Enable 2FA on an account

a1-_
New Community Member

Hi,

How does one enable any form of 2FA? preferably using Authenticator??

Seems like there's no option... The "Security key" option on the security settings page just reloads the page.

https://www.paypal.com/cgi-bin/webscr?cmd=_security-token

 

Regards.

Login to Me Too
1 ACCEPTED SOLUTION

Accepted Solutions
Solved

PayPal_Siobhan2
Moderator
Moderator

Hi a1-_

2FA and the Security Key options are country specific and may not be available in your region. If the Security Key is available, it would be located in the “Security” section of your PayPal account. There is a heading for Security Key and an “Edit” button on the right hand side. When you click on edit it will ask you to register your mobile device.

PayPal are always expanding their services. If the Security Key is currently unavailable in your country, this may not be for long. Any new products or services offered by PayPal will be notified on the PayPal website.

Thanks,

Siobhan

View solution in original post

Login to Me Too
22 REPLIES 22
Solved

PayPal_Siobhan2
Moderator
Moderator

Hi a1-_

2FA and the Security Key options are country specific and may not be available in your region. If the Security Key is available, it would be located in the “Security” section of your PayPal account. There is a heading for Security Key and an “Edit” button on the right hand side. When you click on edit it will ask you to register your mobile device.

PayPal are always expanding their services. If the Security Key is currently unavailable in your country, this may not be for long. Any new products or services offered by PayPal will be notified on the PayPal website.

Thanks,

Siobhan

Login to Me Too

Tolzak
Contributor
Contributor

This is not an adequate response.  As a security professional, I think it is a big miss that PayPal does not offer the use of an authenticator app or something like Yubikey.  SMS authentication is not safe authentication.  Anyone with moderate knowledge of tech can intercept the codes.  If someone performs a SIM card swap, a popular attack today, your second factor is useless.  For all practical purposes, you have what looks like strong authentication to those who don't know better, but it falls far short.

Login to Me Too

Cas7
Contributor
Contributor
Paypal, please listen to your customers. 2fa through sms is NOT safe! Who is gonna pay the bill when they rob your money from your bank account and credit card?
Login to Me Too

geokona
New Community Member

I'm NOT impressed with PayPals lack of 2FA. They say you can use your cell phone to have an SMS pin sent for each time you log in. We all are well aware that that is not secure. How many times have you heard of people having their cell phones cloned or taken over by a hacker who takes over their cell phone service. That's pretty easily done now a days with the lack of Verizon and AT&T security. 

 

I have a personal and small business account. PayPals SMS "security feature" will only attach to one cell number. So, that leaves me completely vulnerable on one of my accounts.

 

Why won't PayPal institute a standard industry wide solution like google authenticator or Auth or some other standard. That is MUCH more secure than SMS. Come on PayPal, be a leader and not a follower who is using out of date technology.  Attn: PayPal Security Product Manager.... go take a security class and understand how vulnerable your company really is. UGH......

Login to Me Too

PayPal_david
Moderator
Moderator

Hey Geokona. 

 

Welcome to the Community!

 

We appreciate your feedback and we will ensure to get it forwarded to the relevant teams. This may be introduced in the near future and we are always trying to build on the current security systems that are integrated on our website. 

 

Rest assured, as soon as there are any new updates on this, you will see this on the PayPal website.

 

I hope this helps.

David.

Login to Me Too

RobGamez
New Community Member

I dont understand how the leading online payment service hasn't got 2 factor authentication as a top priority feature!

Its truly shocking for this to be a feature that paypal are only just now looking at!

 

Paypal - "Come do almost all your online shopping with us, but we dont provide simple 2 factor authentication to protect you or your money."

 

There was a hardware 2fa security key floating around, which didnt catch much traction, so surely the authentication model is there already?!

Login to Me Too

robtain
Contributor
Contributor

I use a One-time password generated by Google Authenticator or my password manager (1Password) for all of my accounts that support 2FA. But here in Canada, the authenticator option isn't available.

 

The SMS Security Key is *horrible*. Not only is it insecure, but for some strange reason, it can take up to 10 minutes to receive the PayPal SMS. By that time, my transaction may have timed out.

 

Paypal: Please do better.

 

 

Login to Me Too

cbj4074
Contributor
Contributor

I concur with the others who contend that it is completely unacceptable for PayPal not to support Authenticator-type app 2FA at this point in time.

 

As others have noted, PayPal's "Security Key" method, which is SMS-based, does not constitute an acceptable 2FA implementation. Again, as others have noted, SMS is not secure and numerous low-tech attacks have been employed in order to intercept SMS messages, which renders SMS a non-option for 2FA.

 

There is absolutely no excuse for a vendor of PayPal's age, size, and stature not to have implemented a proper 2FA solution that utilizes an Authenticator-type app. None. There are coffee shop apps that have 2FA, for goodness's sake!

 

Time to get with the program, PayPal! You are stewards of peoples' hard-earned money! You have direct access to their bank accounts! And to wit, you force binding arbitration on  your customers, so they have virtually no recourse if somebody manages to gain unauthorized access to their accounts and steal their money out from under your behind-the-times, unsecure noses.

 

"We might implement it someday" doesn't fly! This should be at the very top of the priorities list!  Truly unbelievable and equally disappointing.

Login to Me Too

ekrueger
Contributor
Contributor

So I see that authenticator apps are now supported for Personal accounts.

When are business accounts picking this feature up?  Seems like it would make sense to protect the merchants/businesses/charities that are using the Paypal platform.   Right now, business accounts are lacking, and while SMS is clearly insufficient, you only allow 1 phone number to be used with a single business account, so if you have multiple, then you're pretty much stuck.  Same even if you used the security token, the serial# is limited to a single account.    Any word on when authenticator apps will come to the business users?

Login to Me Too

Haven't Found your Answer?

It happens. Hit the "Login to Ask the community" button to create a question for the PayPal community.