The other big issue with their 2FA authentication is that it really isn't two factor. You can say you don't have the token and instead can answer security questions. Two factor is supposed to be something you know plus something you have. "Falling back" to security questions is basically just relying on things you know.
Like any other fraud-signal, though, it can be countered with enough evidence that you are who you say you are--with security questions at a weak level (maybe enough to counter a 2FA token that was only set up a few days ago), or with demands for scanned photo ID at a higher level (if you use 2FA all the time.)
It is more security theatre, giving PayPal's users a feeling of security.
they asked for a month and 3 days. Duo wanted to disclose on June 25th, PayPal has a fix on July 28th.
I hope you were being sarcastic...
It "only" works one time though, the second time you're asked the dreaded "security question"
And people wonder why I'm constantly telling them to stop using PayPal.