Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

221–230 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#221
post #105
post #76

Earlier quoted context omitted.

I think you're deliberately not hearing what I'm saying. Here's a good analogy: Some rich guy buys an amazing house on a beautiful California beachfront. But then never even bothers to stay there because he's got 3 other vacation homes. It just sits there empty all year long. Would it be ok for someone to break in and start living there? No, of course not. But you do have to kind of dislike that guy right? If he does…

> If he doesn't want to use this limited and valuable resource he should maybe give it up so someone else can get good use out of it. You mean Communism?

No! We aren't talking about every property ever. Not your backyard, not your car and not your water bottles. Valuable properties. Nobody cares about @d7a8df74a98d or www.fe5461d77vvc.com. We're talking about crumbling buildings near a national monument, or in the technology field, m.com or @N. Domain squatting is awful. Is it genuinely that unintuitive to you?!

And if seizing it is too "communist" for you, then enormous taxes should be close enough to socialism.

Re: How I Lost My $50,000 Twitter Username

#223
post #179

I feel bad for this guy, and twitter needs to do the right thing and return to him his handle. Then I can come back here and post nasty comments about squatters.

Yes, absolutely. The guy has given a clear and convincing story of what happened. I'm sure that it would be pretty easy for someone on Twitter's security team (assuming that they have one) to verify that the username was taken when he said it was. I don't know what I find more shocking -- that PayPal would actually give the last four digits of a credit-card number to a complete stranger, that GoDaddy would let someon…

Do you mean Godaddy and Paypal should apologize? I don't think twitter did anything wrong yet. They are just looking into what happened.

Re: How I Lost My $50,000 Twitter Username

#224
post #13

Another reason to use Bitcoin. No credit card number to give away to the attacker and identity can be verified by signing a message with a private key instead of guessing at personal information.

Did you even bother to read the damn article or are you throwing blind shit on the wall here.

I believe he read the article.

Re: How I Lost My $50,000 Twitter Username

#225
post #185

I feel bad for this guy, and twitter needs to do the right thing and return to him his handle. Then I can come back here and post nasty comments about squatters.

Any thoughts why the attacker would tell the guy how he did it if this is the obvious solution?

The attacker was hired and once he finished the job he had no reason to be mean to the guy or not help him to improve his security. Maybe he even is a security expert that was in need of a bit extra cash and picked up this job.

Re: How I Lost My $50,000 Twitter Username

#226
post #53

Earlier quoted context omitted.

Twitter's official policy is that an account becomes inactive after 6 months - at that point, they reserve the right to release the account (in practice they rarely do this, though - there isn't an automated job releasing inactive accounts or anything) https://support.twitter.com/articles/15362-inactive-account-... @N (now @N_is_stolen)'s last post was 4 months ago, so he is still technically considered an active use…

Activity doesn't require the creation of a tweet though. There are plenty of active accounts where the users just read.

Doesn't using Medium also coutn as accoutn activity?

Re: How I Lost My $50,000 Twitter Username

#227

Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy. [Edited to add] I would sure love to see a scarlet letter list of compan…

The reason for the 6 digits is probably linked to PCI DSS compliance where agents are allowed to view the first 2 and last 4 of stored card numbers.

The first digit of a credit card number identifies the type of company the issuer is, e.g. 1 is an airline, 3 is a travel agency, 4 and 5 are credit card companies, 7 is an oil company. The final digit is a checksum. Two things about this baffle me: 1) that websites feel the need to have a dropdown to identify what sort of card you have instead of just figuring it out and 2) why they need to ping it off the issuer's servers to detect you've entered an invalid number e.g. a typo.

Re: How I Lost My $50,000 Twitter Username

#228

Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy. [Edited to add] I would sure love to see a scarlet letter list of compan…

well, http://plaintextoffenders.com exists - someone should make creditcardoffenders.com .

Re: How I Lost My $50,000 Twitter Username

#229
post #206
post #59

Earlier quoted context omitted.

I'm consistently surprised at the number of complaints against GoDaddy. They are a horrible company! You get what you pay for...

Just a side note here, GoDaddy has been under new management for a little under two years. There's a lot internal changes happening specifically aimed at improving usability and infrastructure.

(I didn't know that). That's fine, but there are just SO many other companies that provide the same service...

Re: How I Lost My $50,000 Twitter Username

#230

I feel bad for this guy, and twitter needs to do the right thing and return to him his handle. Then I can come back here and post nasty comments about squatters.

Might piss off the attacker pretty bad, though. Not saying that's wrong, just that resulting shenanigans might be a little asymmetric.
Post reply on HN