<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html" />
  <link rel="self" type="application/atom+xml" href="http://consumerist.com/atom.xml" />
  <id>tag:consumerist.com,2010:/1/tag:64.14.177.195,2009://1.5215268-</id>
  <updated>2010-01-24T12:55:55Z</updated>
  <title>Comments for Free iPhone App Improves Paypal And EBay Security</title>
  <subtitle>Shoppers bite back.</subtitle>
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.32-en</generator>
  <entry>
    <id>tag:64.14.177.195,2009://1.5215268</id>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://consumerist.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=5215268" title="Free iPhone App Improves Paypal And EBay Security" />
    <published>2009-04-17T01:36:49Z</published>
    <updated>2009-04-17T02:11:29Z</updated>
    <title>Free iPhone App Improves Paypal And EBay Security</title>
    <summary><![CDATA[-->We've posted before about security keys&mdash;those little digital keyfobs that generate expiring security codes over and over and make it incredibly hard for someone to gain unauthorized access to your account. They're a great idea, and now if you own an iPhone you can install a Verisign app that will work with Paypal and eBay, as well as about two dozen lesser known sites. It's probably the easiest step you can take to vastly improve security on those accounts.]]></summary>
    <author>
      <name>Chris Walters</name>
      
    </author>
    
    <category term="Apple" />
    
    <category term="Other How To" />
    
    <category term="PayPal" />
    
    <category term="eBay" />
    
    <content type="html" xml:lang="en" xml:base="http://consumerist.com/">
      <![CDATA[
<p><!--<img src="http://consumerist.com/images/31/2009/04/041609-003-verisign-vip-app-for-iphone.png" height="158" width="158" class="left" alt="Free iPhone app from Verisign">-->We've posted before about <a href="http://consumerist.com/search/security%20key/">security keys</a>&mdash;those little digital keyfobs that generate expiring security codes over and over and make it <i>incredibly</i> hard for someone to gain unauthorized access to your account. They're a great idea, and now if you own an iPhone you can install a Verisign app that will work with Paypal and eBay, as well as about <a href="https://vipmobile.verisign.com/wheretouse.v">two dozen lesser known sites</a>. It's probably the easiest step you can take to vastly improve security on those accounts.</p>
]]>
      <![CDATA[
<p>It can be a little confusing to connect the Verisign app on your iPhone to your Paypal account, so we've taken screen shots of the process. Here's what you have to do.</p>
<div style="margin-left: 80px; margin-bottom: 10px; padding: 15px 15px 18px 15px; background-color: #fff; width: 480px;">
<p><img src="http://consumerist.com/images/31/2009/04/041609-003-paypal-verisign-1.png"  width="520" height="266" style="display:block;" /></p>
<p><img src="http://consumerist.com/images/31/2009/04/041609-003-paypal-verisign-2.png"  width="520" height="266" style="display:block;" /></p>
<p><img src="http://consumerist.com/images/31/2009/04/041609-003-paypal-verisign-3.png"  width="520" height="266" style="display:block;" /></p>
<p><img src="http://consumerist.com/images/31/2009/04/041609-003-paypal-verisign-4.png"  width="520" height="266" style="display:block;" /></p>
<p><img src="http://consumerist.com/images/31/2009/04/041609-003-paypal-verisign-5.png"  width="520" height="266" style="display:block;" /></p>
</div>
<p><br clear="all">
<br>
To launch the app info page in iTunes, <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewSoftware?id=307658513&mt=8">click here</a>. Sorry, it won't work on iPod Touch devices yet.</p>
<p><b>Update:</b> To address reader questions below, what this does is add a second password to your account. Unlike your real password, however, this one is automatically generated every 30 seconds. Because you register the serial number of the keyfob with the site (e.g. Paypal), it also generates the same password every 30 seconds. Now when you log in with your normal password, you'll be taken to a second screen where you have to enter the valid temporary password to finish logging in.</p>
<p>Because it's changing every 30 seconds, it's virtually useless to steal the password&mdash;you'd have to steal the keyfob or the iPhone. And since most online theft doesn't take place physically near you, it's unlikely that a criminal will be able to grab your real password <i>and</i> your keyfob or iPhone.</p>
]]>
    </content>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12202925</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12202925" />
    <title>Comment from m0unds on 2009-04-19</title>
    <author>
        <name>m0unds</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12164733" rel="nofollow">Harry Pothead</a>: you can continue..not..using them..?</p>]]>
    </content>
    <published>2009-04-19T07:33:50Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12177989</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12177989" />
    <title>Comment from balls187 on 2009-04-17</title>
    <author>
        <name>balls187</name>
        <uri>http://www.deeznuts.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.deeznuts.org">
        <![CDATA[<p>@<a href="#c12154552" rel="nofollow">humphrmi</a>: I can create a fake login site, and all I would need to do is to dupe you into entering your token and password, and I could then login in your stead.</p>]]>
    </content>
    <published>2009-04-18T01:46:35Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12177947</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12177947" />
    <title>Comment from balls187 on 2009-04-17</title>
    <author>
        <name>balls187</name>
        <uri>http://www.deeznuts.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.deeznuts.org">
        <![CDATA[<p>@<a href="#c12154552" rel="nofollow">humphrmi</a>: A couple things:</p>
<p>one, passwords are inherantly a weak form of protection, hence the need for a token.</p>
<p>Second, your token is only as good as it's protection. There are two attacks that tokens are vulnerable too:<br />
one is generating the token (the OATH algorithm used is well documented)</p>
<p>and the other is stealing the token.</p>
<p>Neither of these two protections will protect you against man in the middle or phishing attacks.</p>]]>
    </content>
    <published>2009-04-18T01:45:34Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12164733</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12164733" />
    <title>Comment from WelcomeToMyWorld on 2009-04-17</title>
    <author>
        <name>WelcomeToMyWorld</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p><p>What if you REFUSE to use PayPal? As in, I will no longer shop on EBay if it means I HAVE to use PayPal?</p><br />
<p>PayPal is not a bank, and it's not a credit card company. It does not have to follow any of the established US Banking rules &amp; regs. They are a totally fly-by-night company that exists for one reason, to get their hands on your money.</p></p>]]>
    </content>
    <published>2009-04-17T19:38:00Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12162743</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12162743" />
    <title>Comment from Papercutninja on 2009-04-17</title>
    <author>
        <name>Papercutninja</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12149866" rel="nofollow">YouDidWhatNow?</a>: Yeah man fight the power! Corporations bad! Communes GOOD!! YEAH!!</p>]]>
    </content>
    <published>2009-04-17T18:24:18Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12162703</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12162703" />
    <title>Comment from seishino on 2009-04-17</title>
    <author>
        <name>seishino</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p><p>@<a href="#c12147567" rel="nofollow">pjorg</a>: For that matter, how do you log onto Pay Pal from your iPhone?  30 seconds seems like a small window for a system that doesn't support multitasking.</p></p>]]>
    </content>
    <published>2009-04-17T18:21:57Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12160819</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12160819" />
    <title>Comment from Bearded Rapper on 2009-04-17</title>
    <author>
        <name>Bearded Rapper</name>
        <uri>http://michaelleung.tumblr.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://michaelleung.tumblr.com">
        <![CDATA[<p>@<a href="#c12154257" rel="nofollow">gStein</a>: Word up.</p>]]>
    </content>
    <published>2009-04-17T13:46:26Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12159874</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12159874" />
    <title>Comment from Geoff Evans on 2009-04-17</title>
    <author>
        <name>Geoff Evans</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12148830" rel="nofollow">Geoff Evans</a>: Perhaps it will be easier with copy and paste and iPhone 3.0</p>]]>
    </content>
    <published>2009-04-17T11:35:43Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12154567</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12154567" />
    <title>Comment from humphrmi on 2009-04-17</title>
    <author>
        <name>humphrmi</name>
        <uri>http://famille.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://famille.org">
        <![CDATA[<p>@<a href="#c12154552" rel="nofollow">humphrmi</a>: Whoops meant to end the {b} after "and".</p>]]>
    </content>
    <published>2009-04-17T06:09:57Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12154552</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12154552" />
    <title>Comment from humphrmi on 2009-04-17</title>
    <author>
        <name>humphrmi</name>
        <uri>http://famille.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://famille.org">
        <![CDATA[<p>@<a href="#c12148205" rel="nofollow">balls187</a>: The physical access to your Verisign token is useless without your password, and your password is useless without your Verisign token.  Someone having physical access to your stuff <b>and brute forcing or guessing your (of course already strong) password is highly unlikely.</b></p>]]>
    </content>
    <published>2009-04-17T06:09:24Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12154257</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12154257" />
    <title>Comment from gStein_*|bringing starpipe back|* on 2009-04-17</title>
    <author>
        <name>gStein_*|bringing starpipe back|*</name>
        <uri>http://twitter.com/gstein42</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://twitter.com/gstein42">
        <![CDATA[<p>@<a href="#c12148404" rel="nofollow">LeJerk</a>: that's some real FAIL when people are that concerned with their WoW account security</p>]]>
    </content>
    <published>2009-04-17T05:54:41Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12153612</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12153612" />
    <title>Comment from sethkinast on 2009-04-17</title>
    <author>
        <name>sethkinast</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12150812" rel="nofollow">dchoe</a>: In PayPal, you can set up additional sub-users for an account and assign them specific privileges. I made a Mint subuser and gave it only "View Balance" privileges. Then, I use that subuser to link my PayPal to Mint / Yodlee.</p>]]>
    </content>
    <published>2009-04-17T05:19:50Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12153563</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12153563" />
    <title>Comment from sethkinast on 2009-04-17</title>
    <author>
        <name>sethkinast</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12147567" rel="nofollow">pjorg</a>: Specifically, the verification for PayPal will ask you for either the CC number associated with the account, the number of your PayPal debit card, if you have one, or the number of the bank account linked to your PayPal account. You choose which one to put in.</p>]]>
    </content>
    <published>2009-04-17T05:17:45Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12153342</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12153342" />
    <title>Comment from derelk on 2009-04-17</title>
    <author>
        <name>derelk</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12153259" rel="nofollow">derelk</a>: Okay, sorry, I lied again. I'm just an idiot.</p>
<p>It does work. And it's also worth noting that somehow, when you open the VIP app, it always gives you 30 seconds. So each time you have 30 seconds to remember the number, exit, open your eBay/PayPal app, and log in. Not too bad.</p>]]>
    </content>
    <published>2009-04-17T05:07:35Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12153259</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12153259" />
    <title>Comment from derelk on 2009-04-17</title>
    <author>
        <name>derelk</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12153126" rel="nofollow">derelk</a>: Okay, I lied. It doesn't seem that bad in principle, except that login fails every single time. I'm starting to think the iPhone apps aren't working with the security key at all.</p>]]>
    </content>
    <published>2009-04-17T05:04:40Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12153196</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12153196" />
    <title>Comment from Michael Belisle on 2009-04-17</title>
    <author>
        <name>Michael Belisle</name>
        <uri>http://www.smift.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.smift.com/">
        <![CDATA[<p>@<a href="#c12149912" rel="nofollow">icantreplyright</a>: Boo. No wonder I'm not getting a text message to sent to my iPhone unlocked for T-Mobile.</p>]]>
    </content>
    <published>2009-04-17T05:02:25Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12153126</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12153126" />
    <title>Comment from derelk on 2009-04-16</title>
    <author>
        <name>derelk</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12148830" rel="nofollow">Geoff Evans</a>:<br />
Good question, I tried that right away. Basically, the PayPal and eBay apps tell you to add the security key to the end of your password. It's not too hard: you open the VIP app, then you've got some time to switch to the other app and log in.</p>]]>
    </content>
    <published>2009-04-17T04:59:48Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12151214</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12151214" />
    <title>Comment from vincedia on 2009-04-16</title>
    <author>
        <name>vincedia</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12148246" rel="nofollow">Blueskylaw</a>:</p>
<p>Too True.<br />
Forget Paypal and Ebay!</p>]]>
    </content>
    <published>2009-04-17T03:51:05Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12150812</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12150812" />
    <title>Comment from dchoe on 2009-04-16</title>
    <author>
        <name>dchoe</name>
        <uri>n/a</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="n/a">
        <![CDATA[<p>so will paypal not work on yodlee/mint/etc if you use this?</p>]]>
    </content>
    <published>2009-04-17T03:36:15Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12150697</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12150697" />
    <title>Comment from Kevin Carlyle on 2009-04-16</title>
    <author>
        <name>Kevin Carlyle</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>If you use the facebook iphone app it tells you to enter the keyfob code to the end of your password.</p>
<p>and it works</p>]]>
    </content>
    <published>2009-04-17T03:31:25Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12150395</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12150395" />
    <title>Comment from esarge on 2009-04-16</title>
    <author>
        <name>esarge</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>The security claims for these devices are a little bit overblown. It is important that users be confident they are typing their details into the intended site and note a site that merely looks like it.</p>
<p>It is true that confirming who you are is now based on two factors: what you know (your password) and what you have (your keyfob). However, such systems are still open to attack by sufficiently clever and motivated attackers.</p>
<p>The general attack is called man-in-the-middle (please forgive the non-PCness for the alliteration). By tricking a user to go to the attacker's site the attacker can take the user's password and keyfob password, send it to the real E-Bay and then send the results back to the user.</p>
<p>This is why it pays to check for the little golden key at the bottom of your browser screen.</p>]]>
    </content>
    <published>2009-04-17T03:20:38Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12150156</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12150156" />
    <title>Comment from icantreplyright on 2009-04-16</title>
    <author>
        <name>icantreplyright</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12148830" rel="nofollow">Geoff Evans</a>: I don't think this was designed for mobile sites.</p>]]>
    </content>
    <published>2009-04-17T03:11:09Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12149912</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12149912" />
    <title>Comment from icantreplyright on 2009-04-16</title>
    <author>
        <name>icantreplyright</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>They have it out for the Blackberry too. I just tried to add myself- Tmobile isn't supported. WTF? Why is the app carrier dependent? How does my carrier affect how my device operates? It doesn't. And no, it isn't the network, ATT IS supported. VeriSign = stupid. :)</p>]]>
    </content>
    <published>2009-04-17T03:01:53Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12149866</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12149866" />
    <title>Comment from YouDidWhatNow? on 2009-04-16</title>
    <author>
        <name>YouDidWhatNow?</name>
        <uri>http://</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://">
        <![CDATA[<p><p>...the big problem with this is that you're still dealing with the eBay/PayPal hellhole of eternal suffering.  There is not the slightest bit of trustworthiness in that infernal conflagration of a corporation.</p><br />
</p>]]>
    </content>
    <published>2009-04-17T03:00:14Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12149756</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12149756" />
    <title>Comment from juddcarlos2003 on 2009-04-16</title>
    <author>
        <name>juddcarlos2003</name>
        <uri>http://carlitosphotos.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://carlitosphotos.com">
        <![CDATA[<p>Now I understand. I wish my credit card companies would apply this. Esp social and email accounts such as gmail. Of course, with having the option to turn it off and on. Because I'm  paranoid of step mom intruding half way accross the country. The kind of step mom that doesn't exist to you anymore.</p>]]>
    </content>
    <published>2009-04-17T02:56:29Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12149734</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12149734" />
    <title>Comment from RonDiaz on 2009-04-16</title>
    <author>
        <name>RonDiaz</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Security and PayPal in the same sentence is an oxymoron.</p>]]>
    </content>
    <published>2009-04-17T02:55:55Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12149626</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12149626" />
    <title>Comment from Rachacha on 2009-04-16</title>
    <author>
        <name>Rachacha</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p><p>@<a href="http://consumerist.com/5215268/free-iphone-app-improves-paypal-and-ebay-security#c12148275" rel="nofollow">JGBrock</a>: This would assume however that the person trying to hack into your PayPal/eBay account was also trying to hack into your iPhone at the same exact time. This would require the hacker to know that you had an iPhone and to be in close enough proximity to your phone so that he could somehow intercept any data that is being transmitted.</p><br />
<p>It may not be as foolproof or as secure as the fob, but it will stop probably 99.99% of the hackers, and the remaining 0.01% would need to have so many things going right for them that it is highly unlikely that they would be able to gain access.</p></p>]]>
    </content>
    <published>2009-04-17T02:52:14Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12149331</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12149331" />
    <title>Comment from LeJerk on 2009-04-16</title>
    <author>
        <name>LeJerk</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I was thinking a version for regular cell phones. The PayPal site has one, but the Battle.Net one is "Coming Soon" for the U.S.A.</p>]]>
    </content>
    <published>2009-04-17T02:41:59Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12148971</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12148971" />
    <title>Comment from RecordStoreToughGuy_KnowsThreeChords on 2009-04-16</title>
    <author>
        <name>RecordStoreToughGuy_KnowsThreeChords</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@<a href="#c12148404" rel="nofollow">LeJerk</a>: Heh, should have read the thread before posting my comment.  Yep, Blizzard has an iPhone authenticator app, and it's free.</p>]]>
    </content>
    <published>2009-04-17T02:31:49Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12148934</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12148934" />
    <title>Comment from RecordStoreToughGuy_KnowsThreeChords on 2009-04-16</title>
    <author>
        <name>RecordStoreToughGuy_KnowsThreeChords</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>There is also an iPhone authenticator for Blizzard's Battle.net login, so you can get an authenticator for WoW without having to wait until the key fobs are in stock.</p>]]>
    </content>
    <published>2009-04-17T02:30:40Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12148830</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12148830" />
    <title>Comment from Geoff Evans on 2009-04-16</title>
    <author>
        <name>Geoff Evans</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Doesn't this just make using the iPhone version of eBay and Paypal harder to use?  Meaning, once you get the code you have to race to log into the iPhone app before your 30 seconds are up...</p>
<p>At least with the keyfob you can be looking at both at the same time...</p>]]>
    </content>
    <published>2009-04-17T02:27:29Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12148648</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12148648" />
    <title>Comment from LeJerk on 2009-04-16</title>
    <author>
        <name>LeJerk</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Ha. People don't need your password to scam you through PayPal and eBay.</p>]]>
    </content>
    <published>2009-04-17T02:20:47Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12148404</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12148404" />
    <title>Comment from LeJerk on 2009-04-16</title>
    <author>
        <name>LeJerk</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I know World of Warcraft has the same thing for account security. The problem is, the Blizzard Authenticators which are selling for $6.50 in the Blizzard store are sold out and going for over $40 on eBay. <a href="http://www.blizzard.com/store/details.xml?id=1100000442" rel="nofollow">[www.blizzard.com]</a></p>
<p>My question is, will an application be made for WoW just like this so everyone can have the same level of security?</p>
<p>Authenticator FAQ <a href="http://us.blizzard.com/support/article.xml?articleId=24660&amp;rhtml=true" rel="nofollow">[us.blizzard.com]</a></p>]]>
    </content>
    <published>2009-04-17T02:14:19Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12148275</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12148275" />
    <title>Comment from JGBrock on 2009-04-16</title>
    <author>
        <name>JGBrock</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p><p>My wife uses this sort of thing to access patient records from home. Due to health records privacy laws (HIPA...the reason we have to fill a new form at the doctor/dentist yearly).</p><br />
<p>Seems to me that this would not be a secure as the keyfob. The keyfob has no radio and can not be hacked. It has to be in your physical possesion.</p><br />
<p>Also, would it not be possible to figure out what parameters the software is gathering from the phone and plug these into a program running elsewhere? Again, not possible with the fob since it using a code associated with that chip.</p></p>]]>
    </content>
    <published>2009-04-17T02:10:48Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12148246</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12148246" />
    <title>Comment from Blueskylaw on 2009-04-16</title>
    <author>
        <name>Blueskylaw</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p><p>Improved Paypal security is great!!!!<br />Unless of course Paypal is the one stealing your money.</p></p>]]>
    </content>
    <published>2009-04-17T02:10:07Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12148205</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12148205" />
    <title>Comment from balls187 on 2009-04-16</title>
    <author>
        <name>balls187</name>
        <uri>http://www.deeznuts.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.deeznuts.org">
        <![CDATA[<p>It doesn't make it hard for someone to break into your account.</p>
<p>It makes it hard for people without physical access to your stuff, to break in.</p>]]>
    </content>
    <published>2009-04-17T02:08:31Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12147862</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12147862" />
    <title>Comment from Chris Walters on 2009-04-16</title>
    <author>
        <name>Chris Walters</name>
        <uri>http://twitter.com/consumerchris</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://twitter.com/consumerchris">
        <![CDATA[<p>@<a href="#c12147764" rel="nofollow">tvmitch</a>: If you'd rather go this route, click the middle option in step 4 above. (The one I marked with "not this one!") There you'll enter your cellphone number and be sent a text message that authorizes your phone with your account, and then the rest is as tvmitch describes.</p>]]>
    </content>
    <published>2009-04-17T01:57:48Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12147764</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12147764" />
    <title>Comment from tvmitch on 2009-04-16</title>
    <author>
        <name>tvmitch</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>This comes in handy if you don't have a robust text messaging plan on your cell phone. If you do have a good text plan, PayPal/eBay can send you a text with a six-digit code every time you want to login...this is equivalent to the iPhone app and can be a faster option.</p>
<p>For me, I use this on PayPal, but not eBay, because I probably login to eBay 5 times more than PayPal, and it's not worth the hassle of pulling a code every one of those times.</p>]]>
    </content>
    <published>2009-04-17T01:54:51Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12147672</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12147672" />
    <title>Comment from Chris Walters on 2009-04-16</title>
    <author>
        <name>Chris Walters</name>
        <uri>http://twitter.com/consumerchris</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://twitter.com/consumerchris">
        <![CDATA[<p>@<a href="#c12147567" rel="nofollow">pjorg</a>: If you just don't have it with you at the moment, you'll have to go through a verification process to authorize that you're the owner of the account.</p>
<p>If you've lost it, you'll have to verify you're the account owner and then disable the security key from your account.</p>]]>
    </content>
    <published>2009-04-17T01:52:33Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12147638</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12147638" />
    <title>Comment from starrion on 2009-04-16</title>
    <author>
        <name>starrion</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p><p>@<a href="http://consumerist.com/5215268/free-iphone-app-improves-paypal-and-ebay-security#c12147404" rel="nofollow">juddcarlos2003</a>: <br />It's a security tool. In addition to your Username and password, you would also enter the code on the keyfob. It generates new codes every minute or so, making it nearly impossible for someone to misuse your identity.</p><br />
<p>If all the credit card companies would require something like this, Identity theft would come to a screeching halt.</p></p>]]>
    </content>
    <published>2009-04-17T01:51:37Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12147567</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12147567" />
    <title>Comment from pjorg on 2009-04-16</title>
    <author>
        <name>pjorg</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>This is cool, but I'm worried about what happens on those rare occasions when I'm not near my iPhone.  Or, more realistically, when the battery is dead.</p>
<p>Is there some longer confirmation process that I can use to log in anyway?  Or am I SOL?</p>]]>
    </content>
    <published>2009-04-17T01:49:48Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2009://1.5215268-comment:12147404</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2009://1.5215268" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2009/04/free-iphone-app-improves-paypal-and-ebay-security.html#c12147404" />
    <title>Comment from juddcarlos2003 on 2009-04-16</title>
    <author>
        <name>juddcarlos2003</name>
        <uri>http://carlitosphotos.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://carlitosphotos.com">
        <![CDATA[<p>I don't understand what this is for. Can I give away a "keyfob" as a gift or what? Should I avoid this or what?<br />
Like many people in this world and concerning many things, do not get mad at me for not knowing what this is.</p>]]>
    </content>
    <published>2009-04-17T01:45:43Z</published>
  </entry>


</feed>



