Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

141–150 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#141
post #31

And we all know how this would end. GoDaddy and Paypal will try to make this right because of the negative publicity. Why does it always take a post like this to call for help?

GoDaddy and Paypal have every incentive to bury their shoddy security practices and deny everything that the OP is claiming, to avoid a PR disaster. They might quietly return to the issue later and perhaps address some of their security issues... maybe.

Re: How I Lost My $50,000 Twitter Username

#142
post #97
post #34

It's not a $50K Twitter username unless someone actually paid $50K for it at one point, is it? "Not accepting an offer of $50K for a twitter username I didn't use" doesn't really count...

It's worth what people are willing to pay for it. If people are willing to pay $50k then it is worth $50k. Of course it might have gone down in value since the offer.

That logic only works once an actual payment is made. Claiming you are willing to pay and actually paying are two very different things.

Re: How I Lost My $50,000 Twitter Username

#143
post #122
post #40

This is a scary story! Focusing on the Twitter handle sale part: I have the twitter handle @jetsetter, and have been offered multiple thousands of dollars for it (guess who!). Unfortunately, selling a twitter handle is against TOS. Only @israel has been officially allowed to transfer hands for money, that I'm aware of. So trying to broker the sale of a twitter account can allow the buyer to report your 'behavior' to…

If you're refering to this: http://www.theguardian.com/technology/2010/sep/14/twitter-us... at the bottom a twitter representative is quoted as saying that as long as they give you permission to sell/buy a handle they won't block/lock the account. Also apparently CNN also purchased a handle[1]. [1] http://www.businessinsider.com/cnn-acquires-cnnbrk-twitter-a...

I wrote in 2009 describing the situation and asked for approval. I was turned down. Reviewing the support ticket now, I think I could have handled the sale more professionally. Maybe that's why.

Re: How I Lost My $50,000 Twitter Username

#145

Earlier quoted context omitted.

The attacker was posing as a PayPal employee, not the card owner. Of course, PayPal still needs better security, but posing as an employee of the same company is a classic social engineering exploit.

And that part was never really answered either. How can he pose as an employee calling in from an outside line? Does PayPal not tell you when an extension from PayPal is calling you?

he was probably posing as an employee of the account holder, not paypal

Re: How I Lost My $50,000 Twitter Username

#146
post #13

Another reason to use Bitcoin. No credit card number to give away to the attacker and identity can be verified by signing a message with a private key instead of guessing at personal information.

Did you even bother to read the damn article or are you throwing blind shit on the wall here.

Re: How I Lost My $50,000 Twitter Username

#147
post #102
post #72

Earlier quoted context omitted.

namesilo has extremely tight security and is very price competitive: * 2 factor authentication * 5 security Q/A's before you can make an account change! http://www.namesilo.com/Support/Domain-Defender there is no WAY this guy would have had an issue if he was with namesilo and had both protections enabled (I'm just a happy client and in no other way related to them)

> there is no WAY this guy would have had an issue if he was with namesilo and had both protections enabled Except their customer support has a process to bypass those 5 security questions: http://www.namesilo.com/Support/Forgot-Domain-Defender-Answe... How can you be sure their customer support can't also be socially engineered? I'm actually hesitant to use a service which requires 5 security questions to make a cha…

Because they ask questions only the user would know about the account and its history:

We will need to ask you questions to verify your identity. These questions will be different based upon your account and history with us. Please understand that these verification steps are for your protection.

Re: How I Lost My $50,000 Twitter Username

#148

What was up with the part with the facebook message? Why would the attacker tip him off rather than just take what he came for? Or did I read that wrong?

Never underestimate the enticing nature of boasting. I can think of more than a few would be anonymous attackers who were caught precisely because they wanted to brag about their achievements.

I'm not really sure I understand the psychology behind it and whether it's a juvenile attempt to demonstrate relative power (e.g. "I did this to you, ergo I'm more powerful/smarter/whatever") or something else entirely.

Re: How I Lost My $50,000 Twitter Username

#149
post #52
post #39

Earlier quoted context omitted.

If someone had a Mercedes and only drove it twice a year, is it OK for someone to steal it?

No. But I'd feel less bad for that person than someone who drove their Mercedes every day and had it stolen. Also, a Mercedes and a twitter handle (or domain name) aren't exactly the same thing as a twitter handle is a unique owner of a particular pice of the namespace. A better analogy would be an owner of a valuable piece of property who wasn't putting it to good use.

Good analogy. Another one is email. If you used an email address for personal conversations and commercial transactions, that should not entitle you to keep the email address. You should give your email address to another person that wants it.

For example, I used one email for most of my life. But recently, I stopped using that email address, and have used another one due to wanting to boycott that company. Since I no longer use that email address, I should have to give the password to another person. This is just the right thing to do in all cases.

That would FREE UP a lot of email addresses. If you have any email addresses that you do not need, you are obligated to give your password to another person. If you don't, then they can't use email.

Just make sure that if you use that email to sign in to other websites using that email and password combination, go to all of those websites and notify your friends that you are giving your email to someone else and you are not the same person if you see future comments using that name.

Re: How I Lost My $50,000 Twitter Username

#150

An interesting point made was to avoid using custom domains for the login emails, since a DNS takeover would compromise your accounts tied to that email.

Yes. This seems like his final conclusion. Gave me something to think about.

Wild story coming out today because I was just setting up a couple domains/emails today on Google Apps. There's actually a section in the process in which they suggest setting the MX TTL to 1 Week.

Post reply on HN