Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

381–390 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#381
post #129

Earlier quoted context omitted.

If you have a lot of domains (or willing to pay a premium), I am a huge fan of Fabulous.com. Good support, good pricing, my impression is fairly secure. They have an executive lock feature: Executive-lock (E-Lock) allows for the domain name to be frozen. This means that the domain name is: 1. Unable to be transferred out to another Registrar. 2. Unable to be pushed to another Fabulous account. 3. Unable to have chang…

Holy cow: "If your portfolio generates US$750 a month or you are willing to transfer 750+ domains to Fabulous, please complete the form below." That's a little out of my range though I'd be willing to pay a premium (how much of a premium?).

http://www.fabulous.com/informationcenter/index.htm?formcode...

They are focused on large portfolio customers. That's kind of the caveat for their service. Many of those large customers also use their other services like domain parking too.

Re: How I Lost My $50,000 Twitter Username

#382
I have seen great articles that document the best practices, patterns and anti-patterns for authentication within an application or storing passwords etc. But where is the gold standard for authenticating people over the phone?

Good Developers understand how critical it is to handle authentication and password storage well. It can be complicated thing and is very easy to screw up.

But all that goes out the window when somebody calls the support line. There needs to be just as much scrutiny placed on over the phone authentication as there is within an application. The problem is likely that those over the phone patterns/anti-patterns are not well documented and available.

Re: How I Lost My $50,000 Twitter Username

#383

Earlier quoted context omitted.

During my time working on websites for a retail company the imagery of the credit cards accepted were considered important. They would even be on pages that just mentioned taking payments before you get to the actual input page. One reasoning is that it is a sort of reassurance, much like the stickers you see on doors of retail locations that show which cards they accept. It's a reassurance in the idea that if you're…

All of what you say is true, but I was referring to a dropdown or radio button set for choice of card type, and not the card type images themselves, which I always included unless the client preferred otherwise -- something I don't remember ever happening, now I think back.

One simple solution that I like:

- You have a row of credit card icons. By default they are in full color.

- These icons react like buttons (hover shows clickability) and act like radio buttons if clicked -- all the others gray out.

- When a user starts typing a credit card number, it selects the appropriate icon if not already selected (graying out the others).

Because they aren't radio buttons (or a dropdown), it doesn't force people through the step, but because they can act like radio buttons (providing only visual feedback), they don't confuse anybody who thought they were supposed to be there.

The forms I've used that feel the most natural do something like this.

Re: How I Lost My $50,000 Twitter Username

#384
post #179

I feel bad for this guy, and twitter needs to do the right thing and return to him his handle. Then I can come back here and post nasty comments about squatters.

Yes, absolutely. The guy has given a clear and convincing story of what happened. I'm sure that it would be pretty easy for someone on Twitter's security team (assuming that they have one) to verify that the username was taken when he said it was. I don't know what I find more shocking -- that PayPal would actually give the last four digits of a credit-card number to a complete stranger, that GoDaddy would let someon…

https://www.paypal-forward.com/leadership/paypal-takes-your-...

Re: How I Lost My $50,000 Twitter Username

#385
post #134
post #54

Earlier quoted context omitted.

Oh it definitely doesn't make your username 'up for grabs'. What happened to you totally sucks and I hope you manage to get your account back. That being said if you're not actually going to use your account you might want to at least consider giving it to someone who would put it to more active use. Just a thought.

This COULD make sense. Are all other names taken up on twitter? Is it difficult to tweet without using the @N name? I never used twitter before.

Maybe google.com should have built their web site on kljasdklfjnaksdfn.com instead. That would have worked out just as well for them right? I haven't used the web very much.

Re: How I Lost My $50,000 Twitter Username

#386
post #165
post #160

Earlier quoted context omitted.

I tend to disagree: The right of ownership includes to right to use what you own in your own way.

The ownership of twitter namespace is Twitter's alone, not the user's

There's an agreement between Twitter and each user. And depending on the name used, Twitter users have own rights too, trade marks and of course domain names are examples.

Re: How I Lost My $50,000 Twitter Username

#387
post #193

Why would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy. [Edited to add] I would sure love to see a scarlet letter list of compan…

When a customer calls into the GoDaddy call center, they are supposed to provide a 4 digit pin in order to gain access to their account. I don't work in that department, but I'll forward the page to the CEO and make sure it gets read and addressed.

While you're at it, tell him to stop shooting elephants, donating money to Mitt Romney, decorating your web site with scantily clad women, and acting like a sexist pig.

Edit: I see you got a new CEO since I and so many other customers left in disgust about your company's support of SOPA and all those other issues. I'm sure you still have binders full of scantily clad women to decorate your booths at trade shows. Your company is permanently tainted, one of the worst examples of what's wrong with the computer industry, and I'm never coming back.

Re: How I Lost My $50,000 Twitter Username

#388
post #18

Who are people's current favorite domain registrars? I've been with name.com for the last year or so and have been happy, but I'm always curios to hear from others.

I like http://www.gandi.net/ Not the cheapest registar around, but great service, allows me to edit the zone file directly, and also sells dirt-cheap PaaS.

Re: How I Lost My $50,000 Twitter Username

#389
post #315

Earlier quoted context omitted.

In which case, once I return in the afternoon I will be entitled to shoot whomever is there for trying to steal my home. I'll be 'naturalisticaly' defending it. Sounds like a great way to run a society. I better make sure I have a bigger gun than the rest then. (edit-language)

Is shooting people your first go-to for defense? I prefer arguments and evidence presented to institutions who have both been given permission to shoot people and are willing to do it on my behalf pending their judgements of my arguments and evidence. Of course, if the institution's judgement is that people can take things that I'm not using at that exact moment, and it is not interested in intervening, then it's not…

He was talking in a 'naturalistic' way so I responded in kind. In reality if I found someone has stolen my home I'd call the authorities unless of course I feel a danger to my life in which case, had I not lived in the UK where guns are illegal, yes - shooting them would have been the first course of action. That is nothing to do with law or ethics, and lots to do with survival instinct.

Re: How I Lost My $50,000 Twitter Username

#390
post #276

Earlier quoted context omitted.

As in the attacker would be able to pop up and attack the original user of @N at will for what might very well be a vicious attempt to take over or destroy as much of his digital holdings as possible. The grandfather post is referencing asymmetric warfare[0] which would be a pretty decent name for what could happen. I don't think he just threw some cliches into a sentence. [0] http://en.wikipedia.org/wiki/Assymetrica…

Naoki has already made changes to prevent this type of attack from working again (e.g., removing credit cards from Paypal, moving his domains from GoDaddy, etc.)

Where there is a will there is a way. It's easier for an attacker for find a way in than it is for you to secure everything. The point is the attacker has the edge when the name of the game is, for lack of a better word, terrorism.
Post reply on HN