Major security flaw - the system keeps re-enabling auto login even after I keep turning it off

j_a_s
Contributor
Contributor

I've been dealing with customer support all day over this issue and they say they can do nothing but I want to raise it here as well since it's a major security flaw. Paypal is a financial site and therefore security controls should be very strong. I always log out whenever I complete a transaction and I never click the "stay logged in" button that's always presented. Now, every time I log in, I get an email saying "We've made it easier for you to check out with PayPal. Since we recognize this device, we'll automatically log you in so you can skip typing your password at checkout! ... If this is a shared device, or you don't want us to automatically log you in, we recommend that you turn this feature off." I go in and manually turn the feature off. Then the next time I log in to make a transaction, I get the same email again, the feature is re-enabled again, and I have to go in to manually turn it off again. This is totally unacceptable. I'm the only one who should be able to determine if my device is trusted and and if I want to enable auto login. I was told that there's nothing they can do and that I'll simply have to manually disable the feature every time. This is a major security flaw and it's a big deal. I was told that my concern has been escalated but I'm posting this here in the hopes of raising the visibility of this issue. Thanks. 

Login to Me Too
116 REPLIES 116

mlmtf6
Contributor
Contributor

I got an email about this earlier today.  I called to complain and then got it again this evening.  This is REALLY bad!

Login to Me Too

betterthanyou
Member
Member

I'm having the same issue. I never want to stay logged in on ANY device, especially as I utilize two separate accounts (my personal account and a shared business account). Now, every single time II make a payment with the personal account, I receive the same IMBECILIC email letting me know they have AGAIN enabled Auto Login:

 

"We've made it easier for you to check out with PayPal

Since we recognize this device, we'll automatically log you in so you can skip typing your password at checkout."

 

There is no way to stop PayPal from doing this, and the beyond useless customer service department is of zero help as always.

Login to Me Too

ScottInNY
New Community Member

I was having the same problem for the past week or two.  I solved it today by going into my browser settings and deleting all cookies from domains whose names contain "paypal".

Login to Me Too

shine75
Contributor
Contributor
Um … that won’t solve it . I delete my browser n cookies automatically religiously. Doesn’t work
Login to Me Too

SomeUser567
Contributor
Contributor

I've had this happen to me several times since I started using Ebay & PayPal as my first choice for shopping about a year and half ago.  PayPal keeps defaulting an option to turn it on when you check out.  The option has been displayed a few different ways so you really have to be diligent to protect yourself.  A few times I apparently didn't catch it or it wasn't there and it got turned back on.

 

I absolutely, positively, unequivocally would never, ever, ever want this on under any circumstance!  As a matter of principle and basic security, I want my decision to pay with PayPal to require an explicit login every time I check out.  This is as much of a common sense practice as not allowing your web browser to save passwords.  I'm appalled that PayPal is tricking people into turning off their security.

Login to Me Too

Temp20221223K
Contributor
Contributor

Same here.  I've been going round and round and round and round with the insipid PayPal customer service dept. messaging system for the past month.  They keep suggesting I turn it off myself, but that's not the issue - I DON'T EVER WANT IT ON and there should be a lock or other preference to prevent PayPal from turning it back on.  This is beyond ridiculous...

Login to Me Too

Lol, that's what I told them today- it's beyond ridiculous! And I was told the emails are incorrect and it isnt actually opting you in to auto login. Yet, i go to settings and sure enough Im opted back in. I'm just going to cancel my account.
Login to Me Too

hailhailhail
New Community Member

Same problem happening with my business account. Looking into switching entirely away from PayPal after 12 years. The lack of response on this from their customer service department is unacceptable.

Login to Me Too

Koo1
New Community Member

I share all the same sentiments of comments above. This is a security breach and poor form for PayPal not to respond to these messages.

Login to Me Too

cnayr
Contributor
Contributor

Agreed - this seriously undermines my trust in PayPal. What could they possibly be thinking? 

 

Actually, they had a similarly ridiculous default for "Bill Me Later" some years ago where they changed the default payment method without user permission, made it hard to change back, and then had it programmed to keep reverting back to their preference (Bill Me Later) instead of the user's preference (credit card, in my case). I almost closed my account at that time, but instead decided to just use it less, and to never again use "Bill Me Later" (now "PayPal Credit"). I'm sorry to smell the same scent of deceitfulness and self-serving greed behind this move as well. 

 

Anyway, as a work-around until they take their fingers our of their ears and get around to making changes, I believe setting up two-factor authorization (2FA) for your account will help. At least then it's harder for someone else to place orders and it will give you a moment to pause and rethink that impulse purchase. Come to think of it, maybe it's the latter they are trying to manipulate here (under the guise of "customer convenience" and/or "economic stimulus", of course).  

Login to Me Too

Haven't Found your Answer?

It happens. Hit the "Login to Ask the community" button to create a question for the PayPal community.