Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

41–50 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#41
post #39
post #35

Earlier quoted context omitted.

If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)

If they're relying on such information for security, they aren't secure in the first place.

I think that the idea is to not help out a potential attacker rather than to use this as an absolute security method. I think that we can agree that relying on any single security method is foolish. Maybe we shouldn't jump to conclusions that this is their only security measure in place.

Re: Jb’s story about how he nearly lost his Twitter handle

#42
post #39
post #35

Earlier quoted context omitted.

If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)

If they're relying on such information for security, they aren't secure in the first place.

If they're relying on multiple weak pieces of information like this for security, they still aren't secure, and now they just created a huge pain in the ass for any user of their system, as they have to somehow know all the pieces of information which are supposed to be secret. Huge-pain-in-the-ass security doesn't tend to work very well...

Re: Jb’s story about how he nearly lost his Twitter handle

#43
post #38

Jesus fucking christ. Stop making websites accept anything other than a username+password/token for authentication, and this kind of retarded shit would never happen. It's somehow still the status quo to make backdoors to recover your account incase you lock yourself out, which is why things like this happen all the time. You get what you deserve.

This is great in theory, but in practice your regular customers are going to lose/mix up their usernames and passwords all the time.

They need some kind of back door to recover their access (because honestly, even for the responsible and tech-savvy users, sometimes sh!t happens... e.g., my password manager generated a new password but my laptop crashed before I could save it), and they assume there will be a way to restore their account.

I'm sure you could tell your customers "you get what you deserve", but not if you want them to remain customers.

Re: Jb’s story about how he nearly lost his Twitter handle

#44
post #6

I think a lot of it comes down to this: "4. Some of the biggest companies in the world have security that is only as good as a minimum-wage phone support worker who has the power to reset your account. And they have valid business reasons for giving them this power."

It could be greatly mitigated by automating that power more.

E.g., "No problem, I can reset your password! The system will automatically contact your registered phone number and email address -- if you confirm both, it resets now, and if you can't, it will send the reset to your new email 3 days from now."

Re: Jb’s story about how he nearly lost his Twitter handle

#45
One thing I've found handy is just to have little or no bio information on your accounts. If you absolutely must have bio info on your account, make all the information different from account to account.

This way, if a hacker gets your LinkedIn profile, the information there is different than your Facebook info, which is different than your Twitter info, which is different from your. .

Imagine a hacker with a handful of accounts and all the information is completely inconsistent. How does he decide which one is real and which one's are fake? It's essentially a dead end and will hopefully get them to move on to an easier target.

Re: Jb’s story about how he nearly lost his Twitter handle

#46
post #34

Earlier quoted context omitted.

Definitely. While it's not a perfect solution, it provides an extra layer of protection for your accounts by making an extra hurdle for any attacker to clear. Needing two components to access/change your accounts is elegant and effective. Pay-as-you-go phones are advisable to use for two factor verification, as they are affordable and could be used only for this purpose. Don't hand out the number and you've got a nic…

Many providers shuts down the account if you don't use it for calling at least once per year. Some close it down if you don't fill up the cachpool with money every 6-12 months.

Right, pay-as-you-go phones are annoying that way, if you aren't actually using them. I've lost a few phone numbers because I didn't remember to top-up a phone I wanted for rare uses and/or only incoming calls.

Re: Jb’s story about how he nearly lost his Twitter handle

#47
post #36
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…

You're right, it's not the intended use of the security question - and that's exactly what I want. I feel like entering my pet's name doesn't add to my account security but rather lowers it.

My password safe is stored at many different location so that it's extremely unlikely to loose them all at once. And to secure against amnesia or being-hit-by-a-truck, you should give the passphrase to a person you trust 100%.

Re: Jb’s story about how he nearly lost his Twitter handle

#48
post #23

Earlier quoted context omitted.

No problem - got a spare €100,000 to pay for my lawyers?

I don't know exactly where you are, but back home lawyers with pretty good chances of winning a case like this would be jumping at this with a no-win no fee.

Please show me a lawyer who wants to go head-to-head with Apple, Google or Amazon on a case like this on "no win no fee" terms.

Re: Jb’s story about how he nearly lost his Twitter handle

#49
post #40

It would be useful if a date was given for this story.

At the bottom in tiny text it says: "Published January 29, 2014" Also, in the source:

That is when it was published, but the text gives no indication if the events happened yesterday or 12 months ago. It's useful to know if these abysmal practices are still current or not at Apple/Amazon/etc.

Re: Jb’s story about how he nearly lost his Twitter handle

#50
post #23

Earlier quoted context omitted.

No problem - got a spare €100,000 to pay for my lawyers?

I don't know exactly where you are, but back home lawyers with pretty good chances of winning a case like this would be jumping at this with a no-win no fee.

How much damages do you expect to win for loss of a twitter username?
Post reply on HN