macnn

04/18/2008, 11:25am, EDT

Friday, April 18th

Safari users to be blocked from PayPal?

Users of Apple's Safari web browser may be blocked from making PayPal transactions in the future, according to a white paper from the latter company. While the company has already taken Safari to task for lacking specific anti-phishing protection, or EV SSL (Extended Validation Secure Sockets Layer) certificates, PayPal's CIS officer now argues that the threat of phishing may be too great to allow users to send money through "unsafe" web browsers. "In our view," writes Michael Barrett, "letting users view the PayPal site on one of these browsers is equal to a car manufacturer allowing drivers to buy one of their vehicles without seat belts."

"At PayPal, we are in the process of reimplementing controls which will first warn our customers when logging in to PayPal of those browsers that we consider unsafe," Barrett continues. "Later, we plan on blocking customers from accessing the site from the most unsafe -- usually the oldest -- browsers."

The focus of this effort is said to be on older versions of Internet Explorer no longer supported by Microsoft, but does not exclude other types of unsecured software. At present neither Firefox nor Opera support EV SSL, but the companies behind both have already announced development plans in that regard. To date, Apple has not revealed any intention to add the technology to Safari.


Filed under: security
Other story tags: Safari, Paypal

, , 38comments, del.icio.us, slashdot, digg, buzz


38 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
What?
0
04/18, 11:33am, EDT
"letting users view the PayPal site on one of these browsers is equal to a car manufacturer allowing drivers to buy one of their vehicles without seat belts.""

How?

This is an absurd comment that's not even worth discussing.
Fresh-Faced Recruit
Joined Sep 2000
User is offline
EV a scam
0
04/18, 11:39am, EDT
There's no reason for not having anti-phishing features in Safari; Apple could easily add that.

However, to claim that EV Certificates provide any more security than regular certificates is ludicrous. EV Certificates are nothing more than a cheap ploy to extort more money out of certificate buyers and ends up from preventing non-profit organizations from being able to afford them.

I really wish Steve Jobs or someone would make a public stand against these certificates and expose them for the rip-off they are.

Professional Poster
Joined Sep 1999
User is offline
Good enough for my bank
0
04/18, 11:58am, EDT
Forget PayPal, if Safari is good enough for all my banking and online shopping using my credit card, then who cares about PayPal. If they block Safari they will be losing customers and businesses (me included).
bye-bye
0
04/18, 12:01pm, EDT
I've already stopped selling on eBay due to the fee hike, this will help put the nail in the coffin for me to stop using Paypal also.
Senior User
Joined Aug 2007
User is offline
Google pay
0
04/18, 12:03pm, EDT
Well, if they want me to close my accounts and move to Google Pay, no problem: I'll just do it.

This barrage from Barrett is not only ignorant, but offensive: I'm a big boy, and I don't need a PayPal Mommy to hold my hand. I'm suspicious of an ulterior motive, or some kind of collusion here.

I also agree: if Safari is OK by Bank of America, where does PayPal get off dictating to me?

PP is skating on thin ice here.
Fresh-Faced Recruit
Joined Feb 2005
User is offline
Best thing they've done
0
04/18, 12:09pm, EDT
This is the best thing for Mac security that PayPal have ever done !

How so ? By effectively preventing Mac users from using their website. PayPal is rife with fraud, and they do little to protect their 'customers'. I speak as someone who's been stung by PayPal's paper-thin fraud protection in the past.

Staying clear of PayPal is the best thing you can possibly do....
Mac Elite
Joined Dec 2000
User is offline
Pay Pal
0
04/18, 12:11pm, EDT
Good, I got scammed out of $3000 from that site. Got my money back but what a mess. I will never use Pay Pal again, they get hacked into all the time, either that or someone that works there is a crook.
Did anyone think a bit?
0
04/18, 12:24pm, EDT
Let's see how is Paypal's decision to exclude Safari from access going to help users with phishing.

Scenario: I receive a phishing e-mail to 'confirm my log in information'. I click on the link, Safari opens, I ignorantly enter my PayPal info. Later, I go to real PayPal, it tells me I can't use Safari. Fair enough; I fire up Firefox. I log on and I'm in shock; phisher got my user ID and raided my account.

Is PayPal actually attempting to force Safari users to drop Safari altogether??? Surely they know Safari is on the rise and their little effort will have no consequence on that growth. So how again are they helping their customers against phishing by forcing them to use another browser when going to the LEGITIMATE PayPal site?

This decision is just patently absurd!
Fresh-Faced Recruit
Joined May 2005
User is offline
in your dreams
0
04/18, 12:26pm, EDT
"Maybe sometime in the future Safari users will be blocked from PayPal because Apple haven't voiced EV SSL support in future versions"... Is that all?

Not. Going. To. Happen.
Fresh-Faced Recruit
Joined Jan 2006
User is offline
Unfair
0
04/18, 12:28pm, EDT
I am a business owner who uses paypal for my transactions and people buy my software, nearly all of it Mac based. So 99% of my customers will be banned from purchasing, or greatly impeded. Thus my business now suffers. Paypal must allow all browsers to enter. Anti-phishing is Apple's and the user's problem.
Fresh-Faced Recruit
Joined Jul 2002
User is offline
additional comments:..1..2..3..4..Next
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

NewsGator Enterprise RSS: Improve Corporate Communication via Web 2.0, RSS, and Social Computing.

Get an IT Degree Online: Get solid credentials. Take your hobby to the next level. Adult Programs. Affordable.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.