{"exhaustive":{"nbHits":false,"typo":false},"exhaustiveNbHits":false,"exhaustiveTypo":false,"hits":[{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"pseudolus"},"title":{"fullyHighlighted":false,"matchLevel":"partial","matchedWords":["securities"],"value":"Official abuse of state security has always been bad, now it's horrifying"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"https://www.theregister.com/2025/04/14/opinion_secret_state_security/?td=rt-3a"}},"_tags":["story","author_pseudolus","story_43750144"],"author":"pseudolus","children":[43750451,43750570,43750717,43750927,43751000,43751244,43751761,43752442,43757058],"created_at":"2025-04-21T10:02:18Z","created_at_i":1745229738,"num_comments":10,"objectID":"43750144","points":96,"story_id":43750144,"title":"Official abuse of state security has always been bad, now it's horrifying","updated_at":"2025-08-14T22:18:30Z","url":"https://www.theregister.com/2025/04/14/opinion_secret_state_security/?td=rt-3a"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"andsoitis"},"title":{"matchLevel":"none","matchedWords":[],"value":"S&P's decision not to include SpaceX is a mistake"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"https://seekingalpha.com/news/4603059-s-and-p-s-decision-not-to-include-spacex-is-a-huge-mistake-td-securities-peter-haynes"}},"_tags":["story","author_andsoitis","story_48530979"],"author":"andsoitis","children":[48531043,48531623],"created_at":"2026-06-14T18:40:14Z","created_at_i":1781462414,"num_comments":2,"objectID":"48530979","points":4,"story_id":48530979,"title":"S&P's decision not to include SpaceX is a mistake","updated_at":"2026-06-21T16:44:21Z","url":"https://seekingalpha.com/news/4603059-s-and-p-s-decision-not-to-include-spacex-is-a-huge-mistake-td-securities-peter-haynes"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"trifit"},"title":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"TD Synnex and Arrow bolster security options"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"https://www.computerweekly.com/microscope/news/252528998/TD-Synnex-and-Arrow-bolster-security-options"}},"_tags":["story","author_trifit","story_34336648"],"author":"trifit","created_at":"2023-01-11T09:19:44Z","created_at_i":1673428784,"num_comments":0,"objectID":"34336648","points":1,"story_id":34336648,"title":"TD Synnex and Arrow bolster security options","updated_at":"2024-09-20T13:02:06Z","url":"https://www.computerweekly.com/microscope/news/252528998/TD-Synnex-and-Arrow-bolster-security-options"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"swedegeek"},"title":{"matchLevel":"none","matchedWords":[],"value":"Over a month later and Comcast still doesn't know how to SSL"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"http://forums.comcast.com/t5/Xfinity-com-Website/Comcast-net-s-web-site-SSL-Security-Certificate-has-expired/td-p/1418385"}},"_tags":["story","author_swedegeek","story_4707854"],"author":"swedegeek","children":[4707951,4707992,4707996,4708003,4708010,4708017,4708104,4708120,4708176,4708444,4708493,4708536,4708659,4708881,4709727],"created_at":"2012-10-28T01:41:15Z","created_at_i":1351388475,"num_comments":49,"objectID":"4707854","points":131,"story_id":4707854,"title":"Over a month later and Comcast still doesn't know how to SSL","updated_at":"2024-09-19T18:54:39Z","url":"http://forums.comcast.com/t5/Xfinity-com-Website/Comcast-net-s-web-site-SSL-Security-Certificate-has-expired/td-p/1418385"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"dewey"},"title":{"matchLevel":"none","matchedWords":[],"value":"Skype account hijack technique may affect all users"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"http://community.skype.com/t5/Security-Privacy-Trust-and/URGENT-Skype-Support-Account-Security-Issue-CAN-AFFECT-ALL-USERS/td-p/1552372"}},"_tags":["story","author_dewey","story_5622045"],"author":"dewey","children":[5622146,5622224,5622256,5622278,5622337,5622343,5622395,5622400,5622571,5622689,5622843,5623705,5623846,5624234,5624555],"created_at":"2013-04-28T17:49:13Z","created_at_i":1367171353,"num_comments":66,"objectID":"5622045","points":265,"story_id":5622045,"title":"Skype account hijack technique may affect all users","updated_at":"2024-09-19T19:29:00Z","url":"http://community.skype.com/t5/Security-Privacy-Trust-and/URGENT-Skype-Support-Account-Security-Issue-CAN-AFFECT-ALL-USERS/td-p/1552372"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"rPawel"},"story_text":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"I have started receiving some spoofed messages yesterday from my friends and peers on Skype leading to some doggy urls. It seems I am not the only one:\nhttp://community.skype.com/t5/Security-Privacy-Trust-and/Spoofed-message-from-contact/td-p/4026578

Some people blame new web api: \nhttp://security.stackexchange.com/questions/93305/insert-hidden-link-in-skype

Apparently there is no official Microsoft statement about the issue yet, apart from the quick note from a community moderator:

"We can confirm continued reports from some Skype users about their accounts being used to send spam and we continue to investigating the cause.

Should your account be affected please ensure to change all your passwords. E.g. if you have a Skype account and a linked Microsoft account you need to change the password for both.

We'll provide another update tomorrow.""},"title":{"fullyHighlighted":false,"matchLevel":"partial","matchedWords":["securities"],"value":"Skype security breached"},"url":{"matchLevel":"none","matchedWords":[],"value":""}},"_tags":["story","author_rPawel","story_9862408","ask_hn"],"author":"rPawel","children":[9862508,9863138,9868521,9872787],"created_at":"2015-07-10T05:10:25Z","created_at_i":1436505025,"num_comments":3,"objectID":"9862408","points":21,"story_id":9862408,"story_text":"I have started receiving some spoofed messages yesterday from my friends and peers on Skype leading to some doggy urls. It seems I am not the only one:\nhttp://community.skype.com/t5/Security-Privacy-Trust-and/Spoofed-message-from-contact/td-p/4026578

Some people blame new web api: \nhttp://security.stackexchange.com/questions/93305/insert-hidden-link-in-skype

Apparently there is no official Microsoft statement about the issue yet, apart from the quick note from a community moderator:

"We can confirm continued reports from some Skype users about their accounts being used to send spam and we continue to investigating the cause.

Should your account be affected please ensure to change all your passwords. E.g. if you have a Skype account and a linked Microsoft account you need to change the password for both.

We'll provide another update tomorrow."","title":"Skype security breached","updated_at":"2024-09-19T22:01:59Z","url":""},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"jkaljundi"},"story_text":{"matchLevel":"none","matchedWords":[],"value":""},"title":{"fullyHighlighted":false,"matchLevel":"partial","matchedWords":["securities"],"value":"Skype security bug: chat messages being sent to random people"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"http://community.skype.com/t5/Security-Privacy-Trust-and/Skype-text-messages-I-received-have-gone-to-another-contact/td-p/860602"}},"_tags":["story","author_jkaljundi","story_4246443"],"author":"jkaljundi","created_at":"2012-07-15T07:46:00Z","created_at_i":1342338360,"num_comments":0,"objectID":"4246443","points":3,"story_id":4246443,"story_text":"","title":"Skype security bug: chat messages being sent to random people","updated_at":"2024-09-19T18:45:31Z","url":"http://community.skype.com/t5/Security-Privacy-Trust-and/Skype-text-messages-I-received-have-gone-to-another-contact/td-p/860602"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"mbgaxyz"},"title":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"TD Ameritrade is the first retail brokerage to offer 24/5 trading of securities"},"url":{"matchLevel":"none","matchedWords":[],"value":"https://www.tdameritrade.com/tools-and-platforms/after-hours-trading.page"}},"_tags":["story","author_mbgaxyz","story_16317427"],"author":"mbgaxyz","created_at":"2018-02-06T16:44:03Z","created_at_i":1517935443,"num_comments":0,"objectID":"16317427","points":2,"story_id":16317427,"title":"TD Ameritrade is the first retail brokerage to offer 24/5 trading of securities","updated_at":"2024-09-20T02:00:35Z","url":"https://www.tdameritrade.com/tools-and-platforms/after-hours-trading.page"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"vanchor3"},"story_text":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"I have a US PayPal account.

When I went to check a $10 Starbucks transaction I had made, I noticed a strange link was there saying "Get more details in your PayPal China account".

I do not have a PayPal China account as far as I know. Even stranger is the link starts with "paypa.cn/withdraw". This does not appear to be a site owned by PayPal.

A quick search shows a PayPal community forums post (https://www.paypal-community.com/t5/Managing-Account/What-does-quot-Get-more-details-in-your-Paypal-China-account/td-p/2989268), where users that have contacted support are being told that it's a "known issue". Based on the post date this has been there for at least six days.

I'm a bit skeptical though. A bug causing the link to show up when it shouldn't, as well as someone forgetting the L in paypal.cn both sounds like things that could happen, but simultaneously? Even then, it seems like they could have fixed this days ago, and should have as potentially sending users and their transaction IDs to a different website seems like a pretty big security issue."},"title":{"matchLevel":"none","matchedWords":[],"value":"Ask HN: Why is PayPal sending me to a Chinese website?"}},"_tags":["story","author_vanchor3","story_33104691","ask_hn"],"author":"vanchor3","children":[33105018],"created_at":"2022-10-06T05:27:29Z","created_at_i":1665034049,"num_comments":1,"objectID":"33104691","points":13,"story_id":33104691,"story_text":"I have a US PayPal account.

When I went to check a $10 Starbucks transaction I had made, I noticed a strange link was there saying "Get more details in your PayPal China account".

I do not have a PayPal China account as far as I know. Even stranger is the link starts with "paypa.cn/withdraw". This does not appear to be a site owned by PayPal.

A quick search shows a PayPal community forums post (https://www.paypal-community.com/t5/Managing-Account/What-does-quot-Get-more-details-in-your-Paypal-China-account/td-p/2989268), where users that have contacted support are being told that it's a "known issue". Based on the post date this has been there for at least six days.

I'm a bit skeptical though. A bug causing the link to show up when it shouldn't, as well as someone forgetting the L in paypal.cn both sounds like things that could happen, but simultaneously? Even then, it seems like they could have fixed this days ago, and should have as potentially sending users and their transaction IDs to a different website seems like a pretty big security issue.","title":"Ask HN: Why is PayPal sending me to a Chinese website?","updated_at":"2024-09-20T12:09:12Z"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"-__-"},"story_text":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"I'm building a mobile browser (webkit base) with accessibility features, including an option to override page fonts with OpenDyslexic. I have tried every permutation of:

const style = document.createElement('style');\nstyle.textContent = `\n @font-face {\n font-family: 'OpenDyslexic';\n src: url('data:font/opentype;base64,...') format('opentype');\n }\n * { font-family: 'OpenDyslexic', sans-serif !important; }\n`;\ndocument.head.appendChild(style);

it works everywhere. every link I click from this page, every website from the 90s I can find. everywhere except here!

On HN, the font-family CSS applies (I can see it in the inspector, elements show font-family: OpenDyslexic !important), but the actual rendered font falls back to sans-serif. The @font-face is in the DOM. The base64 is valid, the code works on other sites.

Tried: blob URLs instead of data URLs, MutationObserver to reapply, targeting specific elements (font, td, table), setTimeout delays. so much more. Nothing works on HN specifically.

Is there something about HN's markup or headers that would cause @font-face to fail silently? Has anyone dealt with this issue or know why it could be happening? content security policy & cors don\u2019t seem at fault bc the base64 is in the dom. What might I be missing?"},"title":{"matchLevel":"none","matchedWords":[],"value":"Ask HN: Why can't I apply custom fonts to HN?"}},"_tags":["story","author_-__-","story_46748659","ask_hn"],"author":"-__-","children":[46748704],"created_at":"2026-01-24T23:06:43Z","created_at_i":1769296003,"num_comments":3,"objectID":"46748659","points":4,"story_id":46748659,"story_text":"I'm building a mobile browser (webkit base) with accessibility features, including an option to override page fonts with OpenDyslexic. I have tried every permutation of:

const style = document.createElement('style');\nstyle.textContent = `\n @font-face {\n font-family: 'OpenDyslexic';\n src: url('data:font/opentype;base64,...') format('opentype');\n }\n * { font-family: 'OpenDyslexic', sans-serif !important; }\n`;\ndocument.head.appendChild(style);

it works everywhere. every link I click from this page, every website from the 90s I can find. everywhere except here!

On HN, the font-family CSS applies (I can see it in the inspector, elements show font-family: OpenDyslexic !important), but the actual rendered font falls back to sans-serif. The @font-face is in the DOM. The base64 is valid, the code works on other sites.

Tried: blob URLs instead of data URLs, MutationObserver to reapply, targeting specific elements (font, td, table), setTimeout delays. so much more. Nothing works on HN specifically.

Is there something about HN's markup or headers that would cause @font-face to fail silently? Has anyone dealt with this issue or know why it could be happening? content security policy & cors don\u2019t seem at fault bc the base64 is in the dom. What might I be missing?","title":"Ask HN: Why can't I apply custom fonts to HN?","updated_at":"2026-03-05T23:24:59Z"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"seeker0001"},"story_text":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"(Posting with a throwaway account. My normal HN username would be immediately recognizable to anyone who knows me, and I'd just as soon not advertise the fact that I'm thinking about making changes or that I've entertained other job offers)

tl;dr version: I'm an older S/W engineer. I'm very good at what I do. I've worked for a successful DoD contractor start up for quite a while. I'm bored. I'm interested in CG/VFX and also in prop-trading/HFT. I've had offers from both fields, but I declined them. Looking back, I wished I'd taken them. I'm more than ready for a change. What do I do now?

(many semi-colon delimited lists follow)

Basic facts: I'm forty- years of age; married, no kids; I've been working as a software engineer/devop for many, many years; I know a lot about: C,C++/STL/Boost,Linux,bash,perl,python,node.js,etc; I've been with the same company (a very successful and rapidly growing DoD contractor) for the last 12 or so years; I was a very early employee at said company; as this company continues to grow and mature, I find it more and more boring to work there. Because of my waning interest, I don't see much opportunity for career growth (eg. management) (however, I do have great job security as it is).

So, I think a lot about pivoting my career into a new domain. At this stage of my career/life, this amounts to major changes involving my work, my family, and my future, and so of course I'm turning to complete strangers for advice.

Here are my interests/options:

Option A: stay put. Pros: Indefinite job security; very good salary, ridiculously good benefits; low(-ish) pressure; interesting low-level technical work; chance (slim) that the company will be bought up by one of the big DoD contractors and I'll get a large-ish payout. Cons: minuscule bonuses; domain is mature and not all that exciting to me any more; definitely not interested in moving into management; the DoD doesn't have all that many truly smart people, so it's frustrating to deal with customers; I've been waiting for this mythical payout for years, and I no longer think it will ever happen; I really feel like I'm starting to stagnate professionally, and that it's time for a change.

Option B: cinema CG/VFX. I'm utterly fascinated by this stuff. I'm not much of an artist, but there is a lot of tech work in this domain. Judging by the job postings, I think I'd be good for a \"Pipeline TD\" or \"Studio Tools\" type of position. (Full disclosure: Several years ago, I turned down (what turned out to be) a decent offer from a major, household-name animation studio, and I've regretted it ever since.) Pros: enthusiasm; working with creative types (this is huge for me); enough interest to sustain a career path into management; seemingly many places to work for; movie magic, name in credits, etc. Cons: definite pay cut (the offer was a good 15% lower than my salary at the time, but I was ready to absorb the cut (my wife wasn't)); probably small (if any) bonuses; it's a high-pressure job; unsure that someone my age can pivot into the industry; everybody wants to work in the movies, so there's downward pressure on salaries; relocation to locales that may be a hard sell to my wife; maybe I'm wearing rose-colored glasses here.

Option C: Prop-Trading/HFT. About three years ago, I had a good offer from a (non-HFT) prop trading boutique shop, in a location I like. I was ready to accept when the founders of my current company made me aware of the possible payout (which they claimed was imminent). In retrospect, I should have taken the offer. (The good news is that this shop may still hire me.) Pros: I'm getting a lot of interest on LinkedIn from prop-trading houses, which is gratifying; my skillset & experience seems to slot right into the field; very interesting technical challenges; possibility of astounding bonuses: I have friends working in banking, and they pull down a ton of bonus, and even in a \"not-good\" year, the bonuses would beat the bonuses I make now; binary metric of success is appealing: either you make money or you lose it. Cons: Not interested in relocating to NYC or Chicago (nice places to visit, though); can be very high-pressure; high dollars tend to attract douchebags, which are no fun to work with (to be sure, though, there are some extremely interesting non-douchbags in the field); unsure of the career path beyond writing software; I don't have nearly the enthusiasm for this as I do the CG/VFX stuff.

I should clarify that the company I currently work for is a very good company to be employed by. I can't find any faults, other then the normal faults that any software development company has. The point here is that I'm bored of the problem domain in general. There is just no new ground for me to mine here, other than management, which I just can't do (for this company).

I was content for a long time in my career to simply design and build software. I'm good at it and I enjoy it. But I've reached the point where I want more from my career, and if I'm to achieve that, then I'll need to dive into something that I'm enthusiastic about and that will take me beyond software development. Clearly, if I could turn the clock back a few years, I'd head off in the CG/VFX direction. I don't know how realistic that option is anymore. One thing's for certain, though: I do need a change. I really like working with creative types, but by latching onto the CG/VFX domain, maybe I've got my vision too narrowed. Maybe there's other options.

At any rate, thanks for reading. Any comments appreciated."},"title":{"matchLevel":"none","matchedWords":[],"value":"Ask HN: Advice needed: Career Pivot? (Long)"}},"_tags":["story","author_seeker0001","story_3379386","ask_hn"],"author":"seeker0001","children":[3379393],"created_at":"2011-12-21T22:15:03Z","created_at_i":1324505703,"num_comments":2,"objectID":"3379386","points":2,"story_id":3379386,"story_text":"(Posting with a throwaway account. My normal HN username would be immediately recognizable to anyone who knows me, and I'd just as soon not advertise the fact that I'm thinking about making changes or that I've entertained other job offers)

tl;dr version: I'm an older S/W engineer. I'm very good at what I do. I've worked for a successful DoD contractor start up for quite a while. I'm bored. I'm interested in CG/VFX and also in prop-trading/HFT. I've had offers from both fields, but I declined them. Looking back, I wished I'd taken them. I'm more than ready for a change. What do I do now?

(many semi-colon delimited lists follow)

Basic facts: I'm forty-<mumble> years of age; married, no kids; I've been working as a software engineer/devop for many, many years; I know a lot about: C,C++/STL/Boost,Linux,bash,perl,python,node.js,etc; I've been with the same company (a very successful and rapidly growing DoD contractor) for the last 12 or so years; I was a very early employee at said company; as this company continues to grow and mature, I find it more and more boring to work there. Because of my waning interest, I don't see much opportunity for career growth (eg. management) (however, I do have great job security as it is).

So, I think a lot about pivoting my career into a new domain. At this stage of my career/life, this amounts to major changes involving my work, my family, and my future, and so of course I'm turning to complete strangers for advice.

Here are my interests/options:

Option A: stay put. Pros: Indefinite job security; very good salary, ridiculously good benefits; low(-ish) pressure; interesting low-level technical work; chance (slim) that the company will be bought up by one of the big DoD contractors and I'll get a large-ish payout. Cons: minuscule bonuses; domain is mature and not all that exciting to me any more; definitely not interested in moving into management; the DoD doesn't have all that many truly smart people, so it's frustrating to deal with customers; I've been waiting for this mythical payout for years, and I no longer think it will ever happen; I really feel like I'm starting to stagnate professionally, and that it's time for a change.

Option B: cinema CG/VFX. I'm utterly fascinated by this stuff. I'm not much of an artist, but there is a lot of tech work in this domain. Judging by the job postings, I think I'd be good for a \"Pipeline TD\" or \"Studio Tools\" type of position. (Full disclosure: Several years ago, I turned down (what turned out to be) a decent offer from a major, household-name animation studio, and I've regretted it ever since.) Pros: enthusiasm; working with creative types (this is huge for me); enough interest to sustain a career path into management; seemingly many places to work for; movie magic, name in credits, etc. Cons: definite pay cut (the offer was a good 15% lower than my salary at the time, but I was ready to absorb the cut (my wife wasn't)); probably small (if any) bonuses; it's a high-pressure job; unsure that someone my age can pivot into the industry; everybody wants to work in the movies, so there's downward pressure on salaries; relocation to locales that may be a hard sell to my wife; maybe I'm wearing rose-colored glasses here.

Option C: Prop-Trading/HFT. About three years ago, I had a good offer from a (non-HFT) prop trading boutique shop, in a location I like. I was ready to accept when the founders of my current company made me aware of the possible payout (which they claimed was imminent). In retrospect, I should have taken the offer. (The good news is that this shop may still hire me.) Pros: I'm getting a lot of interest on LinkedIn from prop-trading houses, which is gratifying; my skillset & experience seems to slot right into the field; very interesting technical challenges; possibility of astounding bonuses: I have friends working in banking, and they pull down a ton of bonus, and even in a \"not-good\" year, the bonuses would beat the bonuses I make now; binary metric of success is appealing: either you make money or you lose it. Cons: Not interested in relocating to NYC or Chicago (nice places to visit, though); can be very high-pressure; high dollars tend to attract douchebags, which are no fun to work with (to be sure, though, there are some extremely interesting non-douchbags in the field); unsure of the career path beyond writing software; I don't have nearly the enthusiasm for this as I do the CG/VFX stuff.

I should clarify that the company I currently work for is a very good company to be employed by. I can't find any faults, other then the normal faults that any software development company has. The point here is that I'm bored of the problem domain in general. There is just no new ground for me to mine here, other than management, which I just can't do (for this company).

I was content for a long time in my career to simply design and build software. I'm good at it and I enjoy it. But I've reached the point where I want more from my career, and if I'm to achieve that, then I'll need to dive into something that I'm enthusiastic about and that will take me beyond software development. Clearly, if I could turn the clock back a few years, I'd head off in the CG/VFX direction. I don't know how realistic that option is anymore. One thing's for certain, though: I do need a change. I really like working with creative types, but by latching onto the CG/VFX domain, maybe I've got my vision too narrowed. Maybe there's other options.

At any rate, thanks for reading. Any comments appreciated.","title":"Ask HN: Advice needed: Career Pivot? (Long)","updated_at":"2023-09-06T20:50:55Z"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"ivm"},"story_text":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"Last week I started receiving SMS with PayPal security codes and then got a notification about someone adding a card to my account and withdrawing $1.5k.

2FA was disabled because it doesn't work in Safari (including logging in from their iOS app, imagine this), so I blamed myself, turned it on, reported the unauthorized transaction to PayPal\u2026 and had $1.5k more withdrawn to a newly added card two days later!

Apparently, there is an option of an SMS-based login(!!!) where they send you a 6-digit code that allows for a login without 2FA:\nhttps://www.paypal-community.com/t5/Managing-Account/How-do-I-disable-one-time-codes/td-p/2835147

I don't know if the SMS gateway to my Chilean number is leaky or if they just brute-forced the code, but here we are. Also, no confirmation is needed to add new cards and make withdrawals even when 2FA is enabled.

(Yes, I know keeping money at non-bank payment services isn't good, but withdrawing it from there meant a conversion to my local currency which nowadays devalues much faster than USD. Greed got me.)"},"title":{"matchLevel":"none","matchedWords":[],"value":"Tell HN: PayPal now allows to bypass 2FA with a SMS login"}},"_tags":["story","author_ivm","story_33072443","ask_hn"],"author":"ivm","created_at":"2022-10-03T19:28:31Z","created_at_i":1664825311,"num_comments":0,"objectID":"33072443","points":2,"story_id":33072443,"story_text":"Last week I started receiving SMS with PayPal security codes and then got a notification about someone adding a card to my account and withdrawing $1.5k.

2FA was disabled because it doesn't work in Safari (including logging in from their iOS app, imagine this), so I blamed myself, turned it on, reported the unauthorized transaction to PayPal\u2026 and had $1.5k more withdrawn to a newly added card two days later!

Apparently, there is an option of an SMS-based login(!!!) where they send you a 6-digit code that allows for a login without 2FA:\nhttps://www.paypal-community.com/t5/Managing-Account/How-do-I-disable-one-time-codes/td-p/2835147

I don't know if the SMS gateway to my Chilean number is leaky or if they just brute-forced the code, but here we are. Also, no confirmation is needed to add new cards and make withdrawals even when 2FA is enabled.

(Yes, I know keeping money at non-bank payment services isn't good, but withdrawing it from there meant a conversion to my local currency which nowadays devalues much faster than USD. Greed got me.)","title":"Tell HN: PayPal now allows to bypass 2FA with a SMS login","updated_at":"2024-09-20T12:15:31Z"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"throwprintz"},"story_text":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"The home button on some samsung phones contains a fingerprint scanner. Is it possible to somehow physically block the fingerprint scanner sensor from capturing fingerprints? (e.g. cover it with tape, nail polish or something else?)

Only found these but with no definitive answer:

https://security.stackexchange.com/questions/171494/is-it-possible-to-disable-the-fingerprint-scanner-but-not-the-button-its-on

https://forums.lenovo.com/t5/Moto-G5-Moto-G5-Plus/I-don-t-like-fingerprint-sensors-is-it-possible-to-disable-it-by/td-p/3729524

Seems strange there isn't much discussion around this, given the uniqueness and sensitivity of biometrical data and the blatant disregard companies pay to its protection (industry standard is to view user data as an asset not a liability - and regulator bodies aren't doing much about that either).

[edit]: Added final sentence"},"title":{"matchLevel":"none","matchedWords":[],"value":"Ask HN: Physically block mobile phone fingerprint scanner?"}},"_tags":["story","author_throwprintz","story_15973005","ask_hn"],"author":"throwprintz","created_at":"2017-12-20T19:43:24Z","created_at_i":1513799004,"num_comments":0,"objectID":"15973005","points":1,"story_id":15973005,"story_text":"The home button on some samsung phones contains a fingerprint scanner. Is it possible to somehow physically block the fingerprint scanner sensor from capturing fingerprints? (e.g. cover it with tape, nail polish or something else?)

Only found these but with no definitive answer:

https://security.stackexchange.com/questions/171494/is-it-possible-to-disable-the-fingerprint-scanner-but-not-the-button-its-on

https://forums.lenovo.com/t5/Moto-G5-Moto-G5-Plus/I-don-t-like-fingerprint-sensors-is-it-possible-to-disable-it-by/td-p/3729524

Seems strange there isn't much discussion around this, given the uniqueness and sensitivity of biometrical data and the blatant disregard companies pay to its protection (industry standard is to view user data as an asset not a liability - and regulator bodies aren't doing much about that either).

[edit]: Added final sentence","title":"Ask HN: Physically block mobile phone fingerprint scanner?","updated_at":"2024-09-20T01:50:07Z"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"angrydev"},"story_text":{"matchLevel":"none","matchedWords":[],"value":""},"title":{"matchLevel":"none","matchedWords":[],"value":"Skype ads in rotation have been compromised"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"http://community.skype.com/t5/Security-Privacy-Trust-and/Skype-ads-in-rotation-have-been-compromised-and-contain-Malware/td-p/2894251"}},"_tags":["story","author_angrydev","story_7162525"],"author":"angrydev","children":[7164249],"created_at":"2014-02-01T18:04:48Z","created_at_i":1391277888,"num_comments":1,"objectID":"7162525","points":5,"story_id":7162525,"story_text":"","title":"Skype ads in rotation have been compromised","updated_at":"2024-09-19T20:26:02Z","url":"http://community.skype.com/t5/Security-Privacy-Trust-and/Skype-ads-in-rotation-have-been-compromised-and-contain-Malware/td-p/2894251"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"why-el"},"story_text":{"matchLevel":"none","matchedWords":[],"value":""},"title":{"matchLevel":"none","matchedWords":[],"value":"Skype is still not doing two factor authentication"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"http://community.skype.com/t5/Security-Privacy-Trust-and/2-Factor-Authentication-When-is-it-coming/td-p/3425493"}},"_tags":["story","author_why-el","story_8581003"],"author":"why-el","children":[8581071],"created_at":"2014-11-09T21:41:05Z","created_at_i":1415569265,"num_comments":0,"objectID":"8581003","points":2,"story_id":8581003,"story_text":"","title":"Skype is still not doing two factor authentication","updated_at":"2023-09-06T22:47:35Z","url":"http://community.skype.com/t5/Security-Privacy-Trust-and/2-Factor-Authentication-When-is-it-coming/td-p/3425493"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"helmut_hed"},"story_text":{"matchLevel":"none","matchedWords":[],"value":""},"title":{"matchLevel":"none","matchedWords":[],"value":"Norton Antivirus now deletes Visual Studio output as it runs"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"http://community.norton.com/t5/Norton-Internet-Security-Norton/Suspicious-Cloud-7-F-Visual-Studio/td-p/595032"}},"_tags":["story","author_helmut_hed","story_3344686"],"author":"helmut_hed","created_at":"2011-12-12T19:54:24Z","created_at_i":1323719664,"num_comments":0,"objectID":"3344686","points":2,"story_id":3344686,"story_text":"","title":"Norton Antivirus now deletes Visual Studio output as it runs","updated_at":"2024-09-19T18:13:16Z","url":"http://community.norton.com/t5/Norton-Internet-Security-Norton/Suspicious-Cloud-7-F-Visual-Studio/td-p/595032"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"aphextim"},"title":{"matchLevel":"none","matchedWords":[],"value":"Meraki marks Windows store/updates with a false positive"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"https://community.meraki.com/t5/Security-SD-WAN/W32-779C90C974-100-SBX-TG-ArchiveFile-Disposition-Changed/td-p/56215"}},"_tags":["story","author_aphextim","story_20592321"],"author":"aphextim","children":[20592324],"created_at":"2019-08-02T11:59:40Z","created_at_i":1564747180,"num_comments":1,"objectID":"20592321","points":1,"story_id":20592321,"title":"Meraki marks Windows store/updates with a false positive","updated_at":"2024-09-20T04:42:18Z","url":"https://community.meraki.com/t5/Security-SD-WAN/W32-779C90C974-100-SBX-TG-ArchiveFile-Disposition-Changed/td-p/56215"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"Rebellos"},"title":{"matchLevel":"none","matchedWords":[],"value":"Thread full of complaints about hijacking Skype accounts that's still going on"},"url":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["td","securities"],"value":"http://community.skype.com/t5/Security-Privacy-Trust-and/Spoofed-message-from-contact/td-p/4026578"}},"_tags":["story","author_Rebellos","story_11125416"],"author":"Rebellos","created_at":"2016-02-18T13:04:59Z","created_at_i":1455800699,"num_comments":0,"objectID":"11125416","points":1,"story_id":11125416,"title":"Thread full of complaints about hijacking Skype accounts that's still going on","updated_at":"2024-09-19T22:49:58Z","url":"http://community.skype.com/t5/Security-Privacy-Trust-and/Spoofed-message-from-contact/td-p/4026578"}],"hitsPerPage":50,"nbHits":18,"nbPages":1,"page":0,"params":"query=TD+Securities&tags=story&hitsPerPage=50&advancedSyntax=true&analyticsTags=backend","processingTimeMS":8,"processingTimingsMS":{"_request":{"roundTrip":15},"afterFetch":{"format":{"highlighting":1,"total":1}},"fetch":{"query":6,"total":7},"total":8},"query":"TD Securities","serverTimeMS":10}