Why are all these attacks targeting Twitter usernames? Do these really have particularly significant resale value? It seems like much greater profit could be made with access to someone's Amazon account, but these seem to be used as merely a proxy in these attacks.
Jb’s story about how he nearly lost his Twitter handle
31–40 of 123 posts
Re: Jb’s story about how he nearly lost his Twitter handle
#32Earlier quoted context omitted.
I'd like to enable two factor auth on my twitter account, but I'm put-off by their SMS-based implementation. Does anyone know if they have plans to support TOTP, like Google, GitHub, etc?
If you have the Twitter app on your smartphone, you can get notifications through it. I have 2FA for Twitter but do not receive SMS messages.
I'd still prefer the TOTP approach though because it doesn't require any connectivity on the phone.
Re: Jb’s story about how he nearly lost his Twitter handle
#33It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before…
Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.
Re: Jb’s story about how he nearly lost his Twitter handle
#34Earlier quoted context omitted.
It’s worth setting up two-factor authentication on any service that supports it: Google, Facebook and Github spring to mind.
Definitely. While it's not a perfect solution, it provides an extra layer of protection for your accounts by making an extra hurdle for any attacker to clear. Needing two components to access/change your accounts is elegant and effective. Pay-as-you-go phones are advisable to use for two factor verification, as they are affordable and could be used only for this purpose. Don't hand out the number and you've got a nic…
Re: Jb’s story about how he nearly lost his Twitter handle
#35Earlier quoted context omitted.
Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.
How would that be exploitable?
Re: Jb’s story about how he nearly lost his Twitter handle
#36another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.
To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally secure, location).
Re: Jb’s story about how he nearly lost his Twitter handle
#37It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before…
Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.
Re: Jb’s story about how he nearly lost his Twitter handle
#38Re: Jb’s story about how he nearly lost his Twitter handle
#39Earlier quoted context omitted.
How would that be exploitable?
If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)
Re: Jb’s story about how he nearly lost his Twitter handle
#40It would be useful if a date was given for this story.
Also, in the source: