Live data from Hacker News

Finding vulnerable Twitter accounts with expired domains

zainamro.com

51–60 of 128 posts

Re: Finding vulnerable Twitter accounts with expired domains

#51
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

There are other aspects here.

If you use a third party service for your email ID, the third party can ban you or like you mention - disappear and basically take your identity away.

If you rely on national ID cards, you have another set of problems.

If you rely on phone numbers, these can be sim-jacked.

If you rely on bio-authentication methods, you risk your privacy especially when the master database gets compromised.

Relying on any single source seems to be a recipe for disaster. Perhaps the solution is to have multiple ways to authenticate yourself, with different levels of credibility and to let as many of them survive as possible. Phone numbers and email IDs seem to have similar levels of credibility, but I haven't seen domain name service providers take to phone number authentication as much as I would have liked, but things are looking up. Alternatives could be backup codes, which some registrar's use if you have 2fa enabled.

Re: Finding vulnerable Twitter accounts with expired domains

#52
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

"assume that a public key cryptosystem exists"

Some organisation will try to own it and then users will be at the risk of getting banned and losing themselves.

Re: Finding vulnerable Twitter accounts with expired domains

#53
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

You point out some problems, but how do we actually do these? Without emails as the keys to the kingdom, what would you use? Without a global identifier for a human person (like social security in the US), how would we declare that an identity is compromised? While I believe your ideals are well-intentioned, I think they're impractical in our current society. I would propose that an email is the key to the kingdom, t…

> Without emails as the keys to the kingdom, what would you use?

From Ursula K. LeGuin's indispensable "Dispossessed":

“You're really much too polite for ...”

“For what?”

“For an anarchist,” she said, in her thin and affectedly drawling voice (it was the same intonation Pae used, and Oiie when he was at the University). “I'm disappointed. I thought you'd be dangerous and uncouth.”

“I am.”

She glanced up at him sidelong. She wore a scarlet shawl tied over her head; her eyes looked black and bright against the vivid color and the whiteness of snow all around.

“But here you are tamely walking me to the station, Dr. Shevek.”

“Shevek,” he said mildly. “No `doctor.'”

“Is that your whole name — first and last?”

He nodded, smiling. He felt well and vigorous, pleased by the bright air, the warmth of the well-made coat he wore, the prettiness of the woman beside him. No worries or heavy thoughts had hold on him today.

“Is it true that you get your names from a computer?”

“Yes.”

“How dreary, to be named by a machine!”

“Why dreary?”

“It's so mechanical, so impersonal.”

“But what is more personal than a name no other living person bears?”

“No one else? You're the only Shevek?”

“While I live. There were others, before me.”

“Relatives, you mean?”

“We don't count relatives much; we are all relatives, you see. I don't know who they were, except for one, in the early years of the Settlement. She designed a kind of bearing they use in heavy machines, they still call it a `shevek.'” He smiled again, more broadly. “There is a good immortality!”

Vea shook her head. “Good Lord!” she said. “How do you tell men from women?”

“Well, we have discovered methods...”

...

The five- and six-letter names issued by the central registry computer, being unique to each living individual, took the place of the numbers which a computer-using society must otherwise attach to its members. An Anarresti needed no identification but his name. The name therefore, was felt to be an important part of the self, though one no more chose it than one's nose or height.

Re: Finding vulnerable Twitter accounts with expired domains

#54
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

Gmail is only a single failure point if you let it be one though - set up 2fa on all your accounts, and this problem is solved.

Re: Finding vulnerable Twitter accounts with expired domains

#55
post #29

Earlier quoted context omitted.

Without sharing examples, this is effectively a non-answer. Thanks for the comment.

In Sweden, BankID covers well over 90% of the population between ages 20 and 60 with a unique electronic ID. (Including 98% of those between 20 and 40.) It supports identifying yourself with a credit card and pin using a card reader given to you by your bank or alternatively (and more commonly) a pin combined with a smartphone/computer that you have identified as being yours.

You're going to have a hell of a time trying to sell that to 50 states and a handful of territories, all of which can't even implement REAL-ID properly.

What agency manages BankID in Sweden? I would imagine in a better world, the US Postal Service could be doing some of this work in the states at a federal level, but I wouldn't get my hopes up.

Re: Finding vulnerable Twitter accounts with expired domains

#56
post #36

This isn’t the workflow I see when trying the password reset process on an old account that I’ve recently tried to recover. I’ve forgotten both the password and the email address associated with the account, but I know the domain I would have used, and I own it so I could easily prove ownership of the email address if I knew what it was. But when I click Forgot Password, it asks me for my username and also the email…

I am also not seeing the behaviour that the OP describes.

Re: Finding vulnerable Twitter accounts with expired domains

#57
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

We should be using biometric markers filtered through homomorphic encryption.

This way we can verify/prove our identity without handing over those markers to multiple 3rd parties.

Re: Finding vulnerable Twitter accounts with expired domains

#58

My wife and I started up a small reselling business, based on our name. The dotcom for it was previously owned, but they let the domain lapse, but they still have the Twitter account (that has the web address we now own in their profile; they haven't posted since 2016). I tried an approach similar to the article, but they apparently used Gmail to set it up. (I reached out to them to buy it to no response; I assume th…

time to add an underscore to the name

Or maybe see if they Have Been Pwned in the past.

Re: Finding vulnerable Twitter accounts with expired domains

#59
post #41

What if we could have services encrypt their emails sent to us via pgp? eg Twitter (or anything else) asks for your public key and then sends all future emails using it.

Perfect! A true second factor. Not just some annoying gimmick, like SMS.

Re: Finding vulnerable Twitter accounts with expired domains

#60
post #23

What would be a universal solution to this problem? The only thing I can really think of is platforms not allowing custom domains for connected email accounts, but that seems sub-optimal.

Instead of blocking custom domain email addresses outright, the site could require a secondary recovery email address from an approved provider when an email with a custom domain is used to create the account. Then any security interaction like password reset, or 2fa would go to the primary address and would send an alert to the secondary email address about the nature of the communication. There could be a link in t…

> Instead of blocking custom domain email addresses outright, the site could require a secondary recovery email address from an approved provider when an email with a custom domain is used to create the account.

No thank you, I don't want a mandatory backdoor for every government that might want to claim jurisdiction over one of those large worldwide providers.

Post reply on HN