Bank status
In the United States, PayPal is licensed as a money transmitter on a state-by-state basis. PayPal is not classified as a bank in the United States, though the company is subject to some of the rules and regulations governing the financial industry including Regulation E consumer protections and the USA PATRIOT Act. On May 15, 2007, PayPal announced that it would move its European operations from the UK to Luxembourg, commencing July 2, 2007 as PayPal (Europe) S.à r.l. & Cie, S.C.A. This would be as a Luxembourg entity regulated as a bank by the Commission de Surveillance du Secteur Financier (CSSF), the Luxembourg equivalent of the FSA. PayPal Luxembourg will then provide the PayPal service throughout the European Union (EU).
Safety and protection policies
The PayPal Buyer Protection Policy states that customers may file a buyer complaint within 45 days if they did not receive an item or if the item they purchased was significantly not as described. If the buyer used a credit card, they might get a refund via chargeback from their credit card company.
According to PayPal, it protects sellers in a limited fashion via the Seller Protection Policy. In general the Seller Protection Policy is intended to protect the seller from certain kinds of chargebacks or complaints if seller meets certain conditions including proof of delivery to the buyer. PayPal states the Seller Protection Policy is "designed to protect sellers against claims by buyers of unauthorized payments and against claims of non-receipt of any merchandise". Note that this contrasts with the consumer protection they offer. This policy should be read carefully before assuming protection. In particular the Seller Protection Policy includes a list of "Exclusions" which itself includes "Intangible goods", "Claims for receipt of goods 'not as described'" and "Total reversals over the annual limit". There are also other restrictions in terms of the sale itself, the payment method and the destination country the item is shipped to (simply having a tracking mechanism is not sufficient to guarantee the Seller Protection Policy is in effect). A class-action lawsuit was filed against PayPal, days after the company's successful initial public offering.
Security
A PayPal security key generates a six-digit temporary login code to authenticate the user.
Security key
In early 2006, PayPal introduced an optional security key as an additional precaution against fraud. A user account tied to a security key has a modified login process: the account holder enters their login ID and password, as normal, but is then prompted to press the button on the security key and enter the six-digit number generated by it. This two-factor authentication is intended to prevent an account from being compromised by a malicious third party without access to the physical security key. However, the user (or malicious third party) can alternatively authenticate by providing the credit card or bank account number listed on their account. Thus, the PayPal's implementation does not offer the security of true two-factor authentication.
The key currently costs US$5.00 for all users with no ongoing fees. The option of using a security key with one's account is currently available only to users registered in Australia, Germany, Canada, the United Kingdom and the United States.
MTAN
It is also possible to use a mobile phone to receive an MTAN (Mobile Transaction Authentication Number) via SMS, however this security scheme has known vulnerabilities.
http://en.wikipedia.org/wiki/Paypal
In the United States, PayPal is licensed as a money transmitter on a state-by-state basis. PayPal is not classified as a bank in the United States, though the company is subject to some of the rules and regulations governing the financial industry including Regulation E consumer protections and the USA PATRIOT Act. On May 15, 2007, PayPal announced that it would move its European operations from the UK to Luxembourg, commencing July 2, 2007 as PayPal (Europe) S.à r.l. & Cie, S.C.A. This would be as a Luxembourg entity regulated as a bank by the Commission de Surveillance du Secteur Financier (CSSF), the Luxembourg equivalent of the FSA. PayPal Luxembourg will then provide the PayPal service throughout the European Union (EU).
Safety and protection policies
The PayPal Buyer Protection Policy states that customers may file a buyer complaint within 45 days if they did not receive an item or if the item they purchased was significantly not as described. If the buyer used a credit card, they might get a refund via chargeback from their credit card company.
According to PayPal, it protects sellers in a limited fashion via the Seller Protection Policy. In general the Seller Protection Policy is intended to protect the seller from certain kinds of chargebacks or complaints if seller meets certain conditions including proof of delivery to the buyer. PayPal states the Seller Protection Policy is "designed to protect sellers against claims by buyers of unauthorized payments and against claims of non-receipt of any merchandise". Note that this contrasts with the consumer protection they offer. This policy should be read carefully before assuming protection. In particular the Seller Protection Policy includes a list of "Exclusions" which itself includes "Intangible goods", "Claims for receipt of goods 'not as described'" and "Total reversals over the annual limit". There are also other restrictions in terms of the sale itself, the payment method and the destination country the item is shipped to (simply having a tracking mechanism is not sufficient to guarantee the Seller Protection Policy is in effect). A class-action lawsuit was filed against PayPal, days after the company's successful initial public offering.
Security
A PayPal security key generates a six-digit temporary login code to authenticate the user.
Security key
In early 2006, PayPal introduced an optional security key as an additional precaution against fraud. A user account tied to a security key has a modified login process: the account holder enters their login ID and password, as normal, but is then prompted to press the button on the security key and enter the six-digit number generated by it. This two-factor authentication is intended to prevent an account from being compromised by a malicious third party without access to the physical security key. However, the user (or malicious third party) can alternatively authenticate by providing the credit card or bank account number listed on their account. Thus, the PayPal's implementation does not offer the security of true two-factor authentication.
The key currently costs US$5.00 for all users with no ongoing fees. The option of using a security key with one's account is currently available only to users registered in Australia, Germany, Canada, the United Kingdom and the United States.
MTAN
It is also possible to use a mobile phone to receive an MTAN (Mobile Transaction Authentication Number) via SMS, however this security scheme has known vulnerabilities.
http://en.wikipedia.org/wiki/Paypal
No comments:
Post a Comment