Live data from Hacker News

How I Lost My $50,000 Twitter Username

medium.com

41–50 of 394 posts

Re: How I Lost My $50,000 Twitter Username

#41
post #18

Who are people's current favorite domain registrars? I've been with name.com for the last year or so and have been happy, but I'm always curios to hear from others.

I've heard really good things with gandi and hover. I myself use namecheap, cause well, it's decent service for its price.

I use Gandi (for hosting, domain and email) and Hover. Can't recommend them enough.

Re: How I Lost My $50,000 Twitter Username

#42
One thing that people should realize in why Twitter may not respond to these kinds of issues, or may be slow to respond, is that it's probably true that lots of people buy and sell Twitter accounts, and people may report them stolen when in fact they've already sold them to someone.

This kind of thing happened a lot in MMO games which is why they try to push account security into your hands so they don't have to attempt to arbitrate in deals that may or may not have happened outside of their sphere of control.

Re: How I Lost My $50,000 Twitter Username

#43
post #21

Seems like Twitter could easily verify the story based on their own logs and then restore access to his N account. He doesn't mention pursuing that, though.

He said he wasn't using it much. Thus, isn't he basically a squatter?

Twitter's official policy is that an account becomes inactive after 6 months - at that point, they reserve the right to release the account (in practice they rarely do this, though - there isn't an automated job releasing inactive accounts or anything)

https://support.twitter.com/articles/15362-inactive-account-...

@N (now @N_is_stolen)'s last post was 4 months ago, so he is still technically considered an active user.

Re: How I Lost My $50,000 Twitter Username

#44
post #5

If the author is reading, did you end up getting back your @n username? If so, did you simply go to Twitter and explain to them the whole story?

Nope. A week ago when I explained the situation, Twitter seemed to think I just gave it up, willingly or not.

Re: How I Lost My $50,000 Twitter Username

#45
post #6

Wow, this is both interesting and terrifying. I have a two character Twitter handle that I use actively and it makes me worry that one day I might be targeted too using a similar method, although so far I've had no problems.

I have a two character twitter handle also, and am active on it. Used to receive several "reset" emails per day before two-factor authentication.

Re: How I Lost My $50,000 Twitter Username

#46
Heads really ought to start rolling at PayPal. Their general approach to security is, quite frankly, appalling.

Is there any possible rational for Paypal to give the last four digits of his card number to "him" over the phone? Given that they're routinely used for verification, it's as if they've never heard of social engineering. It's simply inexcusable.

And it's almost as bad as the ridiculous "Log In Without Your PayPal Security Key" option that lets you bypass 2-factor auth and head straight to the ultra-secure world of the ridiculous security questions such as the ever-popular "what city were you born [that's also listed on Facebook]" and what not. I still can't believe they think that's a good idea.

Re: How I Lost My $50,000 Twitter Username

#47
post #25
post #21

Earlier quoted context omitted.

He said he wasn't using it much. Thus, isn't he basically a squatter?

Ya, the fact that he tweeted a grand total of twice in 2013 (see https://twitter.com/N_is_stolen ) makes me have a little less sympathy.

So if I don't really use my $50k collection car, it's as bad if it gets stolen?

Re: How I Lost My $50,000 Twitter Username

#50
My custom domain address was stolen with the Dropbox data leak, got so much spam that I set my Gmail to pull my mails via POP3. Then I changed everything to use my Gmail, and locked down my Gmail account.

I've heard people go on about how Google (and I suppose other corporations) are evil, and how they are rolling their own custom mail solutions etc. It's times like these that people lose important things.

Also, I really don't understand why US companies must store credit card details. I understand the convenience, but there's been a lot of security compromises to let this practice continue. In South Africa online retailers don't store CC info, yet we aren't being brought to our knees by inconvenience.

At least the attacker mentioned his methods, so GoDaddy and PayPal can educate their staff better.

Post reply on HN