We reported to PayPal a way to bypass their two-factor authentication, and their response was to remove the requirement for two-factor authentication. In this article, we document our findings and explain why 2FA is an important security feature that should be taken seriously.