Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Paypal only supports SMS 2FA for me, I've checked last week again. Might be different depending on nationality.

SMS 2FA is not acceptable and not secure.

I also don't recall Amazon (Atleast shopping side) having 2FA either but it's been a month since I checked.



FYI, Amazon (retail) does support TOTP. Here is a direct link to the 2FA settings so you don't have to crawl through the account settings page looking for it: https://www.amazon.com/a/settings/approval.


That seems to only work for the US page but the german login seems immune to this setting.


Nope. The German login works fine with thus — I've been using it on Amazon.de for years.


Paypal supports TOTP everywhere, but it’s hidden on a page not reachable via any of their sites, in their old site, and you need to run a custom python script to even generate the token you want.


Wow, that is horrible. Given that, I would argue that, for all intents and purposes, they do not support TOTP then. An average user has zero chance of doing all of that correctly. Bummer the don't support it as a first class citizen in their security UX on their main site.

Care to share a direct link to the TOTP configuration site though?


This repository contains the software required to generate the TOTP URL from the info PayPal provides to you, as well as the site you need to get to: https://github.com/claudiodekker/symantec-vip-otp-generator

And a blogpost explaining the backstory: https://www.cyrozap.com/2014/09/29/reversing-the-symantec-vi...


For all I care, that means not supported.


Well, we’re on Hacker News here, aren’t we? In that way, it is "supported", for the people that are frequenting this site.

But sure, for the average user, it’s basically useless.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: