Skip to main content

An Open Letter to the PayPal folks responsible for API security and that kind of thing

Warning: This is a technically oriented rant. It has nothing to do with the money side of PayPal. It is simply about things that shouldn't happen the way they currently do.

Dear Geeks That Work for PayPal:

I don't know if you people are lazy, or stupid, or simply use cost benefit analysis before you fix the stupidest dumbest fucking things that plague your platform. Somebody came up with an amazing idea: let's add two-factor authentication, and the sonofabitch works just right. I have used your two-factor mechanism with SMS on no less than two carriers, and the VIP token application in iPhone, Blackberry and Android and they all do the job perfectly.

The problem is that you have external apps that rely on authenticating with PayPal, and these apps can't handle the two-factor authentication.

The first this happened it was with the older version of Blackberry App Word. I assumed that this was the BBAW programmers not implementing the mechanism correctly. It is so fucking stupid that you are expected to open the login window from BBAW, type your password, then switch to the VIP app to get a token, then switch back, append that to the end of the password, and manage to send the login request before the token expires (tokens last 30 seconds).

Good luck with that. Eventually some kind soul at RIM decided to allow other payment methods, which meant I was able to purchase my first BBAW app many months after I had owned a Blackberry device. Dumbasses.

That was a long time ago. But tonight it happened to me again, the same exact fucking thing, and this time it happened with an app PROVIDED BY PAYPAL. How the fuck am I expected to believe that PayPal can't have proper two-factor authentication on their own Android app without resorting to appending the fucking token to the end of the fucking password? Are we expected to believe that the people that built this Android app were not given access to the people that write and maintain the API that handles these requests? What the fuck happened here?

Worse, can't the fucking PayPal app for Android detect that VIP is installed and read the fucking token from it? How hard can this be? I imagine there's no reason that this can't work in iPhone and Blackberry devices too.

I have been using an Android phone for a little over 24 hours, and I already noticed that apps can easily trigger dependency downloads if not present. When I installed Barcode Scanner it told me I needed Google Shopper. One click and  I was presented with the install page for Google Shopper. Two clicks and I was done. I didn't even need to restart the application, it KNEW that the dependency had been met. If something as mundane as a barcode scanner can figure out this kind of thing, how come a huge company like PayPal can't do something similar?

Hell, PayPal allows automated messaging. If your phone is registered it will take commands. Can't this app trigger an SMS request to send a token if the phone is authorized?


Comments

Popular posts from this blog

On sleep deprivation and Incan Monkey Gods

From: Dilbert comic strip for 08/03/1992 from the official Dilbert comic strips archive. I was trying to show this strip to a coworker who is dangerously toying with the harsh mistress that is Insomnia. What shocked me is how quickly I was able to look up the strip, which was published when he was just 11 years old, and two weeks before my just-out-of-college ass shipped out to US Army Basic Training.

The Black Hole

If this was a minigolf hole, you can't reach B from A. Ever. If this was a room lined with mirrors, and you lit a candle at point A, you can't see it from B, not even reflected.  Update: I guess I didn't explain this all the way through. You can't reach B from A with just one stroke, there's no direct line between them, and there is no way to bounce the ball (assuming perfect conditions). Thanks to Ben for pointing this obvious error. 

Add custom speed settings to your ifit map workout

Ifit.com allows you to build a workout walk/race/bike route simply by clicking on a Google Maps interface. You can then use a compatible ifit-enabled workout machine to recreate the route automatically. The problem is that the user interface still isn't final, so there are features in place that aren't exactly obvious. For example, if you create a workout your machine starts at 1 MPH, because that's the default. But how to set it to start at say, 3 MPH? Easy, just switch from map view to graph view: That button switches from the Google Maps interface to a chart that allows you to visualize and control effort: You can't change the elevation, this is fixed due to the geography that you selected. But you can drag the yellow (speed line) to change the speed of your device.  What if you want to have segments at different speeds? Easy, just click and drag and it will break the line, and you can drag each segment of the line independently: ...