A teenage Australian "white hat" hacker discovered a bug in PayPal's authentication system in June and has informed the public about it, because PayPal has yet to patch it.
But Joshua Rogers – who was arrested by armed police earlier this year after alerting the Victorian Transportation Department to a database leak of 600,000 of its users – has divided the security industry by making his findings public, with one expert accusing him of “harming PayPal users, unnecessarily exposing them to new risks and all of which is detrimental to the security industry by perpetuating the hacker stereotype.”.
Rogers, who is 17, said in a blog post on August 5 that PayPal's two-factor authentication (2FA) can be bypassed. The flaw stems from the way PayPal (owned by eBay) allows users to link their eBay and PayPal accounts so that when they sell something on the auction site, the fees automatically come from their account.

