Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

101–110 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#101
post #90

Earlier quoted context omitted.

I'm a very casual and infrequent tweeter, and I can't fathom how that makes my username 'up for grabs'. Sorry you have such a twisted view of username ownership :/

While sympathetic - I'm also slightly amused at your twisted view about twitter name/account "ownership"… Just how much of the "real world" law you're alluding to by using the term "ownership" do you suppose applies to Twitter handles? (or Gmail addresses, or Facebook pages, or even domain names?)

The twitter namespace is property of Twitter alone. It's cute that there are those who think the "owners" of these names would be each user.

Re: How I Lost My $50,000 Twitter Username

#102
post #72
post #18

Who are people's current favorite domain registrars? I've been with name.com for the last year or so and have been happy, but I'm always curios to hear from others.

namesilo has extremely tight security and is very price competitive: * 2 factor authentication * 5 security Q/A's before you can make an account change! http://www.namesilo.com/Support/Domain-Defender there is no WAY this guy would have had an issue if he was with namesilo and had both protections enabled (I'm just a happy client and in no other way related to them)

> there is no WAY this guy would have had an issue if he was with namesilo and had both protections enabled

Except their customer support has a process to bypass those 5 security questions:

http://www.namesilo.com/Support/Forgot-Domain-Defender-Answe...

How can you be sure their customer support can't also be socially engineered? I'm actually hesitant to use a service which requires 5 security questions to make a change, because I bet so many people forget their answers that their support is lax when it comes to bypassing them.

Re: How I Lost My $50,000 Twitter Username

#103
post #50

My custom domain address was stolen with the Dropbox data leak, got so much spam that I set my Gmail to pull my mails via POP3. Then I changed everything to use my Gmail, and locked down my Gmail account. I've heard people go on about how Google (and I suppose other corporations) are evil, and how they are rolling their own custom mail solutions etc. It's times like these that people lose important things. Also, I re…

What do you mean by Dropbox data leak?

Re: How I Lost My $50,000 Twitter Username

#104
I lost a nice handle (@Houselogic) a few years back. Sent Twitter all the proof and email trail and everything, but they were useless. Every time I email their support, it's a new ticket and I have to explain the whole situation again and again. I gave up after two years.

Re: How I Lost My $50,000 Twitter Username

#105
post #76
post #70

Earlier quoted context omitted.

> A better analogy would be an owner of a valuable piece of property who wasn't putting it to good use. So if you were not putting your backyard to good use you would not feel too bad if your neighbors decided to encroach on it?

I think you're deliberately not hearing what I'm saying. Here's a good analogy: Some rich guy buys an amazing house on a beautiful California beachfront. But then never even bothers to stay there because he's got 3 other vacation homes. It just sits there empty all year long. Would it be ok for someone to break in and start living there? No, of course not. But you do have to kind of dislike that guy right? If he does…

> If he doesn't want to use this limited and valuable resource he should maybe give it up so someone else can get good use out of it.

You mean Communism?

Re: How I Lost My $50,000 Twitter Username

#106
post #99
post #37

Earlier quoted context omitted.

http://DNSimple.com for us. Their template system and support is fantastic.

I've heard good things about them from friends. This article was the last straw for me -- I just migrated my 90 domains off of GoDaddy. Actually, I didn't. I just told DNSimple to do all the work, via their (brilliant) concierge onboarding option: http://blog.dnsimple.com/2014/01/domain-transfer-concierge-s... "Here's my credit card and GoDaddy creds, guys, and here's a technical note about my DNS settings that I wan…

That does sound really good.

On the other hand, we're talking about security here, and, sadly, a company that has extra helpful support may be more easily socially engineered. The author's advice to use gmail.com addresses only works because Google basically has no customer support for gmail.com, so there's no one to social engineer!

Re: How I Lost My $50,000 Twitter Username

#109
post #76
post #70

Earlier quoted context omitted.

> A better analogy would be an owner of a valuable piece of property who wasn't putting it to good use. So if you were not putting your backyard to good use you would not feel too bad if your neighbors decided to encroach on it?

I think you're deliberately not hearing what I'm saying. Here's a good analogy: Some rich guy buys an amazing house on a beautiful California beachfront. But then never even bothers to stay there because he's got 3 other vacation homes. It just sits there empty all year long. Would it be ok for someone to break in and start living there? No, of course not. But you do have to kind of dislike that guy right? If he does…

If I own it, it's none of your or anyone else's business what I do with it. One should neither pass judgement on how I use it, why I use it, or if I use it, because it's mine (provided what I do with it isn't criminal in nature). Dislike != ok to take my shit.

Re: How I Lost My $50,000 Twitter Username

#110

Heads really ought to start rolling at PayPal. Their general approach to security is, quite frankly, appalling. Is there any possible rational for Paypal to give the last four digits of his card number to "him" over the phone? Given that they're routinely used for verification, it's as if they've never heard of social engineering. It's simply inexcusable. And it's almost as bad as the ridiculous "Log In Without Your…

The attacker was posing as a PayPal employee, not the card owner. Of course, PayPal still needs better security, but posing as an employee of the same company is a classic social engineering exploit.
Post reply on HN