How I Lost My $50,000 Twitter Username
281–290 of 394 posts
Re: How I Lost My $50,000 Twitter Username
#282Re: How I Lost My $50,000 Twitter Username
#283Earlier quoted context omitted.
And that part was never really answered either. How can he pose as an employee calling in from an outside line? Does PayPal not tell you when an extension from PayPal is calling you?
he was probably posing as an employee of the account holder, not paypal
Re: How I Lost My $50,000 Twitter Username
#284Earlier quoted context omitted.
I've heard really good things with gandi and hover. I myself use namecheap, cause well, it's decent service for its price.
I use Gandi (for hosting, domain and email) and Hover. Can't recommend them enough.
https://www.gandi.net/static/contracts/en/g2/pdf/MSA-1.0-EN....
Re: How I Lost My $50,000 Twitter Username
#285It's sad, but twitter's not transferring it back in a week's time gives me more confidence in twitter, not less. There isn't any evidence of the stealing of the domain names and the extortion available besides OP's copies of the email messages and information that GoDaddy won't provide. With the value twitter ID has, twitter shouldn't do anything without clear evidence. He might have been able to get it back if it wa…
Re: How I Lost My $50,000 Twitter Username
#286Who are people's current favorite domain registrars? I've been with name.com for the last year or so and have been happy, but I'm always curios to hear from others.
Namecheap [1] & IWantMyName [2] [2] http://namecheap.com [2] http://iwantmyname.com
Re: How I Lost My $50,000 Twitter Username
#287This story is horrifying because PayPal was the enabler. PayPal gave the attacker the last four digits of my credit card number over the phone That person should lose their job if it is not PayPal policy. I really hope by some small chance the person that did this gets some serious prison time, if not for this then anything else prior or down the road. Then maybe one of those mornings they wake up in prison they can…
This is a systemic fault of PayPal and firing a lowly phone-jockey will not solve that. There are computer system protections that were clearly not in place (the representative was able to see this data on the screen, rather than having to enter it blind and have it validated - or, if they did, they had infinite re-tries which is also bad. Three wrong attempts, and the account should be locked and have to be escalated) but there are also culture/training problems: Until otherwise satisfactorily proven, anyone calling must be assumed to be in bad faith when they call. A representative with this mindset would not let a caller start guessing the "password".
Re: How I Lost My $50,000 Twitter Username
#288Earlier quoted context omitted.
well, http://plaintextoffenders.com exists - someone should make creditcardoffenders.com .
Kind of off topic but that site also shows sites that email users their password when they create the account. That does not necessarily mean they store it plain text. Though the kind of devs that would send the password in email are likely to store it in plain text, but it's not necessary.
Re: How I Lost My $50,000 Twitter Username
#289Earlier quoted context omitted.
Do you mean Godaddy and Paypal should apologize? I don't think twitter did anything wrong yet. They are just looking into what happened.
Yes, I meant that GoDaddy and PayPal should apologize. Twitter should look into what happened in this specific case, and somehow (if the posting is right) return the username to its original owner. But there does seem to be something terribly broken here if it's possible for someone to get another person's Twitter account, and for it to take a full investigation to get it back to the original owner. And for not havin…
Re: How I Lost My $50,000 Twitter Username
#290Earlier quoted context omitted.
well, http://plaintextoffenders.com exists - someone should make creditcardoffenders.com .
Kind of off topic but that site also shows sites that email users their password when they create the account. That does not necessarily mean they store it plain text. Though the kind of devs that would send the password in email are likely to store it in plain text, but it's not necessary.