Paypal app (Android) and security key login problems.

ironfist
New Community Member

Hi,

 

I installed the Paypal Android app and then tried to login with my credentials. However the loging was denied and I the error message instructed to append the security code from the keyfob to the password. I did that and still cannot login. To illustrate this is what I did:

 

Userid: abcdef

Password: password123456

 

where 123456 has been generated on the security keyfob at the time of entering the password.

 

Am I doing something wrong or is this a known issue. Just for info, I use a very complex password with special characters. I am using Nexus One with Gingerbread. Btw, the same problem has been there before Gingerbread was rolled out on Android handsets.

 

This is very frustrating so any useful help and pointer would be appreciated.

 

Cheers.

Login to Me Too
21 REPLIES 21

Aerion
Contributor
Contributor

I spoke to PayPal about this more than four years ago but clearly they have no interest in solving this issue, even though they provide their own two factor solutions.

 

While I can log into the mobile site with my phone number + PIN code, this is even less secure than a user name + password, for a password can at least a) contain more than 8 characters, and b) contain a combination of letters, numbers and punctuation marks.

 

The reason I have enabled two factor authentication on my PayPal account is that if someone manages to break into my account, they have direct access to my money, my bank account(s) and my credit card(s). Mobile devices are inherently insecure, and should therefore have full support for two factor authentication.

 

With a USB OTG adapter I can use my VIP Yubikey on my mobile phone, and I have successfully logged into other services where I use a combination of user name + password + Yubikey, yet on the PayPal mobile site as well as the Android app, this simply does not work and hasn't done since at least 2010. When I enter just my email address and password, I get an error message that says that the digits from the security key should be appended to the password, but when I do this, I simply get returned to the login screen.

 

Why does PayPal provide support for two factor authentication, yet it doesn't work on the most vulnerable of devices, and more importantly, why do they refuse to fix it?

 

Their support is utterly useless too 😞

 

Epic, epic fail on PayPal's part.

Login to Me Too

mmark27
New Community Member

Just installed two factor auth and now I can't get into my Android app.  This is useless.  WTF Paypal?  I'm taking my biz over to Google Wallet. 

Login to Me Too

ClaytonE
Contributor
Contributor

I just realized that I've signed onto the UK Community instead of the US so the work-around I'm hoping to use here in the US may not work in the UK. 

 

I'm wondering if any of you are using your mobile browser for transactions since the mobile app isn't working with two-factor authentication enabled? I find that I can log in but haven't tried to transfer funds yet from the mobile browser.

Login to Me Too

gr4ce
Contributor
Contributor

So the mobile+PIN login fixed itself for a while (a few months), but after the last two updates, I'm getting the message that it's not supported on this version of PayPal app. 

I cannot log in with email because I have two step verification and it obvioulsy doesn't send me the code thorugh SMS (I haven't got a key fob).

It's so unreliable it's unbelievable.

PayPal, sort it out please!

Login to Me Too

clankfu
New Community Member

Have they mentioned any kind of ETA for implementing a fix for this?  The mobile app is pretty much useless if you have a security key enabled.

Login to Me Too

Aerion
Contributor
Contributor

Don't hold your breath. I contacted PayPal way back in 2010 about this, and the app still gleefully promises that support for security keys will be added soon.

 

Support for the Yubikey Neo would be brillant, but I'd even settle for support for the standard Yubikey via a USB OTG adapter. Anything, as long as I can make payments while out and about!

 

As you say, if you have a security key enabled on your account (and if you don't, you deserve to get your account hacked), the app is utterly useless, especially considering that even logging with mobile number + PIN (very bad, as it is no more secure than an email address + password combination) does not work if you're desperate enough to make a mobile payment.

 

Just the other day I had to pay for two auctions that were ending as I was on my way to work. Had PayPal pulled the proverbial finger out, I would have been able to make the payment while on the train, but instead I had to contact the sellers to let them know that I was unable to make the payment until I got home the next day (I work nights). I needed the items urgently but as a result of not being able to pay instantly from the app, I incurred a day's delay. Completely ridiculous and unacceptable in this day and age, where pretty much the only thing your mobile phone doesn't do is make you breakfast in the morning.

 

PayPal, happy to take your money, but not willing to listen to you…

Login to Me Too

jamess1989
Contributor
Contributor
Having trouble paying for anything using my phone or on a tablet using the phone number and code login, have double checked my code and the phone number setup up but keeps saying incorrect details, I hae used this form of payment previously, am I missing something or is there a genuine problem at the moment.
Login to Me Too

Hudsville
New Community Member

Just spoke with Paypal tech support and this is still an issue.  Apparently it's a third party that created and manages the app and Paypal "can't get them to do move forward with this" .

Knowing roughly what an app costs to write, I find it hard to beleive the Paypal cannot employ authors to create their own.

Very p!ssed off.

Login to Me Too

Aerion
Contributor
Contributor

So we're now five years on from when I first contacted PayPal about this issue, and it still hasn't been solved.

 

Blaming a third part developer is just a feeble excuse. Surely if you can't get your contracted third party to deliver the product you want with the features you need, you give the contract to a developer who can? Lastpass and Yubico can make this work beautifully with the Yubikey Neo, and these companies are inifinitely smaller than a giant like PayPal.

 

I guess it's the same third part who is responsible for the new website design, as this does not work properly either. I just paid for something via PayPal and wanted it shipped to a different address. The shipping address selector showed me a ton of addresses I've used in the past, most of them no longer valid, but there is no way to delete, edit or even just view stored shipping addresses from one's profile.

 

PayPal have joined the likes of Apple, Microsoft, Google etc where they no longer need to achieve maximum customer satisfaction in order to survive.

 

Maybe when some other new startup comes along and challenges PayPal's dominance they will start listening to the very people that justify their existence: the customer.

 

I'll check on this thread again in another year's time to see if there is a positive post announcing full support for the Yubikey Neo with FIDO U2F (get rid of VIP already!), allowing the security conscious amongst us to pay safely, quickly and conveniently from our mobile devices. In the meantime I'll start looking for said startup or other electronic payment companies that (still) care about their customers' opinions and needs.

Login to Me Too

Aerion
Contributor
Contributor

Well, almost a year on from my last post and I'm checking io see if there has been any announcement from PayPal to say that the issue has now been addressed.

 

Surprise, surprise, it has hasn't. Nor has support for the U2F standard been added.

 

Makes one wonder whether anyone from PayPal even reads these forums, or whether they care at all. Maybe they make enough money without having to improve things, which would explain the broken apps, websites and eBay integration (why can I only use SMS as a second factor, even though I get do asked for my security token when I log into the PayPal website proper?). Now I'm trying to make a payment on eBay and have been waiting over 10 minutes for that accursed SMS to arrive.

 

It's a shame, and a scandal, that there is no alternative to PayPal, at least not one that eBay does condone, as maybe some competition would force PayPal to get their act together and fix all these broken bits.

Login to Me Too

Haven't Found your Answer?

It happens. Hit the "Login to Ask the community" button to create a question for the PayPal community.