Free iPhone App Improves Paypal And EBay Security
We've posted before about security keys—those little digital keyfobs that generate expiring security codes over and over and make it incredibly hard for someone to gain unauthorized access to your account. They're a great idea, and now if you own an iPhone you can install a Verisign app that will work with Paypal and eBay, as well as about two dozen lesser known sites. It's probably the easiest step you can take to vastly improve security on those accounts.
It can be a little confusing to connect the Verisign app on your iPhone to your Paypal account, so we've taken screen shots of the process. Here's what you have to do.





To launch the app info page in iTunes, click here. Sorry, it won't work on iPod Touch devices yet.
Update: To address reader questions below, what this does is add a second password to your account. Unlike your real password, however, this one is automatically generated every 30 seconds. Because you register the serial number of the keyfob with the site (e.g. Paypal), it also generates the same password every 30 seconds. Now when you log in with your normal password, you'll be taken to a second screen where you have to enter the valid temporary password to finish logging in.
Because it's changing every 30 seconds, it's virtually useless to steal the password—you'd have to steal the keyfob or the iPhone. And since most online theft doesn't take place physically near you, it's unlikely that a criminal will be able to grab your real password and your keyfob or iPhone.
Post a comment
Comments:
@juddcarlos2003:
It's a security tool. In addition to your Username and password, you would also enter the code on the keyfob. It generates new codes every minute or so, making it nearly impossible for someone to misuse your identity.
If all the credit card companies would require something like this, Identity theft would come to a screeching halt.
@pjorg: If you just don't have it with you at the moment, you'll have to go through a verification process to authorize that you're the owner of the account.
If you've lost it, you'll have to verify you're the account owner and then disable the security key from your account.
This comes in handy if you don't have a robust text messaging plan on your cell phone. If you do have a good text plan, PayPal/eBay can send you a text with a six-digit code every time you want to login...this is equivalent to the iPhone app and can be a faster option.
For me, I use this on PayPal, but not eBay, because I probably login to eBay 5 times more than PayPal, and it's not worth the hassle of pulling a code every one of those times.
@tvmitch: If you'd rather go this route, click the middle option in step 4 above. (The one I marked with "not this one!") There you'll enter your cellphone number and be sent a text message that authorizes your phone with your account, and then the rest is as tvmitch describes.
My wife uses this sort of thing to access patient records from home. Due to health records privacy laws (HIPA...the reason we have to fill a new form at the doctor/dentist yearly).
Seems to me that this would not be a secure as the keyfob. The keyfob has no radio and can not be hacked. It has to be in your physical possesion.
Also, would it not be possible to figure out what parameters the software is gathering from the phone and plug these into a program running elsewhere? Again, not possible with the fob since it using a code associated with that chip.
I know World of Warcraft has the same thing for account security. The problem is, the Blizzard Authenticators which are selling for $6.50 in the Blizzard store are sold out and going for over $40 on eBay. [www.blizzard.com]
My question is, will an application be made for WoW just like this so everyone can have the same level of security?
Authenticator FAQ [us.blizzard.com]
@LeJerk: Heh, should have read the thread before posting my comment. Yep, Blizzard has an iPhone authenticator app, and it's free.
@JGBrock: This would assume however that the person trying to hack into your PayPal/eBay account was also trying to hack into your iPhone at the same exact time. This would require the hacker to know that you had an iPhone and to be in close enough proximity to your phone so that he could somehow intercept any data that is being transmitted.
It may not be as foolproof or as secure as the fob, but it will stop probably 99.99% of the hackers, and the remaining 0.01% would need to have so many things going right for them that it is highly unlikely that they would be able to gain access.
The security claims for these devices are a little bit overblown. It is important that users be confident they are typing their details into the intended site and note a site that merely looks like it.
It is true that confirming who you are is now based on two factors: what you know (your password) and what you have (your keyfob). However, such systems are still open to attack by sufficiently clever and motivated attackers.
The general attack is called man-in-the-middle (please forgive the non-PCness for the alliteration). By tricking a user to go to the attacker's site the attacker can take the user's password and keyfob password, send it to the real E-Bay and then send the results back to the user.
This is why it pays to check for the little golden key at the bottom of your browser screen.
@Geoff Evans:
Good question, I tried that right away. Basically, the PayPal and eBay apps tell you to add the security key to the end of your password. It's not too hard: you open the VIP app, then you've got some time to switch to the other app and log in.
@icantreplyright: Boo. No wonder I'm not getting a text message to sent to my iPhone unlocked for T-Mobile.
@derelk: Okay, I lied. It doesn't seem that bad in principle, except that login fails every single time. I'm starting to think the iPhone apps aren't working with the security key at all.
@derelk: Okay, sorry, I lied again. I'm just an idiot.
It does work. And it's also worth noting that somehow, when you open the VIP app, it always gives you 30 seconds. So each time you have 30 seconds to remember the number, exit, open your eBay/PayPal app, and log in. Not too bad.
@pjorg: Specifically, the verification for PayPal will ask you for either the CC number associated with the account, the number of your PayPal debit card, if you have one, or the number of the bank account linked to your PayPal account. You choose which one to put in.
@dchoe: In PayPal, you can set up additional sub-users for an account and assign them specific privileges. I made a Mint subuser and gave it only "View Balance" privileges. Then, I use that subuser to link my PayPal to Mint / Yodlee.
@balls187: The physical access to your Verisign token is useless without your password, and your password is useless without your Verisign token. Someone having physical access to your stuff and brute forcing or guessing your (of course already strong) password is highly unlikely.
@pjorg: For that matter, how do you log onto Pay Pal from your iPhone? 30 seconds seems like a small window for a system that doesn't support multitasking.
What if you REFUSE to use PayPal? As in, I will no longer shop on EBay if it means I HAVE to use PayPal?
PayPal is not a bank, and it's not a credit card company. It does not have to follow any of the established US Banking rules & regs. They are a totally fly-by-night company that exists for one reason, to get their hands on your money.
@humphrmi: A couple things:
one, passwords are inherantly a weak form of protection, hence the need for a token.
Second, your token is only as good as it's protection. There are two attacks that tokens are vulnerable too:
one is generating the token (the OATH algorithm used is well documented)
and the other is stealing the token.
Neither of these two protections will protect you against man in the middle or phishing attacks.
@humphrmi: I can create a fake login site, and all I would need to do is to dupe you into entering your token and password, and I could then login in your stead.

















I don't understand what this is for. Can I give away a "keyfob" as a gift or what? Should I avoid this or what?
Like many people in this world and concerning many things, do not get mad at me for not knowing what this is.