Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

261–270 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#261

An interesting point made was to avoid using custom domains for the login emails, since a DNS takeover would compromise your accounts tied to that email.

An interesting point made was to avoid using custom domains for the login emails

That's horrible advice. That sort of attitude taken to the extreme means we shouldn't be using DNS for anything ourselves and put everything in Google's (or Amazon's) big bag.

Should I redirect my customers to facebook.com/company as well in fear of someone taking over my DNS?

The lesson from this whole charade is to not trust something as crucial your DNS to untrustworthy companies like Godaddy. We've heard the horror stories before and we keep on hearing them again.

Relying on Google, a company with no direct end-user support and no emergency hotline to secure the most important thing you have, DNS, is even bigger madness. I've been locked out from a Gmail account before. It took me weeks to get it back, because Google has no support.

So yeah. Get a proper DNS-provider, and don't dig yourself deeper into the hellhole you're currently setting up.

Re: How I Lost My $50,000 Twitter Username

#262
post #192

One thing that people should realize in why Twitter may not respond to these kinds of issues, or may be slow to respond, is that it's probably true that lots of people buy and sell Twitter accounts, and people may report them stolen when in fact they've already sold them to someone. This kind of thing happened a lot in MMO games which is why they try to push account security into your hands so they don't have to atte…

So what? If Twitter returned control of a handle if someone could prove that they had recently controlled the handle, that would quickly make the handles market dry up.

Twitter has no interest in there being a handles market. In fact, I wouldn't be surprised if their T&Cs expressly forbids it.

Re: How I Lost My $50,000 Twitter Username

#263
post #185

Earlier quoted context omitted.

Any thoughts why the attacker would tell the guy how he did it if this is the obvious solution?

I guess it's that "security researcher god complex" many security people show. They come around, fuck up your daily routine and expect you to be thankful for making your day hell.

This is correct. "Let me explain to you how smart I am"

Re: How I Lost My $50,000 Twitter Username

#265
post #19

what's more likely, someone hacks your domain name / DNS gaining control of your MX records or someone hacks your username @gmail.com?

possibly depends on whether you are using 2-factor auth with gmail.

Just Google's notification "why are you suddenly using your accounts from a different country" can be life-saving.

(As well as not putting any important stuff there)

Re: How I Lost My $50,000 Twitter Username

#266
post #194

Earlier quoted context omitted.

The problem is stealing @N is, someone will have to use it one day. How can they hope not to be traced?

The hacker sells it anonymously to someone who isn't aware of the controversy or who doesn't care. It will probably shrink the value of the username but I bet it's still worth something.

Selling is prohibited by the TOS, so if the buyer does their due diligence they know what risk they're taking

Re: How I Lost My $50,000 Twitter Username

#267
It doesn’t even take that much. Twitter simply took @mattness from me – without notifying me – because they claimed it was unused. That was a few weeks before I was ready to launch my redesigned website…

I wrote to twitter support and they basically told me that well, it didn’t look like the account in question had my email address on it.

Unregulated centralized name registries are not a good thing.

Re: How I Lost My $50,000 Twitter Username

#268
post #76
post #70

Earlier quoted context omitted.

> A better analogy would be an owner of a valuable piece of property who wasn't putting it to good use. So if you were not putting your backyard to good use you would not feel too bad if your neighbors decided to encroach on it?

I think you're deliberately not hearing what I'm saying. Here's a good analogy: Some rich guy buys an amazing house on a beautiful California beachfront. But then never even bothers to stay there because he's got 3 other vacation homes. It just sits there empty all year long. Would it be ok for someone to break in and start living there? No, of course not. But you do have to kind of dislike that guy right? If he does…

I am trying to understand what you are saying.

I understand that you have not said that the situation the OP faced is deserved, but you don't feel too bad about it.

Unfortunately your defense does make it seem that you are not completely opposed to a framework that would take back "limited resources" not being used well. Most likely this is not your intention at all.

I often come across businesses/store locations and most importantly domain names that are not using even a small fraction of true potential. I do feel sorry for them, but I can't say I dislike them, they might dislike themselves if they knew what I knew.

The only way I can fathom the minutest possibility of disliking them is if they knew how to thrive and did not do anything, if it was common knowledge on how to do it right, but they chose not too.

Unfortunately most people don't know how to use potential or don't recognize it at all, can't dislike them for trying though.

Re: How I Lost My $50,000 Twitter Username

#269
post #3

Why is anyone still using GoDaddy?

Payment channel option is one reason. Linode/DigitalOcean for example are not available in India, due to restrictions on Debit Cards of Indian users. Credit cards are very uncommon here, compared to Debit Cards. Btw, I personally use Bigrock instead. They have a very a good customer support. http://rikacomet.blogspot.in/2013/12/quick-comparison-betwee...

I have been using a debit card (Visa Electron) for both Linode and DigitalOcean. Works fine.

Re: How I Lost My $50,000 Twitter Username

#270

Earlier quoted context omitted.

I actually think it was 4.

The attacked got the last 4 from Paypal and Godaddy asked him to guess two more digits.

Guess from a fairly limited set as well, it wasn't all numbers 00-99.

http://en.wikipedia.org/wiki/List_of_Issuer_Identification_N...

Post reply on HN