{"id":5221,"date":"2019-07-09T14:25:10","date_gmt":"2019-07-09T11:25:10","guid":{"rendered":"https:\/\/www.protectimus.com\/blog\/?p=5221"},"modified":"2025-08-08T22:51:35","modified_gmt":"2025-08-08T19:51:35","slug":"paypal-two-factor-authentication","status":"publish","type":"post","link":"https:\/\/www.protectimus.com\/blog\/paypal-two-factor-authentication\/","title":{"rendered":"PayPal Two-Factor Authentication with Hardware Security Key"},"content":{"rendered":"\n<p>PayPal two-factor authentication became available to users in far 2007. Everybody wishing to protect their PayPal login could <a href=\"http:\/\/voices.washingtonpost.com\/securityfix\/2007\/02\/paypal_selling_antifraud_token.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\" aria-label=\" (opens in a new tab)\">order a $5 security token<\/a> directly from their account.<\/p>\n\n\n\n<p>Unfortunately, later the company discontinued the use of its own hardware tokens in favor of SMS-based authentication, decreasing PayPal security considerably. But the situation with PayPal two-factor authentication is changing once again, for the better now:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Since 2018, you can use MFA applications to log into PayPal (Google Authenticator, Protectimus Smart, etc.)<\/li>\n\n\n\n<li>As MFA apps are available, it&#8217;s also possible to use hardware security keys again. There&#8217;s just one catch \u2014 only programmable tokens will fit for PayPal two-factor authentication.<\/li>\n<\/ol>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-button aligncenter\"><a class=\"wp-block-button__link has-background wp-element-button\" href=\"https:\/\/www.protectimus.com\/token\/slim\/\" style=\"background-color:#269400\" target=\"_blank\" rel=\"noreferrer noopener\">Buy hardware security key for PayPal<\/a><\/div>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How do I enable PayPal 2FA?<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1<\/h3>\n\n\n\n<p>To activate two-factor authentication in PayPal sign in your account and navigate to the settings menu.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter shadow-img\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"67\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-settings-1024x67.png\" alt=\"How to enable PayPal two-factor authentication - settings\" class=\"wp-image-5198\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-settings-1024x67.png 1024w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-settings-300x20.png 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-settings-768x50.png 768w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-settings-610x40.png 610w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-settings.png 1035w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 2<\/h3>\n\n\n\n<p>Choose the Security tab.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter shadow-img\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"147\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-security-1024x147.png\" alt=\"PayPal account settings - security\" class=\"wp-image-5199\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-security-1024x147.png 1024w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-security-300x43.png 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-security-768x110.png 768w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-security-610x88.png 610w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-security.png 1030w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 3<\/h3>\n\n\n\n<p>In the &#8220;2-step verification&#8221; section, click Set Up.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter shadow-img\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-5432 size-full\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-set-up-1024x783-1.png\" alt=\"PayPal 2-step verification set up settings\" width=\"1024\" height=\"783\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-set-up-1024x783-1.png 1024w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-set-up-1024x783-1-300x229.png 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-set-up-1024x783-1-768x587.png 768w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-set-up-1024x783-1-610x466.png 610w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 4<\/h3>\n\n\n\n<p>At this point, you&#8217;ll need to choose one of the available two-factor authentication methods: SMS or MFA application. Programmable hardware tokens can be linked with PayPal as MFA applications.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SMS.<\/strong> When you choose SMS authentication, you&#8217;ll need to provide a real phone number. You&#8217;ll instantly receive a message containing a PayPal security code to confirm the number is correct. We don&#8217;t recommend using SMS if you&#8217;re able to set up a 2FA app instead or order a hardware token for use with PayPal.<\/li>\n\n\n\n<li><strong>2FA app. <\/strong>Choose this option if you want to link an in-app PayPal authenticator, or the <a aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.protectimus.com\/slim-mini\/\" target=\"_blank\" rel=\"noreferrer noopener\">Protectimus Slim NFC<\/a> &#8211; programmable PayPal security key.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter shadow-img\"><img loading=\"lazy\" decoding=\"async\" width=\"560\" height=\"421\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-choose-2FA-method.png\" alt=\"Choose PayPal 2FA method - SMS or 2FA app\" class=\"wp-image-5201\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-choose-2FA-method.png 560w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-choose-2FA-method-300x226.png 300w\" sizes=\"auto, (max-width: 560px) 100vw, 560px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 5<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>If you haven&#8217;t already installed a one-time password generator app, install a free app <a aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.protectimus.com\/protectimus-smart\" target=\"_blank\" rel=\"noreferrer noopener\">Protectimus SMART OTP<\/a> or any other 2-factor authentication app.<\/li>\n\n\n\n<li>If you want to use a hardware security token, you&#8217;ll need to already have one at this point. It must be a programmable <a href=\"https:\/\/www.protectimus.com\/blog\/otp-generation-algorithms-and-token-types\/\">TOTP<\/a> token &#8211; <a aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.protectimus.com\/slim-mini\/\" target=\"_blank\" rel=\"noreferrer noopener\">Protectimus Slim NFC<\/a> or a similar one. The process to link a programmable hardware token to PayPal is no different than the process of linking a two-factor authentication app. To set up the token, you&#8217;ll need an Android smartphone that supports NFC.<\/li>\n<\/ul>\n\n\n\n<p>At this point, you&#8217;ll see a QR code containing the secret key. Scan this secret key using a two-factor authentication app, or using the <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.protectimus.totpburner.nfc&amp;hl=en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\" aria-label=\" (opens in a new tab)\">Protectimus TOTP Burner<\/a> app if you&#8217;re linking a hardware PayPal security key Protectimus Slim NFC. If you aren&#8217;t able to scan the QR code, you can input the secret key manually.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter shadow-img\"><img loading=\"lazy\" decoding=\"async\" width=\"573\" height=\"605\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-QR-code.png\" alt=\"PayPal 2-factor authentication set up - QR code with secret key\" class=\"wp-image-5202\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-QR-code.png 573w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-QR-code-284x300.png 284w\" sizes=\"auto, (max-width: 573px) 100vw, 573px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>You&#8217;ll find detailed instructions for programming the secret key into the Protectimus Slim NFC token <a href=\"https:\/\/www.protectimus.com\/blog\/program-protectimus-slim-nfc\/\">here<\/a>.<\/p>\n\n\n\n<p><center><iframe loading=\"lazy\" width=\"560\" height=\"315\" src=\"https:\/\/www.youtube.com\/embed\/Zc9AwLMKAmg\" frameborder=\"0\" allow=\"accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen=\"\"><\/iframe><\/center><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 6<\/h3>\n\n\n\n<p>To finish setting up PayPal 2-factor authentication, generate a one-time password with your token and enter it in the provided field.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter shadow-img\"><img loading=\"lazy\" decoding=\"async\" width=\"579\" height=\"609\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-enter-otp.png\" alt=\"PayPal two-factor authentication - enter PayPal security code\" class=\"wp-image-5203\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-enter-otp.png 579w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-enter-otp-285x300.png 285w\" sizes=\"auto, (max-width: 579px) 100vw, 579px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 7<\/h3>\n\n\n\n<p>Create a backup token. If you lose access to your current token, you can restore access to PayPal with your backup token. Remember that if you choose SMS authentication for backup, your PayPal account login will be less secure, even if you linked a hardware security key in the previous step. The best option is to use a hardware token as your main means of authentication and a 2FA PayPal app as a backup, or the other way around.<\/p>\n\n\n\n<p><span style=\"color: #ff0000;\">| Read also:<\/span> <a href=\"https:\/\/www.protectimus.com\/blog\/google-authenticator-backup\/\">How to Backup Google Authenticator or Transfer It to a New Phone<\/a><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter shadow-img\"><img loading=\"lazy\" decoding=\"async\" width=\"481\" height=\"478\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-additional-2FA-option.png\" alt=\"PayPal two-factor authentication setup - set a backup\" class=\"wp-image-5204\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-additional-2FA-option.png 481w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-additional-2FA-option-150x150.png 150w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-additional-2FA-option-300x298.png 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-additional-2FA-option-160x160.png 160w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-additional-2FA-option-240x240.png 240w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-additional-2FA-option-60x60.png 60w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/PayPal-two-factor-authentication-additional-2FA-option-184x184.png 184w\" sizes=\"auto, (max-width: 481px) 100vw, 481px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What&#8217;s the best option for PayPal two-factor authentication<\/strong>?<\/h2>\n\n\n\n<p>To answer this question, we&#8217;ve ranked the available PayPal two-factor authentication methods from strongest to weakest. Here are the results:<\/p>\n\n\n\n<p><strong>I place &#8211; Hardware security token<\/strong><\/p>\n\n\n\n<p><strong>II place &#8211; 2FA app<\/strong><\/p>\n\n\n\n<p><strong>III place &#8211; SMS authentication<\/strong><\/p>\n\n\n\n<p>Next, some details about each kind of token for PayPal two-factor auth.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hardware security tokens<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hardware tokens are stand-alone, isolated devices.<\/li>\n\n\n\n<li>A PayPal hardware token Protectimus Slim NFC never connects to the internet, making it invulnerable to viruses.<\/li>\n\n\n\n<li>One-time passwords are generated on the device itself, not transmitted over GSM channels like SMS messages. This means that one-time passwords cannot be intercepted.<\/li>\n\n\n\n<li>Even if you lose your security token, nobody who finds it will be able to gain access to your account. First, in addition to the token, a <a href=\"https:\/\/www.protectimus.com\/blog\/how-to-choose-and-use-strong-passwords\/\">strong password<\/a> is required. Second, someone who comes across the token will probably be unable to tell who the token belongs to and what service it&#8217;s linked to. Besides, you&#8217;ll definitely notice if your physical token is missing and change PayPal password immediately.<\/li>\n<\/ul>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter shadow-img\"><img loading=\"lazy\" decoding=\"async\" class=\"shadow-img aligncenter wp-image-5147\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/Protectimus-Slim-NFC-security-key-PayPal-1024x553.jpg\" alt=\"Protectimus Slim NFC - programmable security key for PayPal\" width=\"512\" height=\"276\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/Protectimus-Slim-NFC-security-key-PayPal-1024x553.jpg 1024w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/Protectimus-Slim-NFC-security-key-PayPal-300x162.jpg 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/Protectimus-Slim-NFC-security-key-PayPal-768x415.jpg 768w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/Protectimus-Slim-NFC-security-key-PayPal-610x329.jpg 610w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/Protectimus-Slim-NFC-security-key-PayPal.jpg 1200w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<p>The main disadvantages of hardware tokens are their cost and the fact that, sooner or later, the token&#8217;s battery will die, requiring you to buy a new token.<\/p>\n\n\n\n<p><span style=\"color: #ff0000;\">| Read also:<\/span> <a href=\"https:\/\/www.protectimus.com\/blog\/two-factor-authentication-types-and-methods\/\">The Pros and Cons of Different Two-Factor Authentication Types and Methods<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2FA app<\/h3>\n\n\n\n<p>Two-factor authentication apps attempt to combine the safety of a hardware PayPal security key with the convenience of SMS authentication. Essentially, by connecting Google Authenticator to PayPal, users receive a stand-alone device for generating one-time passwords right on their smartphones.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter shadow-img\"><img loading=\"lazy\" decoding=\"async\" width=\"348\" height=\"348\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-app-protectimus-smart.jpg\" alt=\"Paypal two-factor authentication app Protectimus Smart\" class=\"wp-image-5144\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-app-protectimus-smart.jpg 348w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-app-protectimus-smart-150x150.jpg 150w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-app-protectimus-smart-300x300.jpg 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-app-protectimus-smart-160x160.jpg 160w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-app-protectimus-smart-240x240.jpg 240w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-app-protectimus-smart-60x60.jpg 60w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-app-protectimus-smart-184x184.jpg 184w\" sizes=\"auto, (max-width: 348px) 100vw, 348px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p>This method of securing a PayPal account is much better than SMS-based two-factor authentication. However, since smartphones have internet access, if you use a 2FA app to protect your PayPal login, there are some risks to keep in mind:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>If you lose your smartphone, you risk <a aria-label=\" (opens in a new tab)\" href=\"https:\/\/security.stackexchange.com\/questions\/183065\/is-paypals-2fa-security-really-this-bad\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">simultaneously losing your password and authentication token<\/a>.<\/li>\n\n\n\n<li>Smartphones can also be infected by viruses, which may be able to extract one-time passwords from 2FA apps.<\/li>\n<\/ol>\n\n\n\n<p><span style=\"color: #ff0000;\">| Read also:<\/span> <a href=\"https:\/\/www.protectimus.com\/blog\/10-most-popular-2fa-apps-on-google-play\/\">10 Most Popular Two-Factor Authentication Apps Compared<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">SMS authentication<\/h3>\n\n\n\n<p>First off, it&#8217;s worth noting that SMS authentication is better than nothing. If you aren&#8217;t able to set up an app for PayPal 2-step verification or order a hardware token, you should enable SMS-based PayPal 2FA, by all means.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter shadow-img\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"400\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-with-sms.jpg\" alt=\"PayPal two-step verification with SMS\" class=\"wp-image-5145\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-with-sms.jpg 400w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-with-sms-150x150.jpg 150w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-with-sms-300x300.jpg 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-with-sms-160x160.jpg 160w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-with-sms-240x240.jpg 240w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-with-sms-60x60.jpg 60w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/07\/paypal-two-factor-authentication-with-sms-184x184.jpg 184w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p>Much has already been written about the disadvantages of SMS-based authentication. The main risks can be divided into three groups:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the possibility of replacing the user&#8217;s SIM card (SIM swap scam);<\/li>\n\n\n\n<li>the risk of SMS messages being intercepted, if the SMS provider&#8217;s infrastructure is compromised or maliciously altered;<\/li>\n\n\n\n<li>the possibility of SMS messages being intercepted on the end user&#8217;s device, by means of a virus.<\/li>\n<\/ul>\n\n\n\n<p>The <a href=\"https:\/\/www.protectimus.com\/blog\/reddit-hacked\/\">hacking of a Reddit employee&#8217;s account<\/a> is one of the most widely discussed cases in which SMS authentication was defeated. The attackers were able to exploit vulnerabilities in the SMS authentication process to compromise the data of thousands of the social network&#8217;s users.<\/p>\n\n\n\n<p>However, the disadvantages of SMS-based authentication do not stop at the three points on this list. There can be quite a few problems using SMS-based PayPal verification if the user travels to a different country (and is using roaming), or if the user travels to an area without cellular service.<\/p>\n\n\n\n<p><span style=\"color: #ff0000;\">| Read also:<\/span> <a href=\"https:\/\/www.protectimus.com\/blog\/sms-verification-is-vulnerable\/\">Dutch Scientists: SMS Verification Is Vulnerable<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Frequently asked questions<\/strong><\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How do I enable two-factor authentication on PayPal?<\/strong><\/strong> <p class=\"schema-faq-answer\"><ol><li>Navigate to the settings menu.<\/li><li>Choose the Security tab.<\/li><li>Find &#8220;2-step verification&#8221;<\/li><li>Choose a PyPal 2-factor authentication method: SMS or 2FA application (hardware tokens can be linked to PayPal as if they were 2FA applications).<\/li><li>Scan the QR code containing the secret key to create a token in your app, or to program your hardware token.<\/li><li>To finish setting up PayPal two-factor authentication, generate a one-time password with your token and enter it in the provided field.<\/li><\/ul><\/p> <\/div> <div class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How do I get access to my PayPal account if I lost my phone number or token?<\/strong><\/strong> <p class=\"schema-faq-answer\">To avoid problems with accessing your PayPal account in the event that you lose your phone or token, set up a backup token in advance. It&#8217;s best to use an app on another phone, or a Protectimus Slim NFC hardware token.<\/p> <\/div> <div class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>Can I replace my old PayPal security key with a new one?<\/strong><\/strong> <p class=\"schema-faq-answer\">Unfortunately, PayPal stopped selling its own hardware security keys. However, you can link the programmable Protectimus Slim NFC security token to your PayPal account.<\/p> <\/div> <div class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How do I connect a hardware security key to PayPal?<\/strong><\/strong> <p class=\"schema-faq-answer\">Only programmable hardware TOTP tokens, like the Protectimus Slim NFC, can be used for two-factor authentication with PayPal. Programmable hardware tokens can be linked as if they were two-factor authentication apps. To link a security key to PayPal, you&#8217;ll need an Android smartphone that supports NFC.<\/p> <\/div> <div class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How much does a PayPal security key cost?<\/strong><\/strong> <p class=\"schema-faq-answer\">The price of one Protectimus Slim NFC token is US$29.99 plus shipping.<\/p> <\/div> <\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Read also:<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.protectimus.com\/blog\/how-does-2-factor-authentication-work\/\">How does 2-factor authentication work?<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.protectimus.com\/blog\/the-evolution-of-two-step-authentication-means\/\">The Evolution of Two-Step Authentication<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.protectimus.com\/blog\/time-drift-in-totp-hardware-tokens\/\">Time Drift in TOTP Hardware Tokens Explained and Solved<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.protectimus.com\/blog\/online-skimming\/\">What is Online Skimming and How to Avoid It<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.protectimus.com\/blog\/the-most-common-ways-of-credit-card-fraud\/\">The Most Common Ways of Credit Card Fraud<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.protectimus.com\/blog\/7-tips-from-phishing-scams\/\">Top 7 Tips How to Protect Yourself from Phishing Scams<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.protectimus.com\/blog\/social-engineering-why-it-works\/\">Social Engineering: What It Is and Why It Works<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.protectimus.com\/blog\/mitm-prevention-and-detection\/\">Man In The Middle Attack Prevention And Detection<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.protectimus.com\/blog\/two-factor-authentication-for-windows\/\">Two-factor authentication for Windows 7, 8, 10<\/a><\/li>\n<\/ul>\n<span class=\"et_bloom_bottom_trigger\"><\/span>","protected":false},"excerpt":{"rendered":"<p>PayPal two-factor authentication became available to users in far 2007. Everybody wishing to protect their PayPal login could order a $5 security token directly from their account. Unfortunately, later the company discontinued the use of its own hardware tokens in favor of SMS-based authentication, decreasing PayPal security considerably. But the situation with PayPal two-factor authentication [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":5240,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[9,329],"tags":[395,1340,335,421,130,139],"class_list":["post-5221","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-protectimus-products","category-setup-guides","tag-authentication-apps","tag-paypal-en","tag-protectimus-slim-nfc-en","tag-setup-guides","tag-sms-authentication","tag-tokens"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts\/5221","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/comments?post=5221"}],"version-history":[{"count":22,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts\/5221\/revisions"}],"predecessor-version":[{"id":9111,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts\/5221\/revisions\/9111"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/media\/5240"}],"wp:attachment":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/media?parent=5221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/categories?post=5221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/tags?post=5221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}