frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

PayPal discloses data breach that exposed user info for 6 months

https://www.bleepingcomputer.com/news/security/paypal-discloses-data-breach-exposing-users-personal-information/
84•el_duderino•2h ago

Comments

Insanity•1h ago
So from the Article they claim:

"PayPal has since rolled back the code change responsible for this error, which potentially exposed the PII. We have not delayed this notification as a result of any law enforcement investigation."

That does little to explain the 2 month-ish delay in disclosing it. I presume they could have disclosed _at least_ that account data was leaked even if the underlying bug wasn’t yet closed?

Obviously without disclosing the nature of the bug in that case.

malfist•1h ago
It's one of those "suspiciously specific denials"

They didn't delay the release because of law enforcement investigation, it doesn't say they didn't delay the release. There's a whole host of reasons besides "law enforcement investigation" to delay an embarrassing release, including "I don't wanna"

sidewndr46•1h ago
The quote is: "We have not delayed this notification as a result of any law enforcement investigation"

The obvious example here would be if the NSA or other agency that isn't law enforcement led the investigation.

But further abuse of the English language reveals a different conclusion. This was not delayed as a result of any law enforcement investigation. It could have been delayed as a result of a specific law enforcement investigation. Furthermore, the word "result" implies that it is tied to the conclusion of said investigation(s). It could in fact have been delayed because of a pending law enforcement investigation.

cmehdy•36m ago
> The company now offers affected users two years of free three-bureau credit monitoring and identity restoration services through Equifax, which require enrollment by June 30, 2026.

How tasteful.

SilverElfin•21m ago
I think all companies just believe security doesn’t matter because the worst thing that can happen is they offer to pay for a credit monitoring. And the victims are powerless to pursue a meaningful lawsuit against them. Even when that happens, it results in a class action settlement where lawyers get a bunch of money and victims get very little.
flipped•33m ago
This is the reason you should be using Monero. The benefits are extremely fruitful for everyone. Private, untraceable, full control over your funds, no breach possible.
_verandaguy•24m ago
These are often undesirable features for SMEs that need to be accountable for a variety of reasons, including KYC regulations; besides, while blockchains provide protocol-level security, they fail in two ways that do matter to consumers:

- They provide no meaningful consumer protections (since this necessarily requires an authority, which blockchains may not have)

- They don't protect at all against meatspace vulnerabilities like scams and other deception-based attacks, which are by far the more common issue in banking. This is exacerbated by the lack of consumer protections.

(To be clear: don't read my comment as being in support of PayPal. They have abused user trust for a while, and I haven't had an account there in over a year -- fuck 'em.)

pennomi•23m ago
What percentage of businesses actually accept monero?
draygonia•20m ago
Aside from it being an unstable store of value, but that's a problem with all cryptos (and stablecoins, when they collapse).
josefritzishere•28m ago
There should be legal penalties for failing to inform users in a timely fashion. A 6 month delay is ridiculous. They put all their users at risk.
anonymous908213•27m ago
Irrelevant to the current breach, but at the end of the article...

> In January 2023, PayPal notified customers of another data breach after a large-scale credential stuffing attack compromised 35,000 accounts between December 6 and December 8, 2022.

> Two years later, in January 2025, New York State announced a $2,000,000 settlement with PayPal over charges that it failed to comply with the state's cybersecurity regulations, leading to the 2022 data breach.

I didn't hear about this New York case. I'm the first to lament the incredibly sorry state of affairs of data security, to the extent that such security exists at all, but it is insane that you can get fined $2,000,000 for your customers re-using e-mail + password combinations between sites and becoming compromised as a result. I truly loathe mandatory 2FA with every fiber of my being and I guess New York would like to enforce it on the world? Sigh. Everything about the internet just gets worse and worse, continuously.

TitaRusell•17m ago
Hopefully WERO will finally wipe out PayPal in Europe. Despite the ridiculous name.
jimnotgym•17m ago
Great, who from PayPal is going to jail over this?

Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI

https://github.com/ggml-org/llama.cpp/discussions/19759
235•lairv•2h ago•43 comments

I found a useful Git one liner buried in leaked CIA developer docs

https://spencer.wtf/2026/02/20/cleaning-up-merged-git-branches-a-one-liner-from-the-cias-leaked-d...
173•spencerldixon•1h ago•96 comments

Child's Play: Tech's new generation and the end of thinking

https://harpers.org/archive/2026/03/childs-play-sam-kriss-ai-startup-roy-lee/
35•ramimac•1h ago•20 comments

Show HN: A native macOS client for Hacker News, built with SwiftUI

https://github.com/IronsideXXVI/Hacker-News
72•IronsideXXVI•1h ago•39 comments

Trump's global tariffs struck down by US Supreme Court

https://www.bbc.com/news/live/c0l9r67drg7t
175•blackguardx•30m ago•98 comments

The path to ubiquitous AI (17k tokens/sec)

https://taalas.com/the-path-to-ubiquitous-ai/
419•sidnarsipur•5h ago•275 comments

Untapped Way to Learn a Codebase: Build a Visualizer

https://jimmyhmiller.com/learn-codebase-visualizer
111•andreabergia•7h ago•19 comments

PayPal discloses data breach that exposed user info for 6 months

https://www.bleepingcomputer.com/news/security/paypal-discloses-data-breach-exposing-users-person...
89•el_duderino•2h ago•14 comments

Gemini 3.1 Pro

https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-pro/
876•MallocVoidstar•1d ago•861 comments

Mothers (YC X26) Is Hiring

https://jobs.ashbyhq.com/9-mothers?utm_source=x8pZ4B3P3Q
1•ukd1•2h ago

Web Components: The Framework-Free Renaissance

https://www.caimito.net/en/blog/2026/02/17/web-components-the-framework-free-renaissance.html
111•mpweiher•7h ago•69 comments

Minions – Stripe's Coding Agents Part 2

https://stripe.dev/blog/minions-stripes-one-shot-end-to-end-coding-agents-part-2
81•ludovicianul•4h ago•38 comments

The Rediscovery of 103 Hokusai Lost Sketches (2021)

https://japan-forward.com/eternal-hokusai-the-rediscovery-of-103-hokusai-lost-sketches/
25•debo_•4d ago•2 comments

Consistency diffusion language models: Up to 14x faster, no quality loss

https://www.together.ai/blog/consistency-diffusion-language-models
167•zagwdt•11h ago•60 comments

Raspberry Pi Pico 2 at 873.5MHz with 3.05V Core Abuse

https://learn.pimoroni.com/article/overclocking-the-pico-2
82•Lwrless•7h ago•18 comments

AI is not a coworker, it's an exoskeleton

https://www.kasava.dev/blog/ai-as-exoskeleton
379•benbeingbin•20h ago•399 comments

Infrastructure decisions I endorse or regret after 4 years at a startup (2024)

https://cep.dev/posts/every-infrastructure-decision-i-endorse-or-regret-after-4-years-running-inf...
374•Meetvelde•3d ago•165 comments

Nvidia and OpenAI abandon unfinished $100B deal in favour of $30B investment

https://www.ft.com/content/dea24046-0a73-40b2-8246-5ac7b7a54323
212•zerosizedweasle•3h ago•175 comments

Reading the undocumented MEMS accelerometer on Apple Silicon MacBooks via iokit

https://github.com/olvvier/apple-silicon-accelerometer
101•todsacerdoti•10h ago•52 comments

Notes on Clarifying Man Pages

https://jvns.ca/blog/2026/02/18/man-pages/
35•surprisetalk•1d ago•20 comments

Show HN: Micasa – track your house from the terminal

https://micasa.dev
598•cpcloud•1d ago•190 comments

FreeCAD

https://www.freecad.org/index.php
293•doener•3d ago•115 comments

I tried building my startup entirely on European infrastructure

https://www.coinerella.com/made-in-eu-it-was-harder-than-i-thought/
551•willy__•6h ago•293 comments

US plans online portal to bypass content bans in Europe and elsewhere

https://www.reuters.com/world/us-plans-online-portal-bypass-content-bans-europe-elsewhere-2026-02...
398•c420•1d ago•763 comments

Silicon Valley engineers were indicted for allegedly sending secrets to Iran

https://www.cnbc.com/2026/02/20/three-engineers-charged-stealing-google-trade-secrets-data-iran-s...
73•giuliomagnifico•5h ago•39 comments

The Popper Principle

https://theamericanscholar.org/the-popper-principle/
4•lermontov•1d ago•0 comments

A beginner's guide to split keyboards

https://www.justinmklam.com/posts/2026/02/beginners-guide-split-keyboards/
194•thehaikuza•4d ago•205 comments

Defer available in gcc and clang

https://gustedt.wordpress.com/2026/02/15/defer-available-in-gcc-and-clang/
230•r4um•4d ago•197 comments

Fast KV Compaction via Attention Matching

https://arxiv.org/abs/2602.16284
54•cbracketdash•11h ago•10 comments

An ARM Homelab Server, or a Minisforum MS-R1 Review

https://sour.coffee/2026/02/20/an-arm-homelab-server-or-a-minisforum-ms-r1-review/
101•neelc•14h ago•80 comments