Anyone else have people sign up for accounts with your email address? I had one recently where I could access a working GrubHub account for a while. And in the spirit of lame on-boarding optimization and “churn” prevention, while I could have used it - I couldn’t cancel the account. That required the phone number associated.
Finding vulnerable Twitter accounts with expired domains
31–40 of 128 posts
Re: Finding vulnerable Twitter accounts with expired domains
#32Re: Finding vulnerable Twitter accounts with expired domains
#33Even though they show the starred email address and one of the suggestions is not to show the email, I really hope people don't do that. There is nothing more frustrating when you're recovering your password and the site says we have sent you an email with no hint where and even worse sometimes they say "if that email was in our records then you should get the link" and you're wondering did that work and #1 worst is…
I don’t think you having to either A) remember what email you used or B) creating a new account is a big ask when the alternative is leaking your account presence on a given system. Not everyone wants other people to be able to essentially query a given app for an email account.
Re: Finding vulnerable Twitter accounts with expired domains
#34Re: Finding vulnerable Twitter accounts with expired domains
#35Earlier quoted context omitted.
You point out some problems, but how do we actually do these? Without emails as the keys to the kingdom, what would you use? Without a global identifier for a human person (like social security in the US), how would we declare that an identity is compromised? While I believe your ideals are well-intentioned, I think they're impractical in our current society. I would propose that an email is the key to the kingdom, t…
There's a difference between an email address and a social security number in a way that the latter will still be around if you stop paying for it or something happens to you. In some way (at least for this threat model) a gmail address is better than one on your own domain as it's unlikely to go away or get taken over.
I use my own domain on my own server with my own running mail server. Why should someone take that over?
Of course someone with state level hacking experience could do that, but I am not a target for those. Script kiddies have no luck, because you can't even login from the Internet into my server you will need to VPN into first.
Re: Finding vulnerable Twitter accounts with expired domains
#36But when I click Forgot Password, it asks me for my username and also the email address before I can continue.
How do you get the email address hint like the article shows?
Re: Finding vulnerable Twitter accounts with expired domains
#37One has to wonder about sustaining access to a compromised account. Twitter in my experience has been very aggressive in asking to verify my account with a phone number when logging in from shady locations / with a VPN. What if you get access to an account using the method described in the article, but then days later get locked out due to suspicious-looking behavior / you don't have access to the phone number used t…
Re: Finding vulnerable Twitter accounts with expired domains
#38Earlier quoted context omitted.
There's a difference between an email address and a social security number in a way that the latter will still be around if you stop paying for it or something happens to you. In some way (at least for this threat model) a gmail address is better than one on your own domain as it's unlikely to go away or get taken over.
Why should my own domain taken over. It can be taken over as easily as someone could take over my gmail. I use my own domain on my own server with my own running mail server. Why should someone take that over? Of course someone with state level hacking experience could do that, but I am not a target for those. Script kiddies have no luck, because you can't even login from the Internet into my server you will need to…
Re: Finding vulnerable Twitter accounts with expired domains
#39Earlier quoted context omitted.
There's a difference between an email address and a social security number in a way that the latter will still be around if you stop paying for it or something happens to you. In some way (at least for this threat model) a gmail address is better than one on your own domain as it's unlikely to go away or get taken over.
You can get locked from Gmail if Google decides to suspend your Account. It has already happened to lots of users, even G Suite ones and good luck trying to get it back. Examples on HN: https://news.ycombinator.com/item?id=22146082 https://news.ycombinator.com/item?id=22705122 https://news.ycombinator.com/item?id=4013799
Re: Finding vulnerable Twitter accounts with expired domains
#40At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…