Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

11–20 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#11

These stories are starting to scare me... I've already started using 1Password but I'm now considering closed some accounts and calling some of these services to ensure they never give out my information for password resets and such... Scary stuff...

It’s worth setting up two-factor authentication on any service that supports it: Google, Facebook and Github spring to mind.

I'd like to enable two factor auth on my twitter account, but I'm put-off by their SMS-based implementation. Does anyone know if they have plans to support TOTP, like Google, GitHub, etc?

Re: Jb’s story about how he nearly lost his Twitter handle

#12
> He then called Amazon with what little information he had gained and cried that he had lost his password and didn’t have access to that email address anymore. The representative caved and reset the password over the phone giving him full access to my Amazon account. His plan was to then gain as much information he could with Amazon (last four of credit card numbers, current and previous addresses, etc…) and use that as ammunition to do the same thing with Apple. And it worked. He had an email in his gmail inbox with instructions on how to reset my iCloud account.

Whatever you think of the state of cybersecurity in terms of encryption, implementation, and user-interface (including 2-factor authentication)...it doesn't seem that the protections against social engineering have developed at the same pace as the increasing ease of accessing public records

Re: Jb’s story about how he nearly lost his Twitter handle

#14

Earlier quoted context omitted.

It’s worth setting up two-factor authentication on any service that supports it: Google, Facebook and Github spring to mind.

I'd like to enable two factor auth on my twitter account, but I'm put-off by their SMS-based implementation. Does anyone know if they have plans to support TOTP, like Google, GitHub, etc?

[deleted]

Re: Jb’s story about how he nearly lost his Twitter handle

#15
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

Agreed. If I get to pick the security question itself, it'll be something like "What's the magic code?" to emphasise that the gibberish answer was set intentionally.

Re: Jb’s story about how he nearly lost his Twitter handle

#16
post #9

Earlier quoted context omitted.

It’s worth setting up two-factor authentication on any service that supports it: Google, Facebook and Github spring to mind.

Dropbox and app.net also do 2FA. If the service you're using doesn't support it, ask them to implement it. If enough people did it..

I'm currently building a framework agnostic Authentication module for PHP/Composer, that has 2FA baked in. I want to give everyone who's building web apps in PHP no excuse for not having it. It's painful, but worth it IMO.

Re: Jb’s story about how he nearly lost his Twitter handle

#17

These stories are starting to scare me... I've already started using 1Password but I'm now considering closed some accounts and calling some of these services to ensure they never give out my information for password resets and such... Scary stuff...

It’s worth setting up two-factor authentication on any service that supports it: Google, Facebook and Github spring to mind.

Definitely. While it's not a perfect solution, it provides an extra layer of protection for your accounts by making an extra hurdle for any attacker to clear. Needing two components to access/change your accounts is elegant and effective.

Pay-as-you-go phones are advisable to use for two factor verification, as they are affordable and could be used only for this purpose. Don't hand out the number and you've got a nice disposable tool for protecting your accounts.

Re: Jb’s story about how he nearly lost his Twitter handle

#19
It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before the reset takes effect, send emails which notifies the current email etc, or even send a pin to their postal address. I know these are not ideal security either but at least there would be some grace period.
Post reply on HN