Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

311–320 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#311
post #299
post #3

Why is anyone still using GoDaddy?

Why did someone not sell a Twitter username for $50k?

It's against Twitter's terms of service to sell usernames. Technically. Lots of people get away with it I'm sure.

https://support.twitter.com/articles/18311-the-twitter-rules

Abuse and Spam > Selling usernames: You may not buy or sell Twitter usernames.

Re: How I Lost My $50,000 Twitter Username

#312
post #76
post #70

Earlier quoted context omitted.

> A better analogy would be an owner of a valuable piece of property who wasn't putting it to good use. So if you were not putting your backyard to good use you would not feel too bad if your neighbors decided to encroach on it?

I think you're deliberately not hearing what I'm saying. Here's a good analogy: Some rich guy buys an amazing house on a beautiful California beachfront. But then never even bothers to stay there because he's got 3 other vacation homes. It just sits there empty all year long. Would it be ok for someone to break in and start living there? No, of course not. But you do have to kind of dislike that guy right? If he does…

What's funny about this discussion is that many states in the US have laws for this very purpose - known as Adverse Possession. If you occupy a piece of land unchallenged for a period of time (often long, like 10+ years), it becomes yours.

Re: How I Lost My $50,000 Twitter Username

#313

Earlier quoted context omitted.

well, http://plaintextoffenders.com exists - someone should make creditcardoffenders.com .

Kind of off topic but that site also shows sites that email users their password when they create the account. That does not necessarily mean they store it plain text. Though the kind of devs that would send the password in email are likely to store it in plain text, but it's not necessary.

It does mean that passwords aren't properly hashed. They may be encrypted, but that still leaves open the possibility for an engineer or attacker to have access to plain text passwords.

Re: How I Lost My $50,000 Twitter Username

#314

>Using my Google Apps email address with a custom domain feels nice but it has a chance of being stolen if the domain server is compromised. Sigh I use Google Apps exactly so that I have control over the domain and aren't subject to the good will of Google. I had never thought of this particular problem. Now I don't know what to do.

This really boils down to who is a better sysadmin-- you or the Google SREs. Choose reliable and paranoid providers that actually verify your identity before shenanigans and you can mitigate the entry vector.

Re: How I Lost My $50,000 Twitter Username

#315
post #274
post #260

Earlier quoted context omitted.

I'm not using my home tomorrow morning. Is it alright for just anyone to go in and take ownership of it?

In a naturalistic sense? Yes. You only have a "right" to anything you can defend.

In which case, once I return in the afternoon I will be entitled to shoot whomever is there for trying to steal my home. I'll be 'naturalisticaly' defending it. Sounds like a great way to run a society. I better make sure I have a bigger gun than the rest then. (edit-language)

Re: How I Lost My $50,000 Twitter Username

#316

That reminds me, a few months ago I had a weird Twitter experience. Someone gained access to my rarely used Twitter account @smartician and started posting spam. Somehow Twitter noticed, reset the password and notified me via email. I have no idea how that was possible.

This happened to a friend of mine too, and he even forgot he had a twitter account.

Re: How I Lost My $50,000 Twitter Username

#317

Earlier quoted context omitted.

Credit card #s and social security #s are not secure. But what should companies use instead? We're a long way from everyone having fingerprint scanners, and I'm sure there will be a way to break that too. Isn't the solution more around recovering from when the break-ins inevitably happen?

Fingerprint scanners sound worse than credit cards to me... Why would you want a password that you can't ever change and leave copies of everywhere you go?

Because fingerprints should be used as usernames, not passwords.

http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...

Re: How I Lost My $50,000 Twitter Username

#318

Interesting that GoDaddy does not keep an audit trail for account detail changes that might help detect malicious activity. I guess they'll rather lose customers and reputation than do this.

They don't have much to lose reputation-wise...

I am surprised anyone can take them seriously as a company after their Superbowl commercials.

Re: How I Lost My $50,000 Twitter Username

#320
Slightly OT, but someone registered a Twitter account with my primary e-mail address. I received a "Confirm your e-mail account" email with a link "Not My Account". That link brings me to a page that says "Sorry, that page doesn’t exist!".

There doesn't appear to be any way to contact Twitter about this.

Shortly after, I received a second email "Welcome to Twitter, "

Going to: https://support.twitter.com/forms/impersonation

..and selecting "Someone is using my email address without my permission." tells me to submit a general support ticket. That's fine except none of the general categories has anything to do with this problem and choosing "My issue is not in the list" simply redirects me immediately to the root support page. I submitted a ticket with a different topic and have not heard back from them in a week and expect I never will.

Post reply on HN