Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

251–260 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#251

I feel bad for this guy, and twitter needs to do the right thing and return to him his handle. Then I can come back here and post nasty comments about squatters.

Might piss off the attacker pretty bad, though. Not saying that's wrong, just that resulting shenanigans might be a little asymmetric.

"that resulting shenanigans might be a little asymmetric. " - What does this statement even mean? You should think before you just throw a load of cliches into a sentence.

Re: How I Lost My $50,000 Twitter Username

#252
post #18

Who are people's current favorite domain registrars? I've been with name.com for the last year or so and have been happy, but I'm always curios to hear from others.

INWX https://www.inwx.de/en They are knowledgable, helpful, competitive and they offer 2-factor-authentication.

Re: How I Lost My $50,000 Twitter Username

#253
This story is horrifying because PayPal was the enabler.

PayPal gave the attacker the last four digits of my credit card number over the phone

That person should lose their job if it is not PayPal policy.

I really hope by some small chance the person that did this gets some serious prison time, if not for this then anything else prior or down the road. Then maybe one of those mornings they wake up in prison they can ponder if it was all worth it.

Re: How I Lost My $50,000 Twitter Username

#255
post #223
post #179

Earlier quoted context omitted.

Yes, absolutely. The guy has given a clear and convincing story of what happened. I'm sure that it would be pretty easy for someone on Twitter's security team (assuming that they have one) to verify that the username was taken when he said it was. I don't know what I find more shocking -- that PayPal would actually give the last four digits of a credit-card number to a complete stranger, that GoDaddy would let someon…

Do you mean Godaddy and Paypal should apologize? I don't think twitter did anything wrong yet. They are just looking into what happened.

Yes, I meant that GoDaddy and PayPal should apologize.

Twitter should look into what happened in this specific case, and somehow (if the posting is right) return the username to its original owner.

But there does seem to be something terribly broken here if it's possible for someone to get another person's Twitter account, and for it to take a full investigation to get it back to the original owner. And for not having better procedures in place, I think that an apology wouldn't be unreasonable.

In general, it seems to me that demonstrating empathy for your customers is a pretty reasonable strategy. Even if they didn't do anything wrong, and before they have finished this investigation, they can show that they care about the people using their system.

I don't think that Twitter could go wrong by saying, "We now see that we need to make it harder for scammers to switch the ownership of a Twitter account, and are looking into how to do so without hurting our legitimate users."

Re: How I Lost My $50,000 Twitter Username

#256
post #253

This story is horrifying because PayPal was the enabler. PayPal gave the attacker the last four digits of my credit card number over the phone That person should lose their job if it is not PayPal policy. I really hope by some small chance the person that did this gets some serious prison time, if not for this then anything else prior or down the road. Then maybe one of those mornings they wake up in prison they can…

This wasn't paypal's fault. I mean entirely. The problem was with goDaddy. The last 4 digits of credit cards show's up everywhere. Check your receipts. Related question in stackexchange: http://security.stackexchange.com/questions/37758/safety-of-...

GoDaddy should not use the 4 last digits as a way to confirm identity, exactly for the reason I mentioned above

Re: How I Lost My $50,000 Twitter Username

#257
post #256
post #253

This story is horrifying because PayPal was the enabler. PayPal gave the attacker the last four digits of my credit card number over the phone That person should lose their job if it is not PayPal policy. I really hope by some small chance the person that did this gets some serious prison time, if not for this then anything else prior or down the road. Then maybe one of those mornings they wake up in prison they can…

This wasn't paypal's fault. I mean entirely. The problem was with goDaddy. The last 4 digits of credit cards show's up everywhere. Check your receipts. Related question in stackexchange: http://security.stackexchange.com/questions/37758/safety-of-... GoDaddy should not use the 4 last digits as a way to confirm identity, exactly for the reason I mentioned above

PayPal gives out info to someone completely unverified and it is not their fault?

It would be one thing if this was a spouse or someone intercepting their physical mail. It's not. It's someone out of the blue who called PayPal to get the last four of a complete stranger.

GoDaddy's verification is bad too but at least they had some kind of attempt.

Re: How I Lost My $50,000 Twitter Username

#258

Everyone looks bad here, but I want to focus on Twitter. For me this case is yet another demonstration that Twitter sees its customers as advertisers and places low priority on the community. I pay Twitter nothing, and yet the service is valuable to me. So instead of continuously crippling the service in the name of goodness knows what, why not actually charge users for a premium experience. Things like customer serv…

I constantly think this about free services. There are a lot of things I'd love to pay a small monthly fee for that would give me peace of mind that the company is actually going to try and do things in my best interests and not in the interests of it's real 'customers', the advertisers.

Just today I got a notification from Facebook saying that videos are going to play silently automatically in my feed on my phone, meaning that if I'm on mobile data, my cap will be used quicker. This is the kind of thing I'd like to be able to pay to avoid.

Re: How I Lost My $50,000 Twitter Username

#259
Crumbs, this makes interesting reading - clearly lots of failings by the companies involved here.

However. If someone were to steal a physical asset in order to extort something else out of me I would go immediately to the police. I'd have thought I'd do the same if the assets involved were digital.

I've no idea if a criminal offence was committed in what ever jurisdiction this happened. But I'd have thought extortion is illegal is many parts of the world?

Re: How I Lost My $50,000 Twitter Username

#260
post #160
post #140

Earlier quoted context omitted.

He's definitely a squatter. If you own something and you don't use it, you're a squatter. I own an old original Nintendo that I haven't used all year. That's why if someone comes into my house and takes it, it's my own fault.

I tend to disagree: The right of ownership includes to right to use what you own in your own way.

I'm not using my home tomorrow morning. Is it alright for just anyone to go in and take ownership of it?
Post reply on HN