Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

171–180 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#171
Reminds me of harvesting ICQ numbers. There was a time when you could search 6-digit ICQ numbers for expired freemail addresses like Hotmail (they deleted your account after a while), register that freemail address and reset your ICQ number password to get a brand "new" 6-digit number. I think this doesn't work anymore, since most freemail hosters don't "free" expired email addresses but keep them locked.

It still works if you find an expired domain name, register the domain name and then do the whole password-reset procedure. Might be cheaper to buy a 6 digit number on eBay though :)

Re: How I Lost My $50,000 Twitter Username

#172
post #18

Who are people's current favorite domain registrars? I've been with name.com for the last year or so and have been happy, but I'm always curios to hear from others.

I'm using a small local regitrar, europeandomaincentre.com - I originally picked them because they can accommodate all sorts of international domains, and partially because they are within walking distance of my office. That way, if something goes wrong, I could go there and talk to them in person.

Their customer service has been really great since, so I'm staying. It's probably slightly more expensive than I could get elsewhere, but for the sense of security I get, it's completely worth it.

Point being- In this shitty business, where trust is everything - I prefer a small player who I can have a direct personal relation to, over some big nameless corporation.

Re: How I Lost My $50,000 Twitter Username

#173
Is it not possible to use the last bills as verification of who you are? screenshot of the bank statements and asking GoDaddy to verify their bank data and you've shown that it is in fact you who paid the bills.

Also if account data is changed they MUST keep a log of what your data was before. At least anything beside passwords.

Re: How I Lost My $50,000 Twitter Username

#174
For all the posts I would make, and the first one having been what it was, it should have included: don't use GoDaddy. I just, can't express how immediately my sympathy disappears when I read that word. The amount of arrogance it takes to be in tech and still use GoDaddy is beyond comprehension.

Re: How I Lost My $50,000 Twitter Username

#175

Just find it interesting to see how different the conversation on the same topic is over at reddit, http://www.reddit.com/r/technology/comments/1wfwfp/how_i_los...

Sad to say, reddit sounds more human today than HN. So many people here saying, "He only tweeted 3 times in 2013, he deserves to lose it". Have some empathy! You think the hacker who tricked Paypal and Godaddy is in the right here to steal it? I can't believe it.

I found this story interesting for the social engineering aspect. The lack of "outrage" is actually quite refreshing.

Re: How I Lost My $50,000 Twitter Username

#176

That reminds me, a few months ago I had a weird Twitter experience. Someone gained access to my rarely used Twitter account @smartician and started posting spam. Somehow Twitter noticed, reset the password and notified me via email. I have no idea how that was possible.

It happened me as well, I just shut down the account.

Re: How I Lost My $50,000 Twitter Username

#177
post #53

Earlier quoted context omitted.

Twitter's official policy is that an account becomes inactive after 6 months - at that point, they reserve the right to release the account (in practice they rarely do this, though - there isn't an automated job releasing inactive accounts or anything) https://support.twitter.com/articles/15362-inactive-account-... @N (now @N_is_stolen)'s last post was 4 months ago, so he is still technically considered an active use…

Activity doesn't require the creation of a tweet though. There are plenty of active accounts where the users just read.

That is what I do.

Less than 10 tweets in 3 years and all I do is read other tweets

Re: How I Lost My $50,000 Twitter Username

#178

Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy. [Edited to add] I would sure love to see a scarlet letter list of compan…

I actually think it was 4.

Re: How I Lost My $50,000 Twitter Username

#179

I feel bad for this guy, and twitter needs to do the right thing and return to him his handle. Then I can come back here and post nasty comments about squatters.

Yes, absolutely.

The guy has given a clear and convincing story of what happened. I'm sure that it would be pretty easy for someone on Twitter's security team (assuming that they have one) to verify that the username was taken when he said it was.

I don't know what I find more shocking -- that PayPal would actually give the last four digits of a credit-card number to a complete stranger, that GoDaddy would let someone guess a two-digit number, or that a credit-card number is all you need to identify yourself. (In Israel, it's common for companies to ask for the last four digits of your credit card number in addition to other details, but never on its own.)

Actually, I'm willing to believe just about anything about GoDaddy. But PayPal is known for being surprisingly harsh and paranoid about security, shutting down accounts and holding money when they suspect problems. It's sad and rather surprising to me that they're willing to give out such information so easily, unless you specifically ask them not to. Shouldn't it be the other way around, that they refuse to provide such details unless you allow them to?

I really hope that Twitter and PayPal apologize profusely to this author, and undo the damage they've done as best as possible.

Re: How I Lost My $50,000 Twitter Username

#180

Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy. [Edited to add] I would sure love to see a scarlet letter list of compan…

I actually think it was 4.

GoDaddy requires 6 digits, but the agent let the attacker guess 2 of them (repeatedly, until he got it right). That's truly awful.
Post reply on HN