Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And that part was never really answered either. How can he pose as an employee calling in from an outside line? Does PayPal not tell you when an extension from PayPal is calling you?


Who cares what number the call was coming from. Security 101 for these phone techs should say something like "don't give out any information over the phone, even if the CEO calls and threatens to fire you if you don't." Or better yet, have much stricter protocols that deny the phone tech access to the information, so even if the caller threatens the tech personally, the information is safe.


he was probably posing as an employee of the account holder, not paypal


Ohh, good point. I never thought of that. I assumed employee of Twitter as well.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: