koehntopp,

OK, so...

only lets me create a on the desktop, not on mobile

only lets me add a new passkey on mobile, not on desktop.

Even after logging in with passkey, PayPal requests a TOTP token additionally.

When i try to send a paymen, PayPal needs to "confirm my identity". ("WhatsApp" - WTF???)

I have rarely seen a bigger mess and security theatre. PayPal, do better. You should be one of the leaders of secure enduser friendly authentication.

jrt,
@jrt@chaos.social avatar

@koehntopp they also only allow one fido2 credential. So adding a second key or a second device without cloud sync is impossible and you need a second MFA method.

ljrk,
@ljrk@todon.eu avatar

@koehntopp Interesting, I could only add Passkeys on the BW browser extension, I'm still stuck with Android release from 9th Oct on mobile :/

PayPall sucks badly though, either way.

koehntopp,

@ljrk
Thanks, of course I wrote that the wrong way around ;)

ljrk,
@ljrk@todon.eu avatar

@koehntopp Ah, and I already got my hopes up that mobile soon gets an update :'-)

bodomenke,
@bodomenke@hessen.social avatar

@koehntopp Ok. Ich warte dann mit Passkeys nochmal ein halbes Jahr. 😉

eingfoan,

@bodomenke @koehntopp wir sind noch ganz am Anfang

Hab heute versucht bei MS welche zu hinterlegen. Fehlanzeige. Naja ist ja eher eine kleine Firma ohne viele Ressourcen.

koehntopp,

And of course this happens on the desktop machine, where I have done hundreds of PayPal transactions already.

And I have already "confirmed my identity" and "remembered this device" multiple times (spoiler: PayPal doesn't remember the device)

Oh, and of course I can "confirm my identity" on the mobile app with a single click, only to then NOT BE LOGGED IN in said app.

koehntopp,

<theSigh>

  • All
  • Subscribed
  • Moderated
  • Favorites
  • passkeys
  • ngwrru68w68
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • Youngstown
  • everett
  • slotface
  • rosin
  • osvaldo12
  • mdbf
  • kavyap
  • cubers
  • megavids
  • modclub
  • normalnudes
  • tester
  • khanakhh
  • Durango
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • anitta
  • cisconetworking
  • JUstTest
  • lostlight
  • All magazines