Live data from Hacker News

Finding vulnerable Twitter accounts with expired domains

zainamro.com

41–50 of 128 posts

Re: Finding vulnerable Twitter accounts with expired domains

#42
post #23

What would be a universal solution to this problem? The only thing I can really think of is platforms not allowing custom domains for connected email accounts, but that seems sub-optimal.

Instead of blocking custom domain email addresses outright, the site could require a secondary recovery email address from an approved provider when an email with a custom domain is used to create the account. Then any security interaction like password reset, or 2fa would go to the primary address and would send an alert to the secondary email address about the nature of the communication. There could be a link in t…

> Instead of blocking custom domain email addresses outright, the site could require a secondary recovery email address from an approved provider when an email with a custom domain is used to create the account.

Great, if we do this, we've done to e-mail addresses (and domains) what we've done to phone numbers. Some phone numbers, because of the carrier serving them, are "less than" others out of some (mistaken) idea that it's easier to get a bulk-load of phone numbers from some kinds of carriers and not others.

And then, what do you do when a new provider wants to join the scene? It already takes a year of process and documentation for a new certificate authority to get into most browsers and even then the adoption will be years in the making because most devices don't get root certificate updates. What's the process like for e-mail in your hypothetical? Does Hey.com not even bother because getting buy-off from even the top 50 account-based web sites takes forever?

> Good practice for users in general is to use email services like gmail as thier login/account email and add thier custom domain emails in thier bio.

Absolutely not. The entire point for using my own domain is so my identity is not irrevocably tied to Google. When Google can, and does, nuke my account from orbit on a whim due to some perceived slight, I have no recourse. I can't even sue because of the mandatory arbitration clause they slapped in their several-thousand-word terms of service.

Re: Finding vulnerable Twitter accounts with expired domains

#43
My wife and I started up a small reselling business, based on our name. The dotcom for it was previously owned, but they let the domain lapse, but they still have the Twitter account (that has the web address we now own in their profile; they haven't posted since 2016). I tried an approach similar to the article, but they apparently used Gmail to set it up. (I reached out to them to buy it to no response; I assume that Twitter account has been orphaned)

Re: Finding vulnerable Twitter accounts with expired domains

#45

My wife and I started up a small reselling business, based on our name. The dotcom for it was previously owned, but they let the domain lapse, but they still have the Twitter account (that has the web address we now own in their profile; they haven't posted since 2016). I tried an approach similar to the article, but they apparently used Gmail to set it up. (I reached out to them to buy it to no response; I assume th…

time to add an underscore to the name

Re: Finding vulnerable Twitter accounts with expired domains

#46
This domain hijacking idea reminds me of an incident with Google I discovered a couple of years ago that landed me a bug bounty with them. I found out they created email logins with a not-registered domain for their candidacy account. I ended up registering that domain and "sold" it back to them in good faith. At least I can die with a smile on my face -- I once sold Google a domain.

details: http://www.tnhh.net/posts/gcandidate-who-is-interviewing-wit...

Re: Finding vulnerable Twitter accounts with expired domains

#47
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

At minimum register a domain and email forward the wildcard address for it to your daily driver. Use this for important things and don't forget to renew.

Edit: you can do all this on namecheap pretty easily.

Re: Finding vulnerable Twitter accounts with expired domains

#48
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

"assume that a public key cryptosystem exists"

Re: Finding vulnerable Twitter accounts with expired domains

#49
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

You point out some problems, but how do we actually do these? Without emails as the keys to the kingdom, what would you use? Without a global identifier for a human person (like social security in the US), how would we declare that an identity is compromised? While I believe your ideals are well-intentioned, I think they're impractical in our current society. I would propose that an email is the key to the kingdom, t…

I would suggest having a bank or similarly regulated institution manage identity recovery. They can declare a login invalid, and they can go through the process of KYC (drivers license, SSN, in-person visit, etc) to get you a new identity.

Think Facebook login except instead of tab unrestricted entity that steals every piece of dignity it gets its hands on, its a bank or legal custodian with strict responsibilities, penalties, and insurance in case of identity theft.

Re: Finding vulnerable Twitter accounts with expired domains

#50
post #29

Earlier quoted context omitted.

This is a solved problem in many other countries. Instead of proposing some new solution maybe it would be better to copy an existing which has already proven to work.

Without sharing examples, this is effectively a non-answer. Thanks for the comment.

In Sweden, BankID covers well over 90% of the population between ages 20 and 60 with a unique electronic ID. (Including 98% of those between 20 and 40.) It supports identifying yourself with a credit card and pin using a card reader given to you by your bank or alternatively (and more commonly) a pin combined with a smartphone/computer that you have identified as being yours.
Post reply on HN