Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That implies that it's easier to get the password change email sent to an address with a different local part at the same domain than to a completely different domain.


He also noted:

  @Alex Khomenko told me in another place, that there may be
  a secondary authentication on password changes from the
  forgotten password link, in the US PayPal. If true and
  currently in place this would mean that the US is not
  vulnerable, although they may still have the email bug
He said he doesn't use PayPal himself and that he only requested a change password link when he was trying to contact them about "effective spam". Perhaps he supplied them with one of his email addresses and it happened to have a counterpart at a different subdomain (like example@email.com vs example@email.com.au)?

EDIT: Formatting.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: