Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

21–30 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#21

Earlier quoted context omitted.

It’s worth setting up two-factor authentication on any service that supports it: Google, Facebook and Github spring to mind.

I'd like to enable two factor auth on my twitter account, but I'm put-off by their SMS-based implementation. Does anyone know if they have plans to support TOTP, like Google, GitHub, etc?

If you have the Twitter app on your smartphone, you can get notifications through it. I have 2FA for Twitter but do not receive SMS messages.

Re: Jb’s story about how he nearly lost his Twitter handle

#22
post #12

> He then called Amazon with what little information he had gained and cried that he had lost his password and didn’t have access to that email address anymore. The representative caved and reset the password over the phone giving him full access to my Amazon account. His plan was to then gain as much information he could with Amazon (last four of credit card numbers, current and previous addresses, etc…) and use tha…

>Whatever you think of the state of cybersecurity in terms of encryption, implementation, and user-interface (including 2-factor authentication)...it doesn't seem that the protections against social engineering have developed at the same pace as the increasing ease of accessing public records

Yep. Around the same time I started using a randomly generated 24 digit alphanumeric password generated with an offline computer, I noticed a twin person who looked nearly the same as me nearly started living in my apartment, and asking an awful lot of questions about our supposedly shared childhood, wanting to "catch up".

It was certainly nice suddenly having a twin, but it wasn't until he suddenly disappeared three years later that I realized I should have been just as wary about social engineering as I was about my encryption.

Re: Jb’s story about how he nearly lost his Twitter handle

#23

Here's what you do. Get a lawyer and sue them for all they're worth. Not just for you, but for every other person their pathetic security has and may cause problems for them in the future.

No problem - got a spare €100,000 to pay for my lawyers?

Re: Jb’s story about how he nearly lost his Twitter handle

#25
Why are all these attacks targeting Twitter usernames? Do these really have particularly significant resale value? It seems like much greater profit could be made with access to someone's Amazon account, but these seem to be used as merely a proxy in these attacks.

Re: Jb’s story about how he nearly lost his Twitter handle

#26
post #23

Here's what you do. Get a lawyer and sue them for all they're worth. Not just for you, but for every other person their pathetic security has and may cause problems for them in the future.

No problem - got a spare €100,000 to pay for my lawyers?

I don't know exactly where you are, but back home lawyers with pretty good chances of winning a case like this would be jumping at this with a no-win no fee.

Re: Jb’s story about how he nearly lost his Twitter handle

#27
post #9

Earlier quoted context omitted.

It’s worth setting up two-factor authentication on any service that supports it: Google, Facebook and Github spring to mind.

Dropbox and app.net also do 2FA. If the service you're using doesn't support it, ask them to implement it. If enough people did it..

And I thought that dropbox had already lost their reputation with pretty much everyone around since those massive security flaws exposed a while back. Silly me.

Re: Jb’s story about how he nearly lost his Twitter handle

#28
post #19

It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before…

Or they could at least call back to the phone number stored on file.

Re: Jb’s story about how he nearly lost his Twitter handle

#29
I thought I'd post to let some people know how I BELIEVE this is being done.

Kevin Mitnick always talks about how social engineering is the key usually, ans it is. he used to make phone calls after dumpster diving and gaining employee names. There's no need for that now, we have all our information on the internet.

let me explain a little better. Take your facebook for example. Most people have the email they use on their for everyone to see, same with linked in. Now once a hacker finds who they want to target, just start googling the person and collect as much data as possible through comments made by and towards them. usually they'll comment on their pets name and all the other info they usually use to reset passwords. adding the person on a fake account acting like one of their friends with a new account is typical.

once they have all this info and the emails you use, time to take over what emails they can with your information. security questions are usually the route they go. once they have an email account, time to grab the others that are usually linked to each other for password resets. once those emails are taken over... it's all downhill from there.

best thing to do is make everything private and don't use the same username or handle on everything because that makes it easier to link to you.

just my thought about how this is done. pretty simple if you have some time to invest

Re: Jb’s story about how he nearly lost his Twitter handle

#30
post #19

It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before…

Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.
Post reply on HN