PayPal

PayPal updated their terms and conditions / acceptable use policy, which caused an internet rage fest, and appears to now have been repealed.

Note that PayPal is odd in that it has registered (and uses) domains of the form "paypal*.com", eg. paypalobjects.com where it publishes its AUP, and paypalcommunication.com for email.

reg() { whois $1 | grep Registrant.Org || echo not found; }
reg paypalobjects.com
Registrant Organization: PayPal Inc.

reg paypalcommunication.com
Registrant Organization: PayPal Inc.

reg paypalpolicy.com
Registrant Organization: PayPal Inc.

reg paypaldocuments.com
not found

This seems like it makes phishing easier since anyone could register paypaldocuments.com and serve evil from there. How are we to know that paypalobjects.com was authored by PayPal? There is nothing in their DNS records that ties it back to paypal.com.

q() { dig "$@" | sed 's/[^ \t-]\{32,\}/.../g' | fmt -t; }
for t in soa a txt ns ; do
  q +noall +answer $t paypalobjects.com
done

paypalobjects.com.	300	IN	SOA
   ppdns.paypal.com. hostmaster.paypal.com. 2008113266 7200 600 1209600
   300
paypalobjects.com.	194	IN	A	64.4.250.38
paypalobjects.com.	194	IN	A	64.4.250.39
paypalobjects.com.	300	IN	TXT	"_globalsign-domain-...
paypalobjects.com.	300	IN	TXT	"_globalsign-domain-...
paypalobjects.com.	300	IN	TXT
   "google-site-...-JNKqxxY8LSxtbsRg"
paypalobjects.com.	300	IN	NS	pdns100.ultradns.com.
paypalobjects.com.	300	IN	NS	ns1.p57.dynect.net.
paypalobjects.com.	300	IN	NS	ns2.p57.dynect.net.
paypalobjects.com.	300	IN	NS	pdns100.ultradns.net.
The only reference to paypal.com is via the SOA record's MNAME, except that it's a hidden master and isn't queriable.
q paypalobjects.com @ppdns.paypal.com
dig: couldn't get address for 'ppdns.paypal.com': not found

Looking at the EV cert at https://paypalobjects.com -- none of the domains are paypal.com.

openssl s_client -connect paypalobjects.com:443 < /dev/null |
  sed -n '/BEGIN.CERT/,/END.CERT/ p' |
  openssl x509 -text -noout -in -  |
  sed -n '
    /Subject:/ { s/.*CN = //; p}
    /Subject.Alter/,/Key.Usage/ { /DNS:/! d; s/DNS://g; s/, /\n/g; p }' |
  tr -d ' ' | sort | fmt

paypal.at paypal-australia.com.au paypal.be paypalbenefits.com
paypal-businesscenter.com paypal-business.com.au paypal-business.co.uk
paypal.ca paypal.ch paypal.cl PAYPAL.CO paypal.co.id paypal.co.il
paypal.co.in paypal.com.ar paypal.com.au paypal.com.br paypal.com.cn
paypal.com.hk paypal-communications.com paypal-community.com
paypal.com.mx PAYPAL.COM.MY paypal.com.pe paypal.com.sa paypal.com.sg
paypal.com.tr paypal.com.tw paypal.com.ve paypal.co.nz paypal.co.th
paypal.co.uk paypal.co.uk paypal.co.za paypal-danmark.dk
paypal.de PAYPAL-DEUTSCHLAND.DE paypal.dk paypal-donations.com
paypal-donations.co.uk paypal.es paypal.eu paypal.fi paypal.fr
paypal-gifts.com paypalgivingfund.org paypal-globalshops.com paypal.ie
paypal.in paypal-information.com paypal.it paypal.jp paypal-knowledge.com
paypal-knowledge-test.com paypal-latam.com paypal.lu paypal-marketing.ca
paypal-marketing.co.uk PAYPAL-MARKETING.PL paypal.me paypal-media.com
paypal-mena.com paypal-mktg.com paypal-nakit.com paypal.nl paypal.no
paypal-norge.no paypalobjects.com paypal-optimizer.com paypal-partners.com
paypal-passport.com paypal.ph paypal.pl paypal-prepagata.com
paypal-promo.es paypal.pt paypal.se paypal-sverige.se paypal-turkiye.com
paypal.vn thepaypalblog.com

At points like these, towels are thrown....