Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

101–110 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#101
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

I set security questions to something random and never store it. It's only a risk to store it.

The only time I needed my security question was when changing email address on PayPal. I gave them a call and was able to change it by reading the security code (a randomly generated PIN).

Any company giving access to your account by security questions is not to be trusted. I never keep more than a few euros in my PayPal account for multiple reasons, and this is one of them.

Shameless plug to a post I wrote on security questions: https://lucb1e.com/?p=post&id=65

Re: Jb’s story about how he nearly lost his Twitter handle

#102

Why are all these attacks targeting Twitter usernames? Do these really have particularly significant resale value? It seems like much greater profit could be made with access to someone's Amazon account, but these seem to be used as merely a proxy in these attacks.

Same sort of thing targeting low numbered ICQ accounts back years ago. I had mine stolen from under me and while it doesn't actually matter anymore, it did upset and make me angry at the time.

I guess if they can't resell it they do it for shits and giggles, and because grabbing a low numbered/low lettered anything these days is a decent trophy to have.

Re: Jb’s story about how he nearly lost his Twitter handle

#103
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

Security questions don't even help. Some of the support reps from various companies can see your answer and with enough prodding they will just tell you it over the phone.

Re: Jb’s story about how he nearly lost his Twitter handle

#104

Why are all these attacks targeting Twitter usernames? Do these really have particularly significant resale value? It seems like much greater profit could be made with access to someone's Amazon account, but these seem to be used as merely a proxy in these attacks.

The problem here is usually the people doing this are just kids in the "scene". They go after original names on all different mediums like xbox live, twitter, instagram, etc. Usually the accounts sell from $100 up to $1000+, but they don't really realize the potential of what they could do with this.

They could easily put their minor SE skills towards hijacking high quality information, but instead they use it to get known for stealing usernames.

Re: Jb’s story about how he nearly lost his Twitter handle

#106
post #87

Earlier quoted context omitted.

I like how Yahoo suddenly decided to make their "security questions" a secondary password. I have no idea what I answered over a decade ago, but I can no longer log into my account despite them acknowledging my password to be correct. Where's the "reset security question" option...

I actually ran into this the other day. The account I had used from 8th grade to about 11th is now probably gone forever.

Only until they decide to recycle the usernames.

Re: Jb’s story about how he nearly lost his Twitter handle

#107
post #98
post #94

Earlier quoted context omitted.

Ironically, HN itself so happens to do it right - it permits you to have only a user/password. Reddit is the same, so is github, stackoverflow. I've never heard of pervasive problems on either of these sites. I don't submit my email to these sites, and they work fine. Please continue to call common fucking sense idealism. Look how shit any other site besides the 4 (and others like them) I mentioned are with their fan…

Even if customers are scatterbrained and unwilling to accept responsibility for themselves, it's still better to keep them on board and making money than trying to teach them a lesson out of principle that probably won't even stick. How well any policies are actually thought through is another matter.

Yes, because users would hate so much to be told explicitly that all they need to remember is a password. They much rather have 20 different pieces of information, some combinations of which if they share, people can take over their accounts on various services.

The problem is not so much that the systems suck, the problem is there's no way for people like me to take on the responsibility and "risk" of just having a simple way to authenticate myself.

For example, in my bank I would opt into having all "suspicious transaction" types of protections turned off, but if I went to my local branch and asked for that, they'd just get confused and think I'm trying to commit fraud.

> it's still better to keep them on board and making money

Maybe better for you, assuming there would be a net loss from turning off the bullshit policy. Definitely not better for customers, as it enables theft, which has the same consequence as forgetting a password.

Re: Jb’s story about how he nearly lost his Twitter handle

#108
post #69
post #59

Earlier quoted context omitted.

That's not completely true. If you're in an old Ameritech area in Ohio, pick up the phone, dial '0' and when the Operator comes on, say: "OBT-125, please read number on display." You'll get the NPA-NXX-XXXX read out to you and she'll tell you to have a good day. As of three years ago, you could call any of the embarq/sprint area operators in Ohio/Kentucky and just say, "ID Me." Phone phreaking is still alive, but, it…

What does 'OBT-125' signify/mean?

OBT stands for Ohio Bell Telephone, and "125" is the job/billing code for a line splicing/Frame/Switch person.

Re: Jb’s story about how he nearly lost his Twitter handle

#109
Had this exact experience happen to one of my coworkers.

We started embedding a secondary “password” in some of our email addresses, by leveraging googles username+tag feature. So something like johndoe@gmail.com becomes johndoe+1bayjdh1x91nj12e@gmail.com

One less piece of guessable info.

Re: Jb’s story about how he nearly lost his Twitter handle

#110
post #98

Earlier quoted context omitted.

Even if customers are scatterbrained and unwilling to accept responsibility for themselves, it's still better to keep them on board and making money than trying to teach them a lesson out of principle that probably won't even stick. How well any policies are actually thought through is another matter.

Yes, because users would hate so much to be told explicitly that all they need to remember is a password. They much rather have 20 different pieces of information, some combinations of which if they share, people can take over their accounts on various services. The problem is not so much that the systems suck, the problem is there's no way for people like me to take on the responsibility and "risk" of just having a…

It doesn't have to be a mess of ill-thought-out questions. Just a traditional password reset email is a good facility, as opposed to "forgotten password? your account is forever locked, you cretin. don't even think about contacting us".

I have a good backup system so it's not that I use such stuff personally either.

Post reply on HN