Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

301–310 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#302

Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy. [Edited to add] I would sure love to see a scarlet letter list of compan…

Credit card #s and social security #s are not secure. But what should companies use instead? We're a long way from everyone having fingerprint scanners, and I'm sure there will be a way to break that too. Isn't the solution more around recovering from when the break-ins inevitably happen?

Fingerprint scanners sound worse than credit cards to me... Why would you want a password that you can't ever change and leave copies of everywhere you go?

Re: How I Lost My $50,000 Twitter Username

#303
post #227

Earlier quoted context omitted.

The first digit of a credit card number identifies the type of company the issuer is, e.g. 1 is an airline, 3 is a travel agency, 4 and 5 are credit card companies, 7 is an oil company. The final digit is a checksum. Two things about this baffle me: 1) that websites feel the need to have a dropdown to identify what sort of card you have instead of just figuring it out and 2) why they need to ping it off the issuer's…

I agree- there's no need to get people to choose the type of card however for 2), that's not always the case. Pretty much all cards can be validated with the Luhn algorithm in js. See http://stackoverflow.com/questions/20725761/validate-credit-...

The card number can be validated, that doesn't make it a valid card. You still have to ask the issuing bank whether the card is an active account, whether it has the funds for the purchase, etc

Re: How I Lost My $50,000 Twitter Username

#304
post #149
post #52

Earlier quoted context omitted.

No. But I'd feel less bad for that person than someone who drove their Mercedes every day and had it stolen. Also, a Mercedes and a twitter handle (or domain name) aren't exactly the same thing as a twitter handle is a unique owner of a particular pice of the namespace. A better analogy would be an owner of a valuable piece of property who wasn't putting it to good use.

Good analogy. Another one is email. If you used an email address for personal conversations and commercial transactions, that should not entitle you to keep the email address. You should give your email address to another person that wants it. For example, I used one email for most of my life. But recently, I stopped using that email address, and have used another one due to wanting to boycott that company. Since I n…

Some email providers actually already free up dormant email addresses for the public to register again. This poses a problem for exactly the reasons you described. I believe hotmail does, for example.

Re: How I Lost My $50,000 Twitter Username

#305
>Using my Google Apps email address with a custom domain feels nice but it has a chance of being stolen if the domain server is compromised.

Sigh I use Google Apps exactly so that I have control over the domain and aren't subject to the good will of Google. I had never thought of this particular problem. Now I don't know what to do.

Re: How I Lost My $50,000 Twitter Username

#307
post #294

Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy. [Edited to add] I would sure love to see a scarlet letter list of compan…

Does Go Daddy require recurring payments or can you pay for a couple years up front? If so you could have generated a one time card number OR had been issued a new card since you paid you you might not even know your card number. How would this even work for everyone? https://www.namecheap.com/ accepts bitcoin as payment to avoid this situation.

You can pay up to 20 years in advance on a domain with GoDaddy if I recall.

Re: How I Lost My $50,000 Twitter Username

#308
post #205

What I take away from this is that: a) Two Factor should be mandatory and as soon as it is, any representative of the company MUST insist that a reset cannot be done over the phone. It should be highly suspicious if someone comes up and says "Hi, I lost my email account access AND my phone so could you please reset my password via phone now?" b) If not Two Factor, the security questions should also be mandatory. No o…

>As long as you remember this

I would NEVER remember this. EVER.

Re: How I Lost My $50,000 Twitter Username

#309
post #18

Who are people's current favorite domain registrars? I've been with name.com for the last year or so and have been happy, but I'm always curios to hear from others.

My friends run sliqua.com, so I go through them. I haven't had any issues with them, their support is pretty good, and the price is good. I would definitely recommend them to other people.
Post reply on HN