> > market_junk, and eventually they direct you back to Paypal).
>
> >> > Is this a security risk? Why? A vendor could send you to a phising
> >> > site. I think this is possible, and some vendors come from places
> >> > which are not so friendly.
>
> >> > One of the main reasons I liked Paypal, from a user perspective, is
> >> > that they insulate you from the vendor. 3rd parth checkout *seems* to
> >> > defeat that insulation, deliberately, in a way which benefits vendors
> >> > only.
>
> >> > Thoughts?
>
> >> > Who would be good to talk to about this? I was thinking of magazines
> >> > or papers or something. I called CERT hoping they could direct me.
>
> >> > (I have talked to Paypal about this twice, at least.)
>
> >> I haven't encountered this behavior, nor have I encountered a seller
> >> who took PayPal who was not happy with getting paid by going straight
> >> to PayPal.
>
> >> If there are such sellers, then don't patronize them.
>
> >> -michael
>
> > Here's another small twist ... this last vendor advertised Paypal no
> > differently than any other seller (on their ebay posting). When I
> > proceeded to checkout there was no clear alternative. The ONLY
> > (almost ..) way was through their page. Even when they gave me an
> > email address Paypal would not let that transaction proceed. It said
> > something like "this vendor only allows checkout through their web
> > site ....(paraphrased)"
>
> There are third-party seller management sites that are tightly (and I do mean tightly) integrated into both eBay and PayPal and are very much technically intertwined in the eBay server system.
>
>
>
> > A Paypal agent said to ask the  vendor to make a "Money Request" for
> > the auction amount. That did work, or at least I didn't have to go
> > through their marketing web site.
>
> > Do you think this is excessive paranoia? I've heard of malicious Java
> > scripts messing up IE without recent patches. I think it could change
> > the DNS settings even.
>
> And you're using unpatched IE because????

No I don't use IE. I read about the DNS hack that affected IE without
a certain patch.

> > It seems hypocritical for Paypal to emphasize security and then turn
> > around and encourage risky behavior when it makes them a little more
> > coin.
>
> The seller is actually being very responsible by using these services which are vetted through eBay.  You have to pass a >lot of stringent requirements to make a public site using the APIs in question and all of your buyer protection features of >PayPal are preserved whenever you use any kind of enabled site.  The site shouldn't be asking for ANY kind of financial >information and the checkout process requires that you redirect to PayPal and log in there to authorize the payment.

That's good to know. I hope they have stringent requirements, but
again, I rather have to trust *just* Paypal. That's one of the main
reasons I like to use Paypal.

>
> If you are truly paranoid about your DNS setting getting hacked then you should get off the internet NOW because you >are at a much higher risk of picking up a virus that targets eBay users by simply browsing a listing than you are by going >through a licensed eBay partner's checkout site.

How could that be done? Could they embed malicious Javascript code, or
something, into an ebay listing page?