Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

321–330 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#321
post #185

I feel bad for this guy, and twitter needs to do the right thing and return to him his handle. Then I can come back here and post nasty comments about squatters.

Any thoughts why the attacker would tell the guy how he did it if this is the obvious solution?

Narcissism. Ooh look at how clever I am! I'm so smart! Please victim, will you validate my cleverness?

Re: How I Lost My $50,000 Twitter Username

#322
post #13

Another reason to use Bitcoin. No credit card number to give away to the attacker and identity can be verified by signing a message with a private key instead of guessing at personal information.

Did you even bother to read the damn article or are you throwing blind shit on the wall here.

Yes, did you? The Attacker got Paypal to give up the last 4 digits of the victim's credit card number. Then he called GoDaddy which allowed him to verify his identity by giving them the last 4 of his credit card number though the attacker said they would have let him guess multiple times.

If GoDaddy accepted Bitcoin PayPal wouldn't even be involved and GoDaddy instead of asking for information which is apparently easily pilfered could have requested the caller sign a message with their private key Bitcoin key corresponding to the public key from which they paid GoDaddy for the domain services to begin with.

Re: How I Lost My $50,000 Twitter Username

#323
this story reeks of fake to me.

what sane person doesn't call the FBI when an attacker blatantly commits fraud against them, admits to it, and then commits extortion based on the successful fraud? Furthermore, what kind of attacker explains how they attacked? Thats ludicrous.

this has got to be some kind of roundabout way of advertising for the various competitors of godaddy mentioned in the post.

Re: How I Lost My $50,000 Twitter Username

#324

Earlier quoted context omitted.

Did you even bother to read the damn article or are you throwing blind shit on the wall here.

Yes, did you? The Attacker got Paypal to give up the last 4 digits of the victim's credit card number. Then he called GoDaddy which allowed him to verify his identity by giving them the last 4 of his credit card number though the attacker said they would have let him guess multiple times. If GoDaddy accepted Bitcoin PayPal wouldn't even be involved and GoDaddy instead of asking for information which is apparently eas…

> If GoDaddy accepted Bitcoin PayPal wouldn't even be involved and GoDaddy instead of asking for information which is apparently easily pilfered could have requested the caller sign a message with their private key

If GoDaddy separated authentication of requests from payment information and had any of a wide number of different authentication methods, this wouldn't have been an issue, either. Using PayPal -- or accepting credit card payments by other means -- does not imply (or normally involve) using the last four digits of CC number as if it were a PIN for authentication. (In fact, since CC numbers are widely exposed information, doing so is insane -- especially the last four digits, which are frequently used without the rest as a reference to identify a credit card to the owner of the card in contexts like receipts where the information is expected to be particularly public.)

Payment methods are really largely irrelevant here, GoDaddy could easily have adopted an equally stupid and brain dead authentication method if they took bitcoin as payment.

Re: How I Lost My $50,000 Twitter Username

#325

Slightly OT, but someone registered a Twitter account with my primary e-mail address. I received a "Confirm your e-mail account" email with a link "Not My Account". That link brings me to a page that says "Sorry, that page doesn’t exist!". There doesn't appear to be any way to contact Twitter about this. Shortly after, I received a second email "Welcome to Twitter, " Going to: https://support.twitter.com/forms/impers…

Doesn't this mean your email account is compromised?

Re: How I Lost My $50,000 Twitter Username

#326
post #317

Earlier quoted context omitted.

Fingerprint scanners sound worse than credit cards to me... Why would you want a password that you can't ever change and leave copies of everywhere you go?

Because fingerprints should be used as usernames, not passwords. http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...

That's probably not a great idea for anything other than very secure systems where users aren't concerned with privacy, flexibility of identity or anonymity.

Re: How I Lost My $50,000 Twitter Username

#327
post #299

Earlier quoted context omitted.

Why did someone not sell a Twitter username for $50k?

It's against Twitter's terms of service to sell usernames. Technically. Lots of people get away with it I'm sure. https://support.twitter.com/articles/18311-the-twitter-rules Abuse and Spam > Selling usernames: You may not buy or sell Twitter usernames.

What happens if you do, surely it's caveat emptor?

The rules only say:

"If such permission is not granted, there is no (zero) market value or worth to this account."

If you walk away, cash in hand, are you liable for any punishment other than the banhammer from Twitter?

Re: How I Lost My $50,000 Twitter Username

#328
post #246
post #235

Earlier quoted context omitted.

Now there needs to be a browser plugin, which warns you when you are about to create an account on such a website.

That's an awesome idea!

The problem with services like that is that they aren't likely to be updated, if the company improve their measures.

You'd have to check in regularly to confirm this is still the way they do things.

Re: How I Lost My $50,000 Twitter Username

#329

Slightly OT, but someone registered a Twitter account with my primary e-mail address. I received a "Confirm your e-mail account" email with a link "Not My Account". That link brings me to a page that says "Sorry, that page doesn’t exist!". There doesn't appear to be any way to contact Twitter about this. Shortly after, I received a second email "Welcome to Twitter, " Going to: https://support.twitter.com/forms/impers…

Doesn't this mean your email account is compromised?

I doubt it. I have two factor auth set up on my email. Looking at the timestamps, the Welcome email was sent the same minute as the "Please confirm" email, so it's possible the Twitter account is not live and this was just an automatic welcome e-mail. Still, it would be nice if the "Not My Account" link actually worked properly or there was some way to contact support about it.

Re: How I Lost My $50,000 Twitter Username

#330

>Using my Google Apps email address with a custom domain feels nice but it has a chance of being stolen if the domain server is compromised. Sigh I use Google Apps exactly so that I have control over the domain and aren't subject to the good will of Google. I had never thought of this particular problem. Now I don't know what to do.

Yeah, I disagree with Naoki's conclusion. I'm pretty sure he just didn't have 2FA turned on with GoDaddy (which I understand - I didn't think to turn 2FA on with my provider until I read his story).

The admonition to use a @gmail.com address was annoying enough to me that I responded with a blog post: https://konklone.com/post/protect-your-domain-name-with-two-...

Post reply on HN