New checkout: eBay is phishing for PayPal password

ay656
Community Member

eBay has changed the checkout process. Now, instead of being transferred to PayPal where I could be securely authenticated, they request that I supply PayPal password to eBay - without leaving eBay site. In my opinion this is absolutely not secure and discloses (or has a potential to disclose) my password to eBay. I decided that I am not going to shop on eBay until this is fixed.

Message 1 of 7
latest reply
6 REPLIES 6

New checkout: eBay is phishing for PayPal password

 

Hello 'ay656', 

You're right, they changed that yet again.  When you go to the check-out, up in the right hand corner it invites you

to "Tell us what you think".   Did you click on it and tell them what you think?  I sure did. Smiley Happy

 

Message 2 of 7
latest reply

New checkout: eBay is phishing for PayPal password

I did leave my feedback. Perhaps other people will too.

Message 3 of 7
latest reply

New checkout: eBay is phishing for PayPal password

I just made a purchase on dotCOM, and there was a direct link to PP as usual.

 

Perhaps this is only on dotCA?

 

Are you sure the request was from eBay and not a counterfeit from elsewhere?

 

That being said, it is still possible to pay directly from the PP site.

Message 4 of 7
latest reply

New checkout: eBay is phishing for PayPal password


@ay656 wrote:

eBay has changed the checkout process. Now, instead of being transferred to PayPal where I could be securely authenticated, they request that I supply PayPal password to eBay - without leaving eBay site. In my opinion this is absolutely not secure and discloses (or has a potential to disclose) my password to eBay. ...


 

I'm pretty sure that's the way it now works when using paypal for non-related companies (which eBay has become).

 

The last few times (on non-eBay sites) that I've used paypal I did not sign into the paypal site, but did the payment via a pop-up box on the sellers website.

 

-.-

Message 5 of 7
latest reply

New checkout: eBay is phishing for PayPal password

When I am promoted to do that, I'll usually follow instructions and then double-check immediately that I'm logged into paypal from another tab in my browser. I do wish companies would warn users in advance that they are making changes to the flow. People are right to be suspicious. 

Message 6 of 7
latest reply

New checkout: eBay is phishing for PayPal password


@mjwl2006 wrote:

When I am promoted to do that, I'll usually follow instructions and then double-check immediately that I'm logged into paypal from another tab in my browser. I do wish companies would warn users in advance that they are making changes to the flow. People are right to be suspicious. 


That is the classical way how phishing works. They ask you for password. You enter it, they log you in. Everything looks cozy, but now they have your password and can drain your PayPal account at any time. If you linked to bank account or credit card - these get drained too. Even though a company such as eBay probably will not drain your PayPal account, but there are employees, hackers etc. It's only a matter of time until this happens.

 

I made a purchase on BetsBay day before yesterday, and this is not how it was done there.

 

It's the same on dorCOM today. I figured I can pay with credit card. Less convenient, but anyway.

Message 7 of 7
latest reply