Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

181–190 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#181
post #105
post #76

Earlier quoted context omitted.

I think you're deliberately not hearing what I'm saying. Here's a good analogy: Some rich guy buys an amazing house on a beautiful California beachfront. But then never even bothers to stay there because he's got 3 other vacation homes. It just sits there empty all year long. Would it be ok for someone to break in and start living there? No, of course not. But you do have to kind of dislike that guy right? If he does…

> If he doesn't want to use this limited and valuable resource he should maybe give it up so someone else can get good use out of it. You mean Communism?

Communism would be suggesting that the government should force him to give it up.

There's nothing wrong with advocating the concept of sharing when a person obviously has more resources than he could actually use.

Re: How I Lost My $50,000 Twitter Username

#182

Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy. [Edited to add] I would sure love to see a scarlet letter list of compan…

I actually think it was 4.

The attacked got the last 4 from Paypal and Godaddy asked him to guess two more digits.

Re: How I Lost My $50,000 Twitter Username

#183

> But guessing 2 digits correctly isn’t that easy, right? The first few digits of card numbers refer to the provider (Visa, Amex, etc) [0]. Given that Paypal gave the last four digits of the card, I'm surprised they wouldn't give out the provider as well, so guessing this would be even easier. [0] https://github.com/stripe/jquery.payment/blob/master/src/jqu...

It wasn't the first 2 digits that were guessed, it was the 2 digits prior to the final 4.

Re: How I Lost My $50,000 Twitter Username

#184
post #107
post #15

So who are you planning on suing? PayPal, godaddy, twitter, or all three?

The Terms of Service agreements for those companies probably all allow them to get away with it.

Terms of service normally don't override law. So, if there is something unlawful about their behavior, it doesn't matter what they wrote in their TOS. At least in many countries, not sure about US.

Re: How I Lost My $50,000 Twitter Username

#185

I feel bad for this guy, and twitter needs to do the right thing and return to him his handle. Then I can come back here and post nasty comments about squatters.

Any thoughts why the attacker would tell the guy how he did it if this is the obvious solution?

Re: How I Lost My $50,000 Twitter Username

#186

Earlier quoted context omitted.

I actually think it was 4.

GoDaddy requires 6 digits, but the agent let the attacker guess 2 of them (repeatedly, until he got it right). That's truly awful.

I thought everyone knew not to use GoDaddy after the SOPA incident. Hopefully this will convince more people to move their domains to a domain registrar that cares about its customers.

Re: How I Lost My $50,000 Twitter Username

#187
post #171

Reminds me of harvesting ICQ numbers. There was a time when you could search 6-digit ICQ numbers for expired freemail addresses like Hotmail (they deleted your account after a while), register that freemail address and reset your ICQ number password to get a brand "new" 6-digit number. I think this doesn't work anymore, since most freemail hosters don't "free" expired email addresses but keep them locked. It still wo…

Maybe I'm missing something, but who uses ICQ still? And why not focus on 3-digit numbers? There's a million 6-digit ICQ numbers; not that unique.

Re: How I Lost My $50,000 Twitter Username

#188
post #168

Everyone looks bad here, but I want to focus on Twitter. For me this case is yet another demonstration that Twitter sees its customers as advertisers and places low priority on the community. I pay Twitter nothing, and yet the service is valuable to me. So instead of continuously crippling the service in the name of goodness knows what, why not actually charge users for a premium experience. Things like customer serv…

Or look into alternatives in the microblogging space. What ever happened to Status.net/ostatus?

But the problem with alternatives is the fact that they're alternatives. Not what other people are using. If it's a social app, it's important.

Re: How I Lost My $50,000 Twitter Username

#189

Earlier quoted context omitted.

The attacker was posing as a PayPal employee, not the card owner. Of course, PayPal still needs better security, but posing as an employee of the same company is a classic social engineering exploit.

And that part was never really answered either. How can he pose as an employee calling in from an outside line? Does PayPal not tell you when an extension from PayPal is calling you?

Who cares what number the call was coming from. Security 101 for these phone techs should say something like "don't give out any information over the phone, even if the CEO calls and threatens to fire you if you don't." Or better yet, have much stricter protocols that deny the phone tech access to the information, so even if the caller threatens the tech personally, the information is safe.

Re: How I Lost My $50,000 Twitter Username

#190
I feel so bad for Naoki that he was compromised in this scary manner. While the hacker did con his way on the phone for personal information, at the minimum, it's...hmmm....not nice...but "informative/narcissistic," of the hacker to describe his method to the victim.

Makes me happy that companies are moving towards text authentication since emails are easy (or at least well practiced) to compromise.

Note: Time to change my Time To Lives on my MX records and up my security.

Post reply on HN