Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

31–40 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#31

Why are all these attacks targeting Twitter usernames? Do these really have particularly significant resale value? It seems like much greater profit could be made with access to someone's Amazon account, but these seem to be used as merely a proxy in these attacks.

I'd imagine that the illegality of fraudulently using an Amazon account would be more clearcut and easier to prosecute.

Re: Jb’s story about how he nearly lost his Twitter handle

#32

Earlier quoted context omitted.

I'd like to enable two factor auth on my twitter account, but I'm put-off by their SMS-based implementation. Does anyone know if they have plans to support TOTP, like Google, GitHub, etc?

If you have the Twitter app on your smartphone, you can get notifications through it. I have 2FA for Twitter but do not receive SMS messages.

Thanks, I didn't know that! That might be good enough, as I quite often have no phone signal (and therefore no SMS) but still have net connectivity via wifi.

I'd still prefer the TOTP approach though because it doesn't require any connectivity on the phone.

Re: Jb’s story about how he nearly lost his Twitter handle

#33
post #30
post #19

It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before…

Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.

How would that be exploitable?

Re: Jb’s story about how he nearly lost his Twitter handle

#34

Earlier quoted context omitted.

It’s worth setting up two-factor authentication on any service that supports it: Google, Facebook and Github spring to mind.

Definitely. While it's not a perfect solution, it provides an extra layer of protection for your accounts by making an extra hurdle for any attacker to clear. Needing two components to access/change your accounts is elegant and effective. Pay-as-you-go phones are advisable to use for two factor verification, as they are affordable and could be used only for this purpose. Don't hand out the number and you've got a nic…

Many providers shuts down the account if you don't use it for calling at least once per year. Some close it down if you don't fill up the cachpool with money every 6-12 months.

Re: Jb’s story about how he nearly lost his Twitter handle

#35
post #30

Earlier quoted context omitted.

Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.

How would that be exploitable?

If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)

Re: Jb’s story about how he nearly lost his Twitter handle

#36
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

> and save that (along with the question title) in your (properly backed up!) password safe.

To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally secure, location).

Re: Jb’s story about how he nearly lost his Twitter handle

#37
post #30
post #19

It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before…

Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.

[deleted]

Re: Jb’s story about how he nearly lost his Twitter handle

#38
Jesus fucking christ. Stop making websites accept anything other than a username+password/token for authentication, and this kind of retarded shit would never happen. It's somehow still the status quo to make backdoors to recover your account incase you lock yourself out, which is why things like this happen all the time. You get what you deserve.

Re: Jb’s story about how he nearly lost his Twitter handle

#39
post #35

Earlier quoted context omitted.

How would that be exploitable?

If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)

If they're relying on such information for security, they aren't secure in the first place.
Post reply on HN