<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: paypals]]></title>
    <link>http://securityratty.com/tag/paypals</link>
    <description></description>
    <pubDate>Tue, 27 Nov 2007 15:07:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Personal Plug: I'm hiring]]></title>
      <link>http://securityratty.com/article/d1457e6103634dacb007af63ca4c1438</link>
      <guid>http://securityratty.com/article/d1457e6103634dacb007af63ca4c1438</guid>
      <description><![CDATA[PayPal's information security team is hiring

Specifically - I'm hiring an Application Security Researcher

Primary responsibilities will be

Lead Research on browser security models
Research new...]]></description>
      <content:encoded><![CDATA[PayPal's information security team is hiring.<br /><br />Specifically  - I'm hiring an <a href="https://jobs.brassring.com/en/asp/tg/cim_jobdetail.asp?sec=1&amp;partnerid=13746&amp;siteid=195&amp;jobId=728682&amp;type=search&amp;JobReqLang=1&amp;recordstart=1&amp;JobSiteId=195&amp;JobSiteInfo=728682_195&amp;GQId=0&amp;codes=IND">Application Security Researcher</a>.<br /><br />Primary responsibilities will be:<br /><ul><li>Lead Research on browser security models</li><li>Research new application security attacks and countermeasures</li><li>Develop prototypes of security protection mechanisms for browsers and PayPal software to implement and prove application security ideas</li><li>Conduct web application security assessment</li><li>Participate in the development, review, and update of application security standards</li><li>Work with PayPal’s SDL group to improve the security of PayPal developed applications</li><li>Research new development techniques</li><li>Research new development, languages, testing methodologies, and frameworks to improve the security of PayPal applications.<br /></li></ul>If you're interested in other security positions we also have open, please go to:  <a href="http://www.ebaycareers.com/">http://www.ebaycareers.com/</a><br /><br />You can search for jobs with the keyword "security" under PayPal.  Brassring makes posting a whole list of positions tricky.<img src="http://feeds.feedburner.com/~r/SecurityRetentive/~4/311488868" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 08:55:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/browser security models">browser security models</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/application security standards">application security standards</category>
      <category domain="http://securityratty.com/tag/security protection mechanisms">security protection mechanisms</category>
      <category domain="http://securityratty.com/tag/application security attacks">application security attacks</category>
      <category domain="http://securityratty.com/tag/information security team">information security team</category>
      <category domain="http://securityratty.com/tag/application security researcher">application security researcher</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <category domain="http://securityratty.com/tag/paypal applications">paypal applications</category>
      <source url="http://feeds.feedburner.com/~r/SecurityRetentive/~3/311488868/personal-plug-im-hiring.html">Personal Plug: I'm hiring</source>
    </item>
    <item>
      <title><![CDATA[Some Comments on PayPal's Security Vulnerability Disclosure Policy]]></title>
      <link>http://securityratty.com/article/bddee49bc02f2f7e22e5aebc4dc60a70</link>
      <guid>http://securityratty.com/article/bddee49bc02f2f7e22e5aebc4dc60a70</guid>
      <description><![CDATA[Thanks to the several places that have written about this policy in the last few days

I was personally involved in crafting the policy and while I can't make commitments or speak officially for...]]></description>
      <content:encoded><![CDATA[Thanks to the <a href="http://jeremiahgrossman.blogspot.com/2007/11/paypals-vulnerability-disclosure-policy.html">several </a><a href="http://shiflett.org/blog/2007/nov/paypal-groks-security">places </a><a href="http://www.securitycatalyst.org/forums/index.php?topic=706.0">that </a><a href="http://genesyswave.bloggerteam.com/294385/">have </a><a href="http://www.cutawaysecurity.com/blog/archives/212">written </a>about this policy in the last few days.<br /><br />I was personally involved in crafting the policy and while I can't make commitments or speak officially for PayPal I thought I'd take a few minutes to explain our thinking on a few of the items in the policy.<br /><br />First, a few points.  PayPal didn't have a great system for reporting security issues until this new policy came out.  Our goals in creating and publishing the policy were several:<br /><ul><li>Improve the security of our site by getting security issues disclosed to us responsibly.<br /></li><li>Create an easy mechanism for people to report a security vulnerability to us. We chose email since we figured security researchers would like it better than a form.<br /></li><li>Create incentives for disclosure and remove disincentives (threat of legal liability)</li><li>Make clear our expectations in these areas, since this is a new and evolving area of security vulnerability disclosure with more than a little legal uncertainty.</li><li>Through our policy - set a standard we hope others can follow. </li></ul>We carefully constructed the language in the policy with our privacy lawyers to ensure that we were not over-promising with respect to legal liability.  We looked at other disclosure policies, and we settled on the policy you can find <a href="https://www.paypal.com/cgi-bin/webscr?cmd=xpt/cps/securitycenter/general/ReportingSecurityIssues-outside">here</a>.<br /><br />A few specific notes are in order:<br /><br /><ul><li>We will revise the policy over time based on user feedback.</li><li>We are serious in our commitment to rapidly address any discovered security issues with the site. Our language around reasonable timeframe is slightly vague because we don't want to over-promise on how quickly we can resolve an issue.</li><li>We do expect to get back to researchers quickly with confirmation of a reported issue and tracking data on how we're doing resolving it.</li></ul>Let me now address a few concerns/comments people have specifically raised.<br /><br />Chris Shiflett <a href="http://shiflett.org/blog/2007/nov/paypal-groks-security">said</a>:<br /><blockquote>Since data can be anything, how do we know if we view data without authorization? Don't most people assume they're authorized to view something if they're allowed to view it? Does intent matter?<br /></blockquote>While we don't want users to test the security of the PayPal site, should they do so they should be careful to minimize the disruption caused by their testing.    If you start tinkering with URLs to see whether you can view certain data, do it between two accounts you control, don't try to view other people's data.  There is a fine line between testing responsibly and irresponsibly and we're encouraging people to stay on the more responsible side of the line.<br /><br />From Don's <a href="http://www.cutawaysecurity.com/blog/archives/212">post</a>:<br /><blockquote>I got a creepy feeling about actually trusting <a href="https://www.paypal.com/cgi-bin/webscr?cmd=xpt/cps/securitycenter/general/ReportingSecurityIssues-outside" onclick="javascript:urchinTracker ('/outbound/article/www.paypal.com');">the statement.</a> I will probably never attempt to test the security of PayPal’s site, but for those who do I would hate for the disclosure statement to change suddenly.<br /></blockquote>As I said earlier, we do believe the policy is a work in progress.  We will modify it from time to time to allay concerns, improve its effectiveness, etc.  Our goal however is to encourage responsible disclosure. I hope that intent behind the policy is enough to allay people's potential fears.<br /><br />One final note on the statement - "Allow us reasonable time to respond to the issue before disclosing it publicly."  We struggled over the wording on this more than any other element of the policy.  It is a tricky business to get the right balance between early disclosure, our commitment to protect our customers and their data, and people's desire to know about the security of a given website or service.  That said, we're committed to working with researchers when an issue is reported to us and we'll decide reasonable on a case-by-case basis.<br /><br />We're hoping that this policy strikes a good balance between our desire for responsible disclosure, and not discouraging researchers from coming forward.<br /><br />Again, I'm not a spokesperson for PayPal, so this post naturally represents my personal beliefs about this policy not a firm binding statement of company policy.  That said - I welcome your comments.<img src="http://feeds.feedburner.com/~r/SecurityRetentive/~4/191982746" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 27 Nov 2007 15:07:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/disclosure">disclosure</category>
      <category domain="http://securityratty.com/tag/encourage responsible disclosure">encourage responsible disclosure</category>
      <category domain="http://securityratty.com/tag/responsible disclosure">responsible disclosure</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security vulnerability disclosure">security vulnerability disclosure</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <category domain="http://securityratty.com/tag/security vulnerability">security vulnerability</category>
      <category domain="http://securityratty.com/tag/disclosure policies">disclosure policies</category>
      <category domain="http://securityratty.com/tag/disclosure statement">disclosure statement</category>
      <source url="http://feeds.feedburner.com/~r/SecurityRetentive/~3/191982746/some-comments-on-paypals-security.html">Some Comments on PayPal's Security Vulnerability Disclosure Policy</source>
    </item>
  </channel>
</rss>
