[HN Gopher] PayPal data breach notification
___________________________________________________________________
PayPal data breach notification
Author : pmoriarty
Score : 187 points
Date : 2023-01-26 10:40 UTC (12 hours ago)
(HTM) web link (apps.web.maine.gov)
(TXT) w3m dump (apps.web.maine.gov)
| alpos wrote:
| "We have also secured the services of Equifax to provide identity
| monitoring services at no cost to you for two years. Below please
| find information on signing up for a complimentary membership to
| Equifax's identity monitoring services, including key product
| features"
|
| Really PayPal? You mean this Equifax?
|
| https://en.wikipedia.org/wiki/2017_Equifax_data_breach
|
| The security breach problem altogether has been turned in to a
| source of extra profit for the credit reporting companies whose
| faulty systems, lack of data verification, and resulting poor
| data quality are the root cause of these issues in the first
| place.
|
| The problem has never been "oh no someone stole your identity!".
| Identity can not be stolen, only temporarily misattributed in the
| eyes of one party or another.
|
| The actual problem is that companies like banks and credit card
| issuers don't actually know who they are dealing with and don't
| want to put any effort in to verifying that. Using just a few
| pieces of already available, static information about a customer
| was never enough to say you actually know who your company is
| signing a contract with.
|
| Calling it "identity theft" when someone feeds your faulty signup
| process incorrect information is merely a means of passing the
| problem with your systems off to the customer. Now we're going as
| far as pretending the root cause of this stupidity can also sell
| us the cure? Nonsense.
|
| If anyone ever "steals my identity", I'm going to sue the credit
| reporters for libel. They have admitted before that some 70% of
| their records contain inaccurate information and they know full
| well that a few bits of static information is not enough the
| identify an individual among hundreds of millions. They also know
| they don't do anything to establish that any new reports coming
| in from partner businesses are actually real and accurate. Yet
| they still peddle that inaccurate information to third parties.
| That is the same as if a journalist made up a story saying you
| did some shit you didn't do. They are knowingly giving out
| information about a person that is either provably false or which
| they have no good reason to believe is true in a way that can
| cause financial harm and loss of reputation. Classic libel.
|
| Further, if some business reported that I took a loan from them
| when I didn't, that isn't my problem, it's theirs. They failed to
| adequately verify who they were dealing with. Not my problem.
| Reporting that inaccuracy to a third party who then broadcasts
| that to a bunch of other companies, is also libel.
|
| They can make a case that they didn't know for sure that their
| claim that I owe them was false at the time, but they actually
| never had a good reason to believe it was true. Static
| information alone, especially that which we already know is in
| circulation among public entities, is not a valid way of
| identifying who you are dealing with. Pretending that it is
| anyway is just bad business.
|
| People need to hold these businesses accountable for the damage
| their faulty system designs are causing.
| scrps wrote:
| Wondering if this isn't related to the LastPass breach?
|
| Paypal's 2FA is a bit of a joke. IIRC (this was quite some time
| ago) when I went to initially setup 2FA SMS was the only option,
| eventually they added support for authenticators but you can just
| click get a text instead of the authenticator. Last time I
| checked there was no way to tell paypal to only accept OTPs from
| an authenticator.
| troymc wrote:
| Probably not. "Credential stuffing" means getting a big list of
| formerly-leaked usernames and passwords and trying them
| _everywhere_. It mainly targets people who use low-entropy
| passwords or who reuse the same password on multiple sites.
| looseyesterday wrote:
| What are the chances this is bigger than they claim?
| app4soft wrote:
| Meanwhile _Twitter_ hides my tweets about _PayPal.Me_ still
| working in Russia.[0]
|
| [0] https://news.ycombinator.com/item?id=34531489#34531574
| TrickardRixx wrote:
| PayPal previously refused to acknowledge a 2FA bypass
| vulnerability submitted to their HackerOne program.
|
| https://cybernews.com/security/we-found-6-critical-paypal-vu...
| seagull-action wrote:
| I personally wouldn't call it a data breach as such if it's just
| credential stuffing, but it's great that Paypal put out a notice
| on it so their customers are aware.
| dgudkov wrote:
| Tried to configure 2FA on PayPal. Adding only 1 authenticator app
| is allowed (why not more?). Failed to recognize Yubikey in
| Firefox.
|
| It's a leading payment processor. They have lots of money and
| developers. The state of things is pity.
| Terretta wrote:
| Who engineered this thing? It's not like it's rocket science.
|
| Oh wait...
| gggggg5 wrote:
| Requiring businesses to file breach notifications over credential
| stuffing attacks seems completely insane to me. What's next?
| Breach notifications over phishing campaigns?
|
| Perhaps the goal is to render breach notifications useless by
| flooding them with nonsense like this?
| RhodesianHunter wrote:
| What's insane is thinking that a bank that handles people's
| money shouldn't be required to report a coordinated successful
| attack, regardless of whether their technology is at fault.
| prophesi wrote:
| If all it takes is someone to download one of the countless
| publicly-available-on-github plaintext password compilations
| and automate login attempts to require a company to file a
| breach notification, I think all of the top services in the
| world would have to file one every hour.
| gggggg5 wrote:
| There are thousands of coordinated successful phishing
| campaigns going on against Paypal every day, what value would
| that reporting provide to anyone?
| Beestie wrote:
| Awesome. They are providing 24 mo identity theft protection by
| Equifax. So the day after the fox broke into the henhouse, they
| are going to secure the premises by adding a sign: "Please do not
| eat the chickens"
|
| Gotta hand it to Equifax, they know how to sell nothing for
| something.
| yalogin wrote:
| Why do companies offer only 2yrs of identity protection coverage
| for breaches? There are tons of these happening and so people can
| wait a couple of years to use them if it's going to be less of a
| hassle. Ofcourse, I don't trust that the identity protection
| coverage is of any use, but still trying to think about the
| effectiveness of the data after 2 years. Is there a reason to
| believe the information is not useful after 2 yrs? Why the 2yrs?
| It should be at least 10yrs if not more to be meaningful.
| autoexec wrote:
| > Why do companies offer only 2yrs of identity protection
| coverage for breaches?
|
| Two years seems like the minimum they feel they can get away
| with. They just need to make it seem like they've done
| "something" to compensate their victims out of fear that if
| they didn't some regulation will come along that requires that
| they actually make up for the harm their negligence has caused
| in an actually meaningful (and more costly) way.
| progbits wrote:
| Two weeks to detect (not great), another month to disclose
| (worse).
|
| "Only" 35k affected so must be some narrow scope. The linked page
| doesn't seem to provide more details.
| Zetobal wrote:
| There was nothing to detect and there was nothing to disclose
| it was a stuffing attack. The fallout of another company's
| breach, they took the proactive course of action to mitigate
| and inform their customers it should be applauded and not
| condemned.
| progbits wrote:
| Apparently I can't read today, sorry for the stupid comment.
| Can't edit it anymore.
| snorremd wrote:
| If I read this correctly this is a case of credential stuffing
| meaning the breach isn't really related to PayPal as much as
| people had credentials stolen other places and had used the same
| ones at PayPal. Maybe PayPal needs to enforce 2FA if they don't
| already do. 2FA SMS factor should be discontinued for any
| financial or otherwise important/sensitive service as SIM jacking
| is apparently quite easy.
|
| But anyone with properly secured accounts seems to not have been
| affected by this breach.
| latchkey wrote:
| https://www.paypal.com/us/cshelp/article/what-is-2-step-veri...
| brador wrote:
| I don't like the term credential stuffing. It is inaccurate by
| definition. Stuffing - "a material or substance used to stuff
| something".
|
| What alternative names could we use?
|
| Credential attack?
|
| Credential reuse attack?
|
| Secondary credential attack?
| doubled112 wrote:
| It's a verb.
|
| to stuff - to push something into a small space, often
| quickly or in a careless way
|
| https://dictionary.cambridge.org/dictionary/english/stuff
|
| As in "I am going to try these credentials quickly and
| carelessly and see if they get me in."
| abathur wrote:
| Credential spray-n-pray
| chatmasta wrote:
| Credential stuffing and password spraying are two distinct
| classes of attack. [0] Stuffing is when you try passwords
| for certain users (hoping they re-used a known password),
| and spraying is when you try common passwords for every
| username.
|
| [0]
| https://security.stackexchange.com/questions/209266/what-
| are...
| kennydude wrote:
| PayPal, at least for me, forces FaceID and an SMS 2FA to access
| it at all which is crazy. Probably would be great if they moved
| away from SMS though :(
| perch56 wrote:
| You can enable or disable FaceI ID from the settings. Just
| curious, why is using Face ID crazy?
| digitallyfree wrote:
| I don't use PayPal but was told by a user that their 2FA SMS
| system isn't really a second factor, but rather it replaces the
| password. Basically when you log in (with username only) it
| sends you an SMS code and you enter the code to log in with no
| password necessary. So basically this becomes a single factor.
|
| I hope they got rid of this feature now and went back to
| "traditional" 2FA requiring both a password and code.
| toastal wrote:
| I've had to ignore my account. I originally want TOTP 2FA, but
| it wasn't an option. I set up 2FA through Google Voice because
| my number changes frequently. A few years later I tried to log
| in and Google Voice has been blocked as a 2FA option for SMS. I
| go to seek support and you, circularly, need to be
| authenticated to get support for authentication, and asking
| support on Twitter got me banned from their account.
|
| The last 2 years directly emailed all independent sellers to
| set up alternative payment options to not go through such a
| careless operation.
| eloff wrote:
| Always have a backup payment processor. PayPal especially,
| but even Stripe will shut you down or freeze your balance
| with little recourse.
|
| Amazon killed my parents business by just sheer incompetence
| and support took a year to get partially back to operation,
| by which time it was over.
|
| Facebook incorrectly nuked my wife's Instagram account and
| hopes of becoming an influencer. No recourse.
|
| Google can ban your account with your email with no recourse.
| You lose your email history, contacts, documents, etc with no
| way to login to a myriad of online services.
|
| I'm really low on patience with the big tech companies. I
| hope the government reins them in.
| bipson wrote:
| As much as I have sympathy for the pain (besides the
| influencer thing) - what exactly do you expect from the
| government here?
|
| And I say this as European, I mean, we at least have _some_
| regulations...
| f-securus wrote:
| I think support shouldn't be 100% automated. The big tech
| companies are automating everything and sometimes those
| false positives need to be corrected and there isn't a
| way to actually do so. I don't know how the government
| could enforce proper support but I believe something as
| simple as requiring the ability to discuss your critical
| issue with a human being as a start.
|
| Then you get into what is a 'critical' issue but I think
| being locked out of your account that is used as a
| gateway to multiple other accounts qualifies.
| ensignavenger wrote:
| At the very least the right to get a dump of your data
| after they close your account.
|
| Also, for money things like PayPal, they should only be
| able to hold your funds for a reasonable amount of time,
| then they have to transfer them to your bank account.
| They should not be allowed to just keep your money.
|
| For sales of digital items, they should not be allowed to
| revoke your access to the items you have bought. Maybe
| they should just have to provide a basic file download
| for a certain amount of time.
| RhodesianHunter wrote:
| Believe it or not here in the US we have a lot of
| regulations as well. They're just designed to favor the
| big guy.
| bipson wrote:
| That's not what the rest of the world considers a
| "regulation"
| eloff wrote:
| I believe those are called barriers to entry to protect
| vested interests. Also known as pulling the ladder up
| behind you. Why that works in the US is beyond me. I
| recall a recent study from one of the Ivy leagues that
| shows that historically the elected representatives favor
| the elite over the people in the US.
|
| I think the elected representatives have to represent the
| people, otherwise you don't really have a democracy,
| right?
| michaelteter wrote:
| Regulations that could be imposed:
|
| 1. When a service is blocked or terminated, the
| terminating company must provide clear and specific
| reasons for the termination (they almost never do this
| now)
|
| 2. Additionally, there must be a human support channel to
| discuss the matter - even if it requires payment for the
| privilege of gaining support help (think 900 numbers of
| the past)
|
| 3. Human support and decision paths must be documented
| and followed such that a final decision can be understood
| within the context of the rules of the organization
| (thereby enabling possible efficient legal options for
| the consumer to further dispute the ruling)
|
| 4. As other people have noted, having access to export
| your data if you are being permanently blocked from the
| service
|
| 5. Having financial compensation (refunds) or post-
| service DRM access to content you have paid for
| Brian_K_White wrote:
| There's lot's of things government could do. Start with
| codifying some concepts that define when a service is
| responsible for having too much impact on a user's life,
| and attach responsibility to that, instead of just
| 'private company, do anything you want'
|
| It's not an accurate or sufficient or desirable
| representation of reality to allow these various big
| companies to actively seek out having you entrust them
| with parts of various critical paths in your life, and
| then be able to nuke those with no protection or recourse
| on your part.
|
| In 1975 when no one had an email address or a cell phone,
| and neither were required to do anything in life, it was
| fine to treat them like luxiries that if you lose them,
| so what?
|
| That was still true but just a bit less so a few years
| later, and it's just been gradually becoming less so
| every year, and by now, it is simply not true at all.
|
| It should essentially be illegal for a service provider
| to completely break some of these services without some
| sort of graceful shutdown or hand-off process, in the
| same way and for the same reasons it's illegal to shut
| off electricity and gas and phone in a lot of cases even
| after the subscriber has failed to pay. They get shut off
| eventually of course, but there are exceptions and ways
| for the subscriber to fight, and they are mandated by the
| government, not out of the goodness of the power
| companies hearts. Basically the power company isn't
| allowed to just let grandma freeze in the winter even if
| she fails to pay. It's not unfair to the power company.
| The investors in the power company are free to be in some
| other business if they don't like those terms.
|
| Today, an email account should not be treated the same
| way as a spotify account, even if you're not even
| charging money for the service. If you don't like that,
| you don't have to offer an email service at all.
|
| The requirement I imagine is some minimal level of
| continued function enough to complete other account
| management procedures, which means being able to both
| receive and send at least some emails. Maybe a limited
| amount, maybe limited attachment size etc, but enough to
| at least send the one or few emails from the previously
| recognized address to other parties as part of the proof
| of identity to direct them to a new address.
|
| This even in cases where the account was terminated for
| supposed cause like illegal activity.
|
| This means that one of the other things government can do
| is recognize that exception for liability. The government
| can determine not to penalize a service provider or allow
| others to sue them for having one of these accounts
| active at that limited level of functionality if the
| account sends someone a phising email or something.
|
| Or maybe the procedure is the accounts do stop
| functioning so no email is passed, but, it can still be
| used by the owner to contact the service provider to
| invoke some kind of recourse procedure 9f they need it.
| So the spammer is blocked but mom can still jump through
| hoops and eventually regain access, including old mails
| and maybe even including unread received mails while it
| was down.
|
| There are all kinds of things a government can do, and
| fully fairly and defensibly and officially, just by
| codifying some principles.
|
| What do I expect from the government? Something. They can
| absolutely do something. It's work to work out exactly
| what and how and develop some consistent rational legal
| theory to base it on, but that it literally their job is
| to to exactly that.
| BolexNOLA wrote:
| >As much as I have sympathy for the pain (besides the
| influencer thing)
|
| Why not? You have no clue what she was doing and it's a
| totally viable source of income for plenty of people.
| f-securus wrote:
| Because influencer is another way to say individual
| advertiser. Nobody wants more advertising.
| eloff wrote:
| If that were true, influences wouldn't exist. Clearly
| they can make money because they add value for people.
|
| If that value is actually improving people's lives it's
| another matter, but from an economics standpoint it seems
| to exist.
| f-securus wrote:
| Advertising works because it is a psychological hack.
| Influencers are using the same hack and once it becomes
| more than a passion or hobby project then the monetary
| incentive perverts their judgement.
|
| I'm all for people sharing their knowledge and hobbies to
| inform others but the term 'influencer' has a connotation
| in which they are earning money from 'influencing' others
| and that seems an awful lot like basic advertising to me.
| BolexNOLA wrote:
| >I'm all for people sharing their knowledge and hobbies
| to inform others
|
| And I'm all for them getting paid to do so. I'm not sure
| where you draw the line. Is a cocktail influencer sharing
| a cool hobby or pushing a product? The answer is usually
| "both." So where do they fit in for you?
| f-securus wrote:
| If the cocktail influencer started making videos with the
| intent of getting paid then their judgement is already
| clouded. Even if they decided they wanted to do the
| morally correct thing and give honest reviews, their
| livelihood now depends on this income and as such they
| are biased subconsciously. Ultimately they are self-
| employed advertisers. We need less advertising in this
| world, IMO.
| BolexNOLA wrote:
| So making movies with the intention of getting paid means
| my judgment is clouded? Can't a job be a job? Does it
| have to always be in the service of some grander or more
| artistic purpose?
| autoexec wrote:
| You aren't wrong. "Influencer" is another word for
| "manipulator" and the world sure doesn't need more ads,
| but companies wanting to take from us love influencers
| because a lot of people, children especially, consume
| that "content" without even recognizing that they're
| watching an ad.
| eloff wrote:
| I think you missed my point. The fact that these people
| have the audience that they have is because people want
| to see their content.
|
| Whether or not they monetize that via advertising or not
| it's largely irrelevant to that value proposition.
| BolexNOLA wrote:
| > Nobody wants more advertising.
|
| Seems plenty do given the number of influencers who have
| made it into basically a career. I in some way share your
| cynicism towards it, but there are plenty of jobs we
| don't "need" yet don't look down on in the same way. For
| all you know this guy's wife is spreading valuable
| information and genuinely helping people. Not all
| influencers are Andrew Tate and such. Hell my wife's
| cousin is big into legos and has a thriving instagram
| showing off their builds and talking about what goes in
| to them. Tons of hobbyists genuinely enjoy their insight.
| I don't see the harm.
| wasmitnetzen wrote:
| In Germany, there has been a high-level court decision
| last year about requiring a "proper" recourse process[1].
|
| [1]: https://www.sueddeutsche.de/politik/facebook-bgh-
| urteil-1.53... (German)
| [deleted]
| eloff wrote:
| If a company has your livelihood, bank balance, etc by
| the balls - they should at least be required to offer a
| minimum level of human support with a path for escalating
| things or a way to reasonably handle disputes with a
| neutral adjudicator. The stakes are too high to simply
| leave decisions up to algorithms.
| eminent101 wrote:
| > If a company has your livelihood, bank balance, etc by
| the balls
|
| Whose fault is it that people are relying on free email
| service (with no human support) for critical things like
| livelihood, bank balance, etc.? Is the provider of a free
| email service liable for the damages they can cause? What
| do their terms and conditions say about it? Do they have
| a disclaimer in there for this kind of things?
| Retric wrote:
| At a minimum long term freezing an account with a
| positive balance should be treated as simple theft.
|
| It's fine if they want to arbitrarily flag something as
| fraud and refund money, but saying something is
| suspicious therefore we keep your money isn't.
| eloff wrote:
| They should have to pay interest on seized funds. Like
| fed rate +5%. Then it will only happen in serious cases
| and they will resolve it quickly.
| judge2020 wrote:
| The problem is that few card processors will underwrite you
| for your small transaction volume at the start, so
| PayPal/Braintree and Stripe are go-to solutions with the
| promise to scale up without ever needing to rewrite your
| payment processing code. Once you get big, you can either
| seek out a real contract with the services (but this
| requires a lot of scale) or go for something like Adyen or
| Chase which seem to still require some level of scale but
| not a million dollars a day or anything.
| vorpalhex wrote:
| You should be able to have them close your account by sending
| them a formal letter.
| compsciphd wrote:
| paypal works fine with my google voice account. get sms's and
| copy/paste them into the field.
| gorbachev wrote:
| Same. Can not log into my Paypal account any more, because
| they don't accept Google Voice numbers as valid phone numbers
| any longer.
| latchkey wrote:
| I use TOTP on my Paypal account.
|
| https://www.paypal.com/us/cshelp/article/what-is-2-step-
| veri...
| londons_explore wrote:
| Most companies wouldn't even act on a credential stuffing attack
| against their users. They'd shrug and say 'not our problem if our
| users don't secure their passwords properly'.
|
| Kudos to Paypal here for considering it a breach, and reporting
| it as such.
| insanitybit wrote:
| Lots of companies deal with credential stuffing, especially a
| large targeted attack.
| [deleted]
| fmajid wrote:
| And I'd agree. Their lawyers probably made them do it.
| londons_explore wrote:
| As a bank, your agreements are with the actual humans, and
| your duty is to protect their money.
|
| The fact that you choose to use usernames and passwords to
| authenticate humans is your choice. It is well known that
| humans don't secure passwords well (reuse, writing on postit
| notes, etc). As a bank, any losses attributable to someone
| evil finding/guessing a password are your own.
|
| That's why credential stuffing counts as a breach. Even
| though most banks will try to tell you that it's your
| responsibility to protect your passwords, the law doesn't see
| it that way.
| bob1029 wrote:
| > As a bank
|
| Technically, Paypal is not regulated as a bank (per FDIC).
| That said, they certainly have immense fiduciary & privacy
| duty to their customers considering the format of their
| business.
| moxli wrote:
| > Technically, Paypal is not regulated as a bank
|
| PayPal has a banking license in Luxembourg which allows
| them to operate in Europe.
|
| I guess it depends on the region/country.
| boring_twenties wrote:
| Well that sucks for those of us who can use passwords
| effectively, instead we all get this SMS 2FA crap which is
| both more annoying and less secure.
| survirtual wrote:
| [flagged]
| phoe-krk wrote:
| And people (especially here on HN) really can't see why so many
| are invested in and believe in actual money?
|
| Your shitcoins are being hoarded by incompetent people in
| giant, minimally secured exchanges not to provide you with a
| better service, but to make a very small number of people
| bucket loads of money.
|
| They put in minimal viable effort to provide a minimal viable
| service and make money hand over fist without consequence when
| their incompetence result in your cryptocurrencies that you
| entrusted them with being rug-pulled.
|
| Once that crypto is "compromised" it is free for the attacker
| to use for any reason, outside the ToS defined by the
| exchanges. They are not held accountable, there is a proven
| record of no oversight nor any accountability.
|
| Do you really wonder why people are putting their faith and
| confidence in actually regulated currencies as opposed to these
| joke shitcoins?
|
| Look around you. The Web3 is going great[0]. Get out while you
| still can.
|
| [0] https://web3isgoinggreat.com/
| rajamaka wrote:
| The common retort to this is, "well you should be holding
| your coins in your own physical wallet".
|
| Usually from a person who stores their life saving of
| dogecoin in some weird 25% APR Ponzi.
| danuker wrote:
| Ah, I remember the Ledger customer data leak. Just as
| incompetent, even for a hardware wallet.
| mypastself wrote:
| Your argument entirely relies on the assumption that the OP
| stores significant amounts of funds on an exchange.
| lm28469 wrote:
| The extreme vast majority of crypto owners are on exchanges
| mypastself wrote:
| It's a fair assumption the OP is not one of them given
| the website we're on, and their stated opposition to
| handing custody of their funds to others.
|
| Also, plenty of retail "investors" seem to be moving away
| from the exchanges:
|
| https://www.reuters.com/technology/cryptoverse-bitcoin-
| inves...
| frankenst1 wrote:
| Don't know about crypto, but for Bitcoin:
|
| ~11% of the Bitcoin supply is held by exchanges, and it
| decreases on average by 2,500 BTC per day or ~5% per year
| (over the last 3 years).
| ilyt wrote:
| That just means they are not stored there as often, not
| that the exchanges are where most bitcoin related
| transactions happen
| survirtual wrote:
| Don't use an exchange?
|
| This isn't as clever as you think it is, and it will not age
| well. Fiat does not have a future within a spacefaring
| civilization.
|
| Cryptocurrency is not an exchange. Bitcoin is not an
| exchange. The technology is unprecedented and revolutionary.
| It removes parasitic intermediaries and allows the common man
| to transact at light speed directly with each other.
|
| The same old parasites are hard at work to inject themselves
| in the process. How anyone could conflate centralized
| exchanges with decentralized protocols is beyond me. May as
| well complain at the sun for being hot or complain at water
| for being wet.
|
| Water is a good example actually. You know, it is possible to
| drown with water, should we all stop drinking it? Some people
| even take the water, bottle it up, then sell it back to us.
| Those companies must be water, I don't like them. We should
| stop using water because it's centralized with Nestle.
| frankenst1 wrote:
| Just use Bitcoin. Don't trust anyone except yourself. You can
| store your coins in your phone, hardware wallet, paper
| wallet. You can encode it in steel and bury it in your
| backyard. You can "horcrux" them (e.g. via MultiSig or SSS)
| and store the parts (and copies of them) at different
| locations (friends, family, attorney, ...). Or put them in a
| safe deposit box if you like. Put a small amount on your
| phone and you can send them in seconds via the Lightning
| Network to anyone in the world at minimal fees, without
| relying on or needing permission from anybody else.
|
| Few actual need custodial services and nobody needs the
| greedy shitcoin casino. Decentralize. Be your own bank.
| dmitriid wrote:
| Wow. Haven't seen one of you in a wild for while now.
| survirtual wrote:
| Trust me, you've never seen one of me before.
| wil421 wrote:
| I've had a couple instances of fraud on my Bank account. Every
| time it was refunded in full within 2-3 business days.
|
| Beyond that all of my cash is insured by FDIC. If Bank of
| America decided to pull an FTX and scam away my money I'm
| getting it back.
| rationalist wrote:
| Bank of America's deposits were 1.4 trillion in Feb 2021.
| FDIC's Deposit Insurance Fund was 125 billion in Dec 2022.
|
| You aren't getting your money back if BoA loses it all.
|
| https://newsroom.bankofamerica.com/content/newsroom/press-
| re...
|
| https://www.fdic.gov/analysis/quarterly-banking-
| profile/fdic...
| loloquwowndueo wrote:
| Just remember FDIC insurance has limits; I know you know how
| much you have and it might not be over the limit but folks
| should know "all of my cash is insured" may not be entirely
| accurate.
| wil421 wrote:
| Correct, the limit is $250k for anyone curious. It's $250k
| per co-owner for joint accounts.[1]
|
| [1]https://www.fdic.gov/deposit/diguidebankers/documents/jo
| int-...
| hnlmorg wrote:
| Bitcoin ledgers are public so your data is still out there.
|
| Plus crypto currencies are subject practically zero oversight
| and accountability so the situation is even worse there. Hence
| why you hear about so many exchanges going bang.
|
| The problems cryptocurrencies attempt to solve are different
| from the arguments you're favouring them for.
| deweller wrote:
| Cryptocurrency exchanges are not the same thing as
| cryptocurrencies. And not all exchanges are created equal.
|
| Yes it is the wild west out there and consumers have gotten
| hurt. It is unfortunate. But crypto does serve a real and
| needed function of decentralized digital cash. I'm optimistic
| we'll have good regulated exchanges someday.
| mrguyorama wrote:
| As a resident of the state in question, I'm curious as to why
| this comes from our state. Did paypal not have to report this
| anywhere else?
___________________________________________________________________
(page generated 2023-01-26 23:02 UTC)