Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

201–210 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#201

Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy. [Edited to add] I would sure love to see a scarlet letter list of compan…

The reason for the 6 digits is probably linked to PCI DSS compliance where agents are allowed to view the first 2 and last 4 of stored card numbers.

Re: How I Lost My $50,000 Twitter Username

#202
post #185

I feel bad for this guy, and twitter needs to do the right thing and return to him his handle. Then I can come back here and post nasty comments about squatters.

Any thoughts why the attacker would tell the guy how he did it if this is the obvious solution?

An attempt to induce Stokholm Syndrome?

Re: How I Lost My $50,000 Twitter Username

#204
post #103
post #50

My custom domain address was stolen with the Dropbox data leak, got so much spam that I set my Gmail to pull my mails via POP3. Then I changed everything to use my Gmail, and locked down my Gmail account. I've heard people go on about how Google (and I suppose other corporations) are evil, and how they are rolling their own custom mail solutions etc. It's times like these that people lose important things. Also, I re…

What do you mean by Dropbox data leak?

A project document with e-mail addresses was retrieved through the account of a dropbox employee[1].

Some people noticed they got e-mail through unique non-disclosed e-mail addresses.

[1]: http://lifehacker.com/5930706/dropbox-confirms-user-email-le...

Re: How I Lost My $50,000 Twitter Username

#205
What I take away from this is that:

a) Two Factor should be mandatory and as soon as it is, any representative of the company MUST insist that a reset cannot be done over the phone. It should be highly suspicious if someone comes up and says "Hi, I lost my email account access AND my phone so could you please reset my password via phone now?"

b) If not Two Factor, the security questions should also be mandatory. No other "data" like past addresses or cc numbers should suffice to reset over the phone if the person doesn't know the answers to all security questions.

And, speaking of these questions, of course they should be stuff that you know and cannot be "guessed" by anyone who is able to read your facebook page or similar. Maybe even some non nonsensical thing like "Favorite Food" - "Horse Droppings". As long as you remember this, nobody should be able to "hack" that over the phone. Even if you go on and on on facebook about how you "could eat your way through a giant bowl of pasta you love it so much"

Re: How I Lost My $50,000 Twitter Username

#206
post #59

Ditch GoDaddy - They are a terrible company. Also considering closing my paypal account now.

I'm consistently surprised at the number of complaints against GoDaddy. They are a horrible company! You get what you pay for...

Just a side note here, GoDaddy has been under new management for a little under two years. There's a lot internal changes happening specifically aimed at improving usability and infrastructure.

Re: How I Lost My $50,000 Twitter Username

#207

Heads really ought to start rolling at PayPal. Their general approach to security is, quite frankly, appalling. Is there any possible rational for Paypal to give the last four digits of his card number to "him" over the phone? Given that they're routinely used for verification, it's as if they've never heard of social engineering. It's simply inexcusable. And it's almost as bad as the ridiculous "Log In Without Your…

Ironically, PayPal's core business _is_ security.

The founder's interview [1] describe the beginning as a constant race against fraud, which no other bank was willing to compete in: "You're going to go bankrupt when the chargebacks start".

The was a locked room with a screen-and-keyboard-only computer where you could research about transactions and find suspicious and fraudulent ones. According to the founder, it became PayPal's core asset.

[1] in the book Founders At Work, which I recommend.

Re: How I Lost My $50,000 Twitter Username

#210
post #191

Earlier quoted context omitted.

I thought everyone knew not to use GoDaddy after the SOPA incident. Hopefully this will convince more people to move their domains to a domain registrar that cares about its customers.

SOPA was from one person (in-house counsel) and was not and is not the sentiment of c-level management or any employees I've ever talked to.

totally off-topic, but because of the SOPA nonsense I've slowly moved my 40-or-so domains to namecheap during 2013 when their renewals came up. I was otherwise ambivalent about which DNS service/registrar to use before that incident...

but thank you for helping the guy get his twitter account back and fixing up the internal controls.

Post reply on HN