Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

281–290 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#283

Earlier quoted context omitted.

And that part was never really answered either. How can he pose as an employee calling in from an outside line? Does PayPal not tell you when an extension from PayPal is calling you?

he was probably posing as an employee of the account holder, not paypal

Ohh, good point. I never thought of that. I assumed employee of Twitter as well.

Re: How I Lost My $50,000 Twitter Username

#284
post #41

Earlier quoted context omitted.

I've heard really good things with gandi and hover. I myself use namecheap, cause well, it's decent service for its price.

I use Gandi (for hosting, domain and email) and Hover. Can't recommend them enough.

Gandi's pretty good, except they have strange terms of service : "By accepting Our Contracts and using Our Services, You agree to abide to Our code of ethics which consists, in particular, of protecting and respecting minors, human dignity, public order and good moral standards [...]"

https://www.gandi.net/static/contracts/en/g2/pdf/MSA-1.0-EN....

Re: How I Lost My $50,000 Twitter Username

#285

It's sad, but twitter's not transferring it back in a week's time gives me more confidence in twitter, not less. There isn't any evidence of the stealing of the domain names and the extortion available besides OP's copies of the email messages and information that GoDaddy won't provide. With the value twitter ID has, twitter shouldn't do anything without clear evidence. He might have been able to get it back if it wa…

I was thinking how witty that would be if THIS was the actually hacker, and he was using us to create a shitstorm in order to rush Twitter into giving him the account. I'm sure there is sufficient data to support that he was the original owner though.

Re: How I Lost My $50,000 Twitter Username

#286
post #18

Who are people's current favorite domain registrars? I've been with name.com for the last year or so and have been happy, but I'm always curios to hear from others.

Namecheap [1] & IWantMyName [2] [2] http://namecheap.com [2] http://iwantmyname.com

+1 for Namecheap, I have 2 (going on 3 soon) domains with them and I've never had a problem. They also have a coupon code for pretty much anything you want to purchase for them.

Re: How I Lost My $50,000 Twitter Username

#287
post #253

This story is horrifying because PayPal was the enabler. PayPal gave the attacker the last four digits of my credit card number over the phone That person should lose their job if it is not PayPal policy. I really hope by some small chance the person that did this gets some serious prison time, if not for this then anything else prior or down the road. Then maybe one of those mornings they wake up in prison they can…

It's possible that this was gross negligence on part of the employee and that the thief just got really, really lucky - but that seems unlikely.

This is a systemic fault of PayPal and firing a lowly phone-jockey will not solve that. There are computer system protections that were clearly not in place (the representative was able to see this data on the screen, rather than having to enter it blind and have it validated - or, if they did, they had infinite re-tries which is also bad. Three wrong attempts, and the account should be locked and have to be escalated) but there are also culture/training problems: Until otherwise satisfactorily proven, anyone calling must be assumed to be in bad faith when they call. A representative with this mindset would not let a caller start guessing the "password".

Re: How I Lost My $50,000 Twitter Username

#288

Earlier quoted context omitted.

well, http://plaintextoffenders.com exists - someone should make creditcardoffenders.com .

Kind of off topic but that site also shows sites that email users their password when they create the account. That does not necessarily mean they store it plain text. Though the kind of devs that would send the password in email are likely to store it in plain text, but it's not necessary.

If you send the password in email, that's at least one instance where it was readable in clear text to everyone on the network between you and the server (and probably things like packet sniffers on the local network, right?). It's not as bad as storing it in the clear, but it removes some of the value of (e.g.) hosting a login page via SSL.

Re: How I Lost My $50,000 Twitter Username

#289
post #255
post #223

Earlier quoted context omitted.

Do you mean Godaddy and Paypal should apologize? I don't think twitter did anything wrong yet. They are just looking into what happened.

Yes, I meant that GoDaddy and PayPal should apologize. Twitter should look into what happened in this specific case, and somehow (if the posting is right) return the username to its original owner. But there does seem to be something terribly broken here if it's possible for someone to get another person's Twitter account, and for it to take a full investigation to get it back to the original owner. And for not havin…

The Twitter account wasn't actually compromised. The guy was blackmailed to hand it over. It would be pretty nice of Twitter to hand it back, but it's really hard to fault them, and it's especially hard to fault them for not just reassigning the account without a very careful investigation - what if the writer of this article is actually the guy trying to steal the account from someone else, using this article to bully Twitter into a swift response?

Re: How I Lost My $50,000 Twitter Username

#290

Earlier quoted context omitted.

well, http://plaintextoffenders.com exists - someone should make creditcardoffenders.com .

Kind of off topic but that site also shows sites that email users their password when they create the account. That does not necessarily mean they store it plain text. Though the kind of devs that would send the password in email are likely to store it in plain text, but it's not necessary.

Shouldn't email plaintext passwords, ever. Email is not a secure way of communication. Users wouldn't delete their email. Admins can read their email from the server.
Post reply on HN