So I go to dealextreme to buy cheap crap and I try to pay by paypal. The site redirects to the paypal secure login/checkout and I log in. It says I can't pay because my account access has been restricted. My thats certainly odd. Everything looks on the up and up but just to be sure I log on to to clean paypal url from another computer. Sure enough, locked so it isn't some nasty spyware taking over the hosts file or anything.
Shortly after I also receive
Now I find several things interesting. My paypal email address and password are unique so its not likely they've been stolen from another site. I don't want to say I'm impervious to social engineering but I've been working in the tech field, well since I was old enough to work. I like to think I've got the basics down and this is more than likely poor detection.
When I looked at the information on the paypal site it also said it locked my account May 24th. I believe I used paypal from my office PC on that date, and I suspect thats what its related to. It seems improbable as I can't imagine that many people don't access their paypal account from work also but its the only thing that makes sense. Which brings up another issue, why if my account was locked weeks ago didn't paypal send me paper notification or call me at the time? They're going to send me a 4 digit address confirmation code in the mail now but that seems quite late and irresponsible as far as notifying your customers in the event of security problems.
Anyway I just wanted to get a good paypal rant out there because despite reading tons of "I hate paypal" posts I've never gotten to make one. I did get the genuine version of one of the most spammy emails in history though. Maybe a real prince will email me soon too.
Shortly after I also receive
Subject: Notification of Limited Account Access
Dear Soy Bomb,
As part of our security measures, we regularly screen activity in the PayPal system. During a recent screening, we noticed an issue regarding your account.
We have reason to believe that your account was accessed by a third party. We have limited access to sensitive PayPal account features in case your account has been accessed by an unauthorized third party. We understand that having limited access can be an inconvenience, but protecting your account is our primary concern.
Case ID Number: PP-123-456-789
Sincerely, PayPal Account Review Department
----------------------------------------------------------------
PayPal Email ID PP522
Now I find several things interesting. My paypal email address and password are unique so its not likely they've been stolen from another site. I don't want to say I'm impervious to social engineering but I've been working in the tech field, well since I was old enough to work. I like to think I've got the basics down and this is more than likely poor detection.
When I looked at the information on the paypal site it also said it locked my account May 24th. I believe I used paypal from my office PC on that date, and I suspect thats what its related to. It seems improbable as I can't imagine that many people don't access their paypal account from work also but its the only thing that makes sense. Which brings up another issue, why if my account was locked weeks ago didn't paypal send me paper notification or call me at the time? They're going to send me a 4 digit address confirmation code in the mail now but that seems quite late and irresponsible as far as notifying your customers in the event of security problems.
Anyway I just wanted to get a good paypal rant out there because despite reading tons of "I hate paypal" posts I've never gotten to make one. I did get the genuine version of one of the most spammy emails in history though. Maybe a real prince will email me soon too.
