37 ms·
How I Lost My $50,000 Twitter Username
- micahgoulart 13y agoAn interesting point made was to avoid using custom domains for the login emails, since a DNS takeover would compromise your accounts tied to that email.
- troels 13y agoI think that's missing the point a bit. Using gmail as your primary address will make you vulnerable to Google arbitrarily (or even justified) shutting down your access. We all heard stories about that. What you should do, is make sure that you trust your registrar. Paypal sure have some questionable practises, but the real culprit in this story is clearly GoDaddy.
- zuccs 13y agoAgree - never thought of that before!
- ben0x539 13y agoOr maybe DNS should be secured with something besides the honor system.
- adrr 13y agoWonder how would you prevent or detect this hack attempt early. Are there services that monitor for DNS changes? Could you up the TTLs on the MX records so if you did notice a breach, you would have adequate time to resolve it?
- scintill76 13y agoThis is quite frustrating. I don't use Gmail or Google Apps mail, so that I can't be compromised by a malicious insider (however unlikely) or a flaw in their authentication systems. Instead my security is exactly as weak as my registrar's authentication.
- ereckers 13y agoYes. This seems like his final conclusion. Gave me something to think about. Wild story coming out today because I was just setting up a couple domains/emails today on Google Apps. There's actually a section in the process in which they suggest setting the MX TTL to 1 Week.
- acangiano 13y agoThe counterargument is that Google's notoriously poor customer care team could ignore your plea when they deny you access to your own gmail address for god-only-knows-what reason. But it's still probably safer to go the gmail two-factor authentication route.
- josteink 13y agoAn interesting point made was to avoid using custom domains for the login emails That's horrible advice. That sort of attitude taken to the extreme means we shouldn't be using DNS for anything ourselves and put everything in Google's (or Amazon's) big bag. Should I redirect my customers to facebook.com/company as well in fear of someone taking over my DNS? The lesson from this whole charade is to not trust something as crucial your DNS to untrustworthy companies like Godaddy. We've heard the horror stories before and we keep on hearing them again. Relying on Google, a company with no direct end-user support and no emergency hotline to secure the most important thing you have, DNS, is even bigger madness. I've been locked out from a Gmail account before. It took me weeks to get it back, because Google has no support. So yeah. Get a proper DNS-provider, and don't dig yourself deeper into the hellhole you're currently setting up.
- brown9-2 13y agoWhy is anyone still using GoDaddy?
- RexRollman 13y agoand Network Solutions.
- rikacomet 13y agoPayment channel option is one reason. Linode/DigitalOcean for example are not available in India, due to restrictions on Debit Cards of Indian users. Credit cards are very uncommon here, compared to Debit Cards. Btw, I personally use Bigrock instead. They have a very a good customer support. http://rikacomet.blogspot.in/2013/12/quick-comparison-between-godaddy.html http://rikacomet.blogspot.in/2013/12/quick-comparison-betwee...
- moondowner 13y agoI have been using a debit card (Visa Electron) for both Linode and DigitalOcean. Works fine.
- tagabek 13y agoThe 99c domain names.
- MildlySerious 13y agoGuess these still have their price...
- chmars 13y agoAffordable pricing. If you are used to GoDaddy, you simply ignore all the, ehmmm, special offers …
- fletchowns 13y agoThe pricing isn't even that good though
- georgemcbay 13y agoSeems like Twitter could easily verify the story based on their own logs and then restore access to his N account. He doesn't mention pursuing that, though.
- timhaines 13y agoHave just been talking with him. He first asked Twitter for it back on the 20th of Jan. 8 days ago.
- brador 13y agoHe said he wasn't using it much. Thus, isn't he basically a squatter?
- harryh 13y agoYa, the fact that he tweeted a grand total of twice in 2013 (see https://twitter.com/N_is_stolen https://twitter.com/N_is_stolen) makes me have a little less sympathy.
- imsofuture 13y agoI'm a very casual and infrequent tweeter, and I can't fathom how that makes my username 'up for grabs'. Sorry you have such a twisted view of username ownership :/
- harryh 13y agoOh it definitely doesn't make your username 'up for grabs'. What happened to you totally sucks and I hope you manage to get your account back. That being said if you're not actually going to use your account you might want to at least consider giving it to someone who would put it to more active use. Just a thought.
- nathanb 13y agoSomeone offered him 50 grand for it, and he turned them down. I would be surprised if he hadn't considered it at that point, if not previously.
- Oculus 13y agoIf the author is reading, did you end up getting back your @n username? If so, did you simply go to Twitter and explain to them the whole story?
- owenwil 13y agoI don't think you realize how unresponsive and poor Twitter's support is. I was once locked out of my Twitter account via anything but Tweetdeck (due to two-factor authentication suddenly breaking and not sending SMS') for four weeks before I wound up accidentally finding a PC that I hadn't signed out of previously and was able to disable. I logged a ticket on the first day it happened and never even received a response.
- rickyc091 13y agoI can concur with their shitty support. I guess iOS 7 autoupdated my Vine app and somehow logged me out. I tried password resetting every email I could think of, I tried to connect via my social network. No dice. My account couldn't be found. I email their support team with my username asking them if they could provide me with my email, do a forgot password to the email. I even linked them to a few direct vines I had created and saved the URL to. Their response was unless I could provide them with the Vine ID number of my user account they could not locate my account. Seems I emailed them back and forth six times and I kept getting this canned message from them. Needless to say, I've given up and deleted Vine from my phone. "Unfortunately, we are unable to locate the Vine account in question. If you can still log in to your Vine account, go to your profile settings and select either "Invite via text" or "Invite via email." From there you will see your Vine account ID number. Can you reply to this message with the Vine ID number? If you no longer have access to this account, but can see the account in Vine search, press the more icon (three dots) on the top right of the profile. After that, tap on "Share this profile" and from there you will see your Vine account ID number."
- nh7a 13y agoNope. A week ago when I explained the situation, Twitter seemed to think I just gave it up, willingly or not.
- owenwil 13y agoWow, this is both interesting and terrifying. I have a two character Twitter handle that I use actively and it makes me worry that one day I might be targeted too using a similar method, although so far I've had no problems.
- andre 13y agoI have a two character twitter handle also, and am active on it. Used to receive several "reset" emails per day before two-factor authentication.
- seniorsassycat 13y agoI found it interesting how open the attacker was about how they did it.
- 650REDHAIR 13y agoI felt very angry and uncomfortable reading that. I can't imagine being in a helpless position like that.
- pmorici 13y agoAnother reason to use Bitcoin. No credit card number to give away to the attacker and identity can be verified by signing a message with a private key instead of guessing at personal information.
- OafTobark 13y agoDid you even bother to read the damn article or are you throwing blind shit on the wall here.
- knocte 13y agoI believe he read the article.
- pmorici 13y agoYes, did you? The Attacker got Paypal to give up the last 4 digits of the victim's credit card number. Then he called GoDaddy which allowed him to verify his identity by giving them the last 4 of his credit card number though the attacker said they would have let him guess multiple times. If GoDaddy accepted Bitcoin PayPal wouldn't even be involved and GoDaddy instead of asking for information which is apparently easily pilfered could have requested the caller sign a message with their private key Bitcoin key corresponding to the public key from which they paid GoDaddy for the domain services to begin with.
- dragonwriter 13y ago> If GoDaddy accepted Bitcoin PayPal wouldn't even be involved and GoDaddy instead of asking for information which is apparently easily pilfered could have requested the caller sign a message with their private key If GoDaddy separated authentication of requests from payment information and had any of a wide number of different authentication methods, this wouldn't have been an issue, either. Using PayPal -- or accepting credit card payments by other means -- does not imply (or normally involve) using the last four digits of CC number as if it were a PIN for authentication. (In fact, since CC numbers are widely exposed information, doing so is insane -- especially the last four digits, which are frequently used without the rest as a reference to identify a credit card to the owner of the card in contexts like receipts where the information is expected to be particularly public.) Payment methods are really largely irrelevant here, GoDaddy could easily have adopted an equally stupid and brain dead authentication method if they took bitcoin as payment.
- ChrisArchitect 13y agopretty freaky stuff. Also, what was the attacker so interested in the @N for anyways? future investment in case some big company/celeb comes along wanting the username? Seems so crazy to go after it...... if Twitter can't sort this out, can't we all just shame the acct into inactivity... Is squatting on it worth all this Mitnick-attack-work?
- bryan_rasmussen 13y agoWell, if this story is true ( I put the if because it seems silly to have that account be the target ) then access to the account is proof of a crime (this is why it seems silly) If they sell it to someone I guess that is a reason to take it, but it also seems like some enterprising DA would want to use it as an example of receiving stolen property ( because News! Hacking! Fame!) So if anyone buys this name they might be in trouble at some unspecified point in the future.
- ericcumbee 13y agoAnd in this case I would be pulling for the DA to tear this hacker a new one.
- RawData 13y agoSo who are you planning on suing? PayPal, godaddy, twitter, or all three?
- TwoBit 13y agoThe Terms of Service agreements for those companies probably all allow them to get away with it.
- jkrems 13y agoTerms of service normally don't override law. So, if there is something unlawful about their behavior, it doesn't matter what they wrote in their TOS. At least in many countries, not sure about US.
- harryh 13y agoWho are people's current favorite domain registrars? I've been with name.com for the last year or so and have been happy, but I'm always curios to hear from others.
- rickyc091 13y agoI've heard really good things with gandi and hover. I myself use namecheap, cause well, it's decent service for its price.
- dombili 13y agoI use Gandi (for hosting, domain and email) and Hover. Can't recommend them enough.
- arnoooooo 13y agoGandi's pretty good, except they have strange terms of service : "By accepting Our Contracts and using Our Services, You agree to abide to Our code of ethics which consists, in particular, of protecting and respecting minors, human dignity, public order and good moral standards [...]" https://www.gandi.net/static/contracts/en/g2/pdf/MSA-1.0-EN.pdf https://www.gandi.net/static/contracts/en/g2/pdf/MSA-1.0-EN....
- kawera 13y agoBeen with gandi.net for a few years now; excellent service and 2-factor auth.
- zzzeek 13y agowhat's more likely, someone hacks your domain name / DNS gaining control of your MX records or someone hacks your username @gmail.com?
- girvo 13y agoHacking (via social engineering) your GoDaddy account would be easier, IMO. And that looks like what's happened here?
- dabernathy89 13y agopossibly depends on whether you are using 2-factor auth with gmail.
- gcp 13y agoJust Google's notification "why are you suddenly using your accounts from a different country" can be life-saving. (As well as not putting any important stuff there)
- poopsintub 13y ago$50,000 twitter username. Sigh...
- deleted 13y ago[deleted]
- DanBlake 13y agopoopsintub Twitter added two-factor authentication back in May. If you're constantly being attacked that you ignore important emails, at least add phone authentication. - You might want to read the post before you comment. He willingly gave the twitter to the hacker.
- poopsintub 13y agoGoDaddy added two-factor authentication in December...Twitter almost a year ago, Facebook in 2011. Like I said, if he was under attack frequently that he just ignored security emails, you think turning on two-factor authentication would have been a pretty good idea on any one of those. He did none and wants to grab attention about a $50k twitter handle. This is what happens when you run with scissors.
- TwoBit 13y agoTwo factor is irrelevant when they will give up your account for just the last four card digits.
- kevinchen 13y agoDoesn't help if you're being blackmailed, as you have access to both factors.
- markdown 13y agoI feel bad for this guy, and twitter needs to do the right thing and return to him his handle. Then I can come back here and post nasty comments about squatters.
- reuven 13y agoYes, absolutely. The guy has given a clear and convincing story of what happened. I'm sure that it would be pretty easy for someone on Twitter's security team (assuming that they have one) to verify that the username was taken when he said it was. I don't know what I find more shocking -- that PayPal would actually give the last four digits of a credit-card number to a complete stranger, that GoDaddy would let someone guess a two-digit number, or that a credit-card number is all you need to identify yourself. (In Israel, it's common for companies to ask for the last four digits of your credit card number in addition to other details, but never on its own.) Actually, I'm willing to believe just about anything about GoDaddy. But PayPal is known for being surprisingly harsh and paranoid about security, shutting down accounts and holding money when they suspect problems. It's sad and rather surprising to me that they're willing to give out such information so easily, unless you specifically ask them not to. Shouldn't it be the other way around, that they refuse to provide such details unless you allow them to? I really hope that Twitter and PayPal apologize profusely to this author, and undo the damage they've done as best as possible.
- jrs99 13y agoDo you mean Godaddy and Paypal should apologize? I don't think twitter did anything wrong yet. They are just looking into what happened.
- reuven 13y agoYes, I meant that GoDaddy and PayPal should apologize. Twitter should look into what happened in this specific case, and somehow (if the posting is right) return the username to its original owner. But there does seem to be something terribly broken here if it's possible for someone to get another person's Twitter account, and for it to take a full investigation to get it back to the original owner. And for not having better procedures in place, I think that an apology wouldn't be unreasonable. In general, it seems to me that demonstrating empathy for your customers is a pretty reasonable strategy. Even if they didn't do anything wrong, and before they have finished this investigation, they can show that they care about the people using their system. I don't think that Twitter could go wrong by saying, "We now see that we need to make it harder for scammers to switch the ownership of a Twitter account, and are looking into how to do so without hurting our legitimate users."
- fjcaetano 13y agoI believe that it is ISO 9001 (quality assurance) that states that a company must be able to audit any stored data and data changes dating back some time. Judging by Paypal (specially for being a financial company), Twitter (for being an open capital company), and GoDaddy's size they may all comply to ISO 9001, but I'm just guessing. Anyhow, if any of them actually comply to ISO 9001, it is possible to audit previous data to establish the true identity of the owner in some arbitrary date before any of this happened. Quite possibly, to avoid unnecessary user annoyance, these companies will only subject themselves to the effort of analyzing that data under court order, so it's fair to suppose there is need to open a judicial process. Therefore, I believe it's possible to regain access to everything that was supposedly stolen, even though it may take quite some time.
- dmak 13y agoAnd we all know how this would end. GoDaddy and Paypal will try to make this right because of the negative publicity. Why does it always take a post like this to call for help?
- eplumlee 13y agoGoDaddy and Paypal have every incentive to bury their shoddy security practices and deny everything that the OP is claiming, to avoid a PR disaster. They might quietly return to the issue later and perhaps address some of their security issues... maybe.
- mrbill 13y agoIt's not a $50K Twitter username unless someone actually paid $50K for it at one point, is it? "Not accepting an offer of $50K for a twitter username I didn't use" doesn't really count...
- joelrunyon 13y agoIt's a close approximation of value. Much closer than saying "I would sell this if I received a 50k offer."
- enscr 13y agoIt has a lot of value for brands like Nike, Nokia, Netflix, Nordstrom... Or a News channel - @N is very attractive to advertise. I don't see any trouble selling it for more than that.
- Buge 13y agoIt's worth what people are willing to pay for it. If people are willing to pay $50k then it is worth $50k. Of course it might have gone down in value since the offer.
- stanleydrew 13y agoThat logic only works once an actual payment is made. Claiming you are willing to pay and actually paying are two very different things.
- bredren 13y agoThis is a scary story! Focusing on the Twitter handle sale part: I have the twitter handle @jetsetter, and have been offered multiple thousands of dollars for it (guess who!). Unfortunately, selling a twitter handle is against TOS. Only @israel has been officially allowed to transfer hands for money, that I'm aware of. So trying to broker the sale of a twitter account can allow the buyer to report your 'behavior' to twitter. They can seize the account and make it so no one has it, which may be what the buyer prefers to you having it. So no matter the price you could command, it isn't like you could just list @n up for sale and make it rain.
- jordsmi 13y agoUnless you are talking on the actual twitter account about selling it you should be fine. If not I could just make fake email logs and report you.
- lingben 13y agoactually several twitter handles have been "sold" although the transaction was done in such a way that it was not as straightforward to get around the TOS the most famous is the CNNbrk handle
- markdown 13y ago> Only @israel has been officially allowed to transfer hands for money, that I'm aware of. Twitter: "I'm sorry, you can't do that." Israel: "What are you, some kind of Anti-semite!?!" Twitter: "OK, OK, go ahead and do what you want. See, we're not anti-semite :)"
- vxNsr 13y agoWell at least you didn't make some bad pun involving Israel, jews and money....
- vxNsr 13y agoIf you're refering to this: http://www.theguardian.com/technology/2010/sep/14/twitter-user-sells-israel-username http://www.theguardian.com/technology/2010/sep/14/twitter-us... at the bottom a twitter representative is quoted as saying that as long as they give you permission to sell/buy a handle they won't block/lock the account. Also apparently CNN also purchased a handle[1]. [1] http://www.businessinsider.com/cnn-acquires-cnnbrk-twitter-account-with-nearly-1-million-followers-2009-4 http://www.businessinsider.com/cnn-acquires-cnnbrk-twitter-a...
- codezero 13y agoOne thing that people should realize in why Twitter may not respond to these kinds of issues, or may be slow to respond, is that it's probably true that lots of people buy and sell Twitter accounts, and people may report them stolen when in fact they've already sold them to someone. This kind of thing happened a lot in MMO games which is why they try to push account security into your hands so they don't have to attempt to arbitrate in deals that may or may not have happened outside of their sphere of control.
- baddox 13y agoSo what? If Twitter returned control of a handle if someone could prove that they had recently controlled the handle, that would quickly make the handles market dry up.
- Herald_MJ 13y agoTwitter has no interest in there being a handles market. In fact, I wouldn't be surprised if their T&Cs expressly forbids it.
- Bluestrike2 13y agoHeads really ought to start rolling at PayPal. Their general approach to security is, quite frankly, appalling. Is there any possible rational for Paypal to give the last four digits of his card number to "him" over the phone? Given that they're routinely used for verification, it's as if they've never heard of social engineering. It's simply inexcusable. And it's almost as bad as the ridiculous "Log In Without Your PayPal Security Key" option that lets you bypass 2-factor auth and head straight to the ultra-secure world of the ridiculous security questions such as the ever-popular "what city were you born [that's also listed on Facebook]" and what not. I still can't believe they think that's a good idea.
- autarch 13y agoThe attacker was posing as a PayPal employee, not the card owner. Of course, PayPal still needs better security, but posing as an employee of the same company is a classic social engineering exploit.
- Aqueous 13y agoAnd that part was never really answered either. How can he pose as an employee calling in from an outside line? Does PayPal not tell you when an extension from PayPal is calling you?
- phpnode 13y agohe was probably posing as an employee of the account holder, not paypal
- xauronx 13y agoOhh, good point. I never thought of that. I assumed employee of Twitter as well.
- baddox 13y agoWho cares what number the call was coming from. Security 101 for these phone techs should say something like "don't give out any information over the phone, even if the CEO calls and threatens to fire you if you don't." Or better yet, have much stricter protocols that deny the phone tech access to the information, so even if the caller threatens the tech personally, the information is safe.
- deleted 13y ago[deleted]
- philliphaydon 13y agoDitch GoDaddy - They are a terrible company. Also considering closing my paypal account now.
- cpayne 13y agoI'm consistently surprised at the number of complaints against GoDaddy. They are a horrible company! You get what you pay for...
- Osiris 13y agoJust a side note here, GoDaddy has been under new management for a little under two years. There's a lot internal changes happening specifically aimed at improving usability and infrastructure.
- cpayne 13y ago(I didn't know that). That's fine, but there are just SO many other companies that provide the same service...
- driverdan 13y agoDo it. Paypal is a terrible company who doesn't give a shit about its users.
- 13y ago
- nevi-me 13y agoMy custom domain address was stolen with the Dropbox data leak, got so much spam that I set my Gmail to pull my mails via POP3. Then I changed everything to use my Gmail, and locked down my Gmail account. I've heard people go on about how Google (and I suppose other corporations) are evil, and how they are rolling their own custom mail solutions etc. It's times like these that people lose important things. Also, I really don't understand why US companies must store credit card details. I understand the convenience, but there's been a lot of security compromises to let this practice continue. In South Africa online retailers don't store CC info, yet we aren't being brought to our knees by inconvenience. At least the attacker mentioned his methods, so GoDaddy and PayPal can educate their staff better.
- TwoBit 13y agoWhat do you mean by Dropbox data leak?
- _ikke_ 13y agoA project document with e-mail addresses was retrieved through the account of a dropbox employee[1]. Some people noticed they got e-mail through unique non-disclosed e-mail addresses. [1]: http://lifehacker.com/5930706/dropbox-confirms-user-email-leaks-offers-new-security-features http://lifehacker.com/5930706/dropbox-confirms-user-email-le...
- hhw 13y agoA custom domain address can also be used with a custom mail server configuration that includes spamassassin. You can even setup IMAP folders for you to drag and drop mail into to be learned automatically as spam, ham, or forgotten. You can also setup fairly sophisticated rules with procmail or sieve. A good mail provider will also have this implemented for you. Aside from mining your data for marketing purposes, Google is evil because they continue to store your e-mails even after you delete them. Custom mail solutions are markedly superior if you know what you're doing, like anything else in life that you assume your own direct control over rather than leaving it to someone else.
- seanlinmt 13y agoInteresting that GoDaddy does not keep an audit trail for account detail changes that might help detect malicious activity. I guess they'll rather lose customers and reputation than do this.
- hackmiester 13y agoThey don't have much to lose reputation-wise...
- aestra 13y agoI am surprised anyone can take them seriously as a company after their Superbowl commercials.
- joshmlewis 13y agoI could be wrong but what is the value of a stolen Twitter handle? Just like a stolen car or phone if someone starts using it won't it be obvious that it's the thief or the thieves buyer? That's like stealing a Porsche and then showing it off downtown in front of everyone.
- obiterdictum 13y agoComparatively few people will read this story. Even fewer will care enough to continue the crusade against the attacker for any prolonged period of time to raise awareness among the potential future audience that this account was stolen. High chance the story will be quickly forgotten and the account will be re-used.
- scott_karana 13y agoOr resold, even more sensibly...
- vysakh0 13y agoSince medium also depends on Twitter, his page is no longer available. I checked @N_is_stolen page, it is fresh. So, all his posts in medium is gone, just because there is a change in username?
- nitinag 13y agoNo domain registrar should be taking the last four of your credit card number as proof of account identity or ownership. We certainly don't. Have you confirmed they reset the password based on just the last four of the credit card OR was your account's email address itself comprised, allowing them to reset the password via your email address?
- enscr 13y agoCan't you sue paypal or godaddy ? Or better yet, both. Shouldn't be hard to track down the attacker either if you report the crime.
- pyk 13y agoNo lawyer? Any reason why none was mentioned? Extortion is serious federal crime (across state lines, multiple companies, even clear admission of guilt). At the least it would get GoDaddy's attention vs. just asking nicely.
- ivanbrussik 13y agoIt is a long shot, and would take ton of money in fees mainly for a very skilled private investigator but you are absolutely correct this is one route to go.
- nroach 13y agoI was surprised that the victim didn't get an attorney involved. This is an example of a situation in which a court could very swiftly (same day, usually) issue an injunction to preserve the status quo while the merits get sorted out in court. Most domain providers I've dealt with will freeze a disputed account pending legal resolution of ownership, which can be decided via the court system or a WIPO arbitration.
- betenoire 13y agoWhat was up with the part with the facebook message? Why would the attacker tip him off rather than just take what he came for? Or did I read that wrong?
- Buge 13y agoMaybe the hacker was bragging about the hack and someone who heard that tipped him off.
- Zancarius 13y agoNever underestimate the enticing nature of boasting. I can think of more than a few would be anonymous attackers who were caught precisely because they wanted to brag about their achievements. I'm not really sure I understand the psychology behind it and whether it's a juvenile attempt to demonstrate relative power (e.g. "I did this to you, ergo I'm more powerful/smarter/whatever") or something else entirely.
- Shank 13y agoI don't understand why Twitter doesn't have the standard 30 day wait period on handle changes that most sites have. For a while it was a standard to not let old usernames be available until 30/60/90 days after a change, so that in the event that this kind of thing happened, it could be reclaimed with ease as soon as the GoDaddy account is in his possession.
- smartician 13y agoThat reminds me, a few months ago I had a weird Twitter experience. Someone gained access to my rarely used Twitter account @smartician and started posting spam. Somehow Twitter noticed, reset the password and notified me via email. I have no idea how that was possible.
- rth 13y agoIt happened me as well, I just shut down the account.
- westi 13y ago> Somehow Twitter noticed, reset the password and notified me via email. I have no idea how that was possible. This sounds like pretty normal automated monitoring for what looks like compromised account behaviour.
- aestra 13y agoThis happened to a friend of mine too, and he even forgot he had a twitter account.
- zaidf 13y agoI have a four letter twitter handle(zaid) and I probably average a half dozen forgot-password requests daily...many of them people in the middle east with the same name as me trying to take over my account. I've had two users offer to buy my username.
- lancewiggs 13y agoEveryone looks bad here, but I want to focus on Twitter. For me this case is yet another demonstration that Twitter sees its customers as advertisers and places low priority on the community. I pay Twitter nothing, and yet the service is valuable to me. So instead of continuously crippling the service in the name of goodness knows what, why not actually charge users for a premium experience. Things like customer service that works, a gold member status flag, controls on swapping account ownership, analytics and so on. Offer 3 paid levels - personal, business and corporate, and obviously keep the free level forever. Once revenue comes from customers, then perhaps it will help in understanding that while other revenue night be larger, the true value of Twitter is derived from the community.
- riffic 13y agoOr look into alternatives in the microblogging space. What ever happened to Status.net/ostatus?
- slazaro 13y agoBut the problem with alternatives is the fact that they're alternatives. Not what other people are using. If it's a social app, it's important.
- riffic 13y agoI dug a little deeper, and ostatus is a currently working group committee within the w3c. If I was the cio at oh, say an org in the public realm (generic government agency for example), I'd rather have control over the publishing and namespace of its tweet-like messages rather than putting every egg into the single-basket solution. Who knows if twitter will be around 20 years from now? The nice thing about standards is that there are so many to choose from.
- odinho 13y agoThey started pump.io instead. Which is a much more low-level project than StatusNet. Trying to build a federation-server that other people can make services on top of. Trying to win a market that way. If only one popular site starts to use it, -- you might be getting some network effect out of it. I think it was a better level to work on. Let others help with the network.
- benatkin 13y agoIt's sad, but twitter's not transferring it back in a week's time gives me more confidence in twitter, not less. There isn't any evidence of the stealing of the domain names and the extortion available besides OP's copies of the email messages and information that GoDaddy won't provide. With the value twitter ID has, twitter shouldn't do anything without clear evidence. He might have been able to get it back if it was his trademark or even name that he lost and not some witty username.
- ivanbrussik 13y agoI value any company's committment to security however there are ways that Twitter can prove who the owner of the account was, if they really wanted to. Let's see if this story hits real news headlines and affects Twitters stock before closing bell tomorrow and action will happen.
- xauronx 13y agoI was thinking how witty that would be if THIS was the actually hacker, and he was using us to create a shitstorm in order to rush Twitter into giving him the account. I'm sure there is sufficient data to support that he was the original owner though.
- Dnguyen 13y agoI lost a nice handle (@Houselogic) a few years back. Sent Twitter all the proof and email trail and everything, but they were useless. Every time I email their support, it's a new ticket and I have to explain the whole situation again and again. I gave up after two years.
- mannat 13y agoWoah ! What a story. You can trust nobody. Well hope that twitter people are reading this and can understand how badly they are trolled. All the best buddy. All the best.
- Ryel 13y agoI'm still wondering WHY the hacker took a twitter handle and why he didn't blackmail his victim into keeping quiet. $50k is hardly worth such a bold crime with no exit strategy.
- unreal37 13y agoWho's going to pay $50K for a stolen twitter handle? The value has surely dropped quite a bit.
- downandout 13y agoWas @n private before? It is now. If this kid is trying to sell the handle to someone, the buyer is likely in for a rude awakening if and when Twitter does the right thing and returns it.
- ivanbrussik 13y agostory archived here in case it did/does go down: http://pastebin.com/g7R6Ren2 http://pastebin.com/g7R6Ren2
- hoektoe 13y agoJust find it interesting to see how different the conversation on the same topic is over at reddit, http://www.reddit.com/r/technology/comments/1wfwfp/how_i_lost_my_50000_twitter_username/ http://www.reddit.com/r/technology/comments/1wfwfp/how_i_los...
- unreal37 13y agoSad to say, reddit sounds more human today than HN. So many people here saying, "He only tweeted 3 times in 2013, he deserves to lose it". Have some empathy! You think the hacker who tricked Paypal and Godaddy is in the right here to steal it? I can't believe it.
- rangibaby 13y agoI found this story interesting for the social engineering aspect. The lack of "outrage" is actually quite refreshing.
- lucaspiller 13y ago> But guessing 2 digits correctly isn’t that easy, right? The first few digits of card numbers refer to the provider (Visa, Amex, etc) [0]. Given that Paypal gave the last four digits of the card, I'm surprised they wouldn't give out the provider as well, so guessing this would be even easier. [0] https://github.com/stripe/jquery.payment/blob/master/src/jquery.payment.coffee#L11 https://github.com/stripe/jquery.payment/blob/master/src/jqu...
- eridius 13y agoIt wasn't the first 2 digits that were guessed, it was the 2 digits prior to the final 4.
- callesgg 13y agoDon't use godady is what I would take away from the story.
- chavesn 13y agoWhy would a company ever ever ever accept 6 digits of a credit card number as a way to authenticate an identity?? Credit card numbers are not secure. Therefore, they should not ever be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy. [Edited to add] I would sure love to see a scarlet letter list of companies which allow such practices, so I can never use them.
- ivanbrussik 13y agoI actually think it was 4.
- eridius 13y agoGoDaddy requires 6 digits, but the agent let the attacker guess 2 of them (repeatedly, until he got it right). That's truly awful.
- fredsted 13y agoI thought everyone knew not to use GoDaddy after the SOPA incident. Hopefully this will convince more people to move their domains to a domain registrar that cares about its customers.
- Osiris 13y agoSOPA was from one person (in-house counsel) and was not and is not the sentiment of c-level management or any employees I've ever talked to.
- yajoe 13y agototally off-topic, but because of the SOPA nonsense I've slowly moved my 40-or-so domains to namecheap during 2013 when their renewals came up. I was otherwise ambivalent about which DNS service/registrar to use before that incident... but thank you for helping the guy get his twitter account back and fixing up the internal controls.
- ksk 13y agoThe "we take X seriously at Y company" line is so tired. These companies are so incompetent that it would be funny if not for people getting screwed IRL.
- WA 13y agoReminds me of harvesting ICQ numbers. There was a time when you could search 6-digit ICQ numbers for expired freemail addresses like Hotmail (they deleted your account after a while), register that freemail address and reset your ICQ number password to get a brand "new" 6-digit number. I think this doesn't work anymore, since most freemail hosters don't "free" expired email addresses but keep them locked. It still works if you find an expired domain name, register the domain name and then do the whole password-reset procedure. Might be cheaper to buy a 6 digit number on eBay though :)
- fredsted 13y agoMaybe I'm missing something, but who uses ICQ still? And why not focus on 3-digit numbers? There's a million 6-digit ICQ numbers; not that unique.
- WA 13y agoThis was ~10 years ago. 3-digit numbers were all gone. Having a million 6 digit numbers increases chances to actually get one by registering an expired domain/email address. In times of 9 digit numbers, 6 digit numbers were still sufficiently unique :)
- lurkinggrue 13y agoI still use my ICQ account.... Mind you it's combined into trillian.
- erikb 13y agoIs it not possible to use the last bills as verification of who you are? screenshot of the bank statements and asking GoDaddy to verify their bank data and you've shown that it is in fact you who paid the bills. Also if account data is changed they MUST keep a log of what your data was before. At least anything beside passwords.
- ossreality 13y agoFor all the posts I would make, and the first one having been what it was, it should have included: don't use GoDaddy. I just, can't express how immediately my sympathy disappears when I read that word. The amount of arrogance it takes to be in tech and still use GoDaddy is beyond comprehension.
- quackerhacker 13y agoI feel so bad for Naoki that he was compromised in this scary manner. While the hacker did con his way on the phone for personal information, at the minimum, it's...hmmm....not nice...but "informative/narcissistic," of the hacker to describe his method to the victim. Makes me happy that companies are moving towards text authentication since emails are easy (or at least well practiced) to compromise. Note: Time to change my Time To Lives on my MX records and up my security.
- GunlogAlm 13y agoWhy on earth are people still using GoDaddy?
- sdaityari 13y agoSerious lapses on the parts of PayPal and GoDaddy. Ironically, there are sites which even refuse to identify the real person - like this one posted on HN a few days back(http://kevinchen.co/blog/square-identity-verification/ http://kevinchen.co/blog/square-identity-verification/)
- yaeger 13y agoWhat I take away from this is that: a) Two Factor should be mandatory and as soon as it is, any representative of the company MUST insist that a reset cannot be done over the phone. It should be highly suspicious if someone comes up and says "Hi, I lost my email account access AND my phone so could you please reset my password via phone now?" b) If not Two Factor, the security questions should also be mandatory. No other "data" like past addresses or cc numbers should suffice to reset over the phone if the person doesn't know the answers to all security questions. And, speaking of these questions, of course they should be stuff that you know and cannot be "guessed" by anyone who is able to read your facebook page or similar. Maybe even some non nonsensical thing like "Favorite Food" - "Horse Droppings". As long as you remember this, nobody should be able to "hack" that over the phone. Even if you go on and on on facebook about how you "could eat your way through a giant bowl of pasta you love it so much"
- aestra 13y ago>As long as you remember this I would NEVER remember this. EVER.
- blueskin_ 13y agoDon't use GoDaddy. Simple as that. If that hadn't happened, he'd still have his twitter account. >If I were using an @gmail.com email address for my Facebook login, the attacker would not have been able to access my Facebook account. Just google and the NSA then. Also, Gmail has an exposed password reset and social-engineerable support. A server running Postfix/Exim doesn't. I'd consider a domain with a good registrar far more secure than google.
- Tepix 13y agoI read the article. Sounds like an epic fail by GoDaddy, I blame them for 99% of what happened. Glad I'm not a customers of theirs... Oh btw, try to find a registrar that does 2factor authentication!
- bjpirt 13y agoTry Gandi: http://wiki.gandi.net/en/contacts/login/2-factor-activation http://wiki.gandi.net/en/contacts/login/2-factor-activation (note to self: activate 2FA)
- bevacqua 13y agohttp://xkcd.com/1279/ http://xkcd.com/1279/
- vladtaltos 13y agobesides the obvious stupidity of the parties involved, why would anyone pay for such an uninformative handle 50k ? @N ? seriously -- doesn't spam occur for twitter feeds yet ? I remember when google started off they didn't allow you to have email addresses less than 6 characters to avoid spam... btw, @! google search returns 0 results. interesting... hmm, twitter apparently allows alphanumeric handles only...
- edem 13y agoThis was the last straw. I'm moving away from GoDaddy.
- ck2 13y agoThis story is horrifying because PayPal was the enabler. PayPal gave the attacker the last four digits of my credit card number over the phone That person should lose their job if it is not PayPal policy. I really hope by some small chance the person that did this gets some serious prison time, if not for this then anything else prior or down the road. Then maybe one of those mornings they wake up in prison they can ponder if it was all worth it.
- fuj 13y agoThis wasn't paypal's fault. I mean entirely. The problem was with goDaddy. The last 4 digits of credit cards show's up everywhere. Check your receipts. Related question in stackexchange: http://security.stackexchange.com/questions/37758/safety-of-publishing-last-4-credit-card-digits-in-age-of-fast-computing http://security.stackexchange.com/questions/37758/safety-of-... GoDaddy should not use the 4 last digits as a way to confirm identity, exactly for the reason I mentioned above
- ck2 13y agoPayPal gives out info to someone completely unverified and it is not their fault? It would be one thing if this was a spouse or someone intercepting their physical mail. It's not. It's someone out of the blue who called PayPal to get the last four of a complete stranger. GoDaddy's verification is bad too but at least they had some kind of attempt.
- baldfat 13y agoWhy oh why do people support GoDaddy? I find their TV Commercials the worst and makes us as a community go back to the 1950s stereo types???? Love it when I help churches with their websites and it has a GoDaddy account :(
- mseebach 13y agoIt's possible that this was gross negligence on part of the employee and that the thief just got really, really lucky - but that seems unlikely. This is a systemic fault of PayPal and firing a lowly phone-jockey will not solve that. There are computer system protections that were clearly not in place (the representative was able to see this data on the screen, rather than having to enter it blind and have it validated - or, if they did, they had infinite re-tries which is also bad. Three wrong attempts, and the account should be locked and have to be escalated) but there are also culture/training problems: Until otherwise satisfactorily proven, anyone calling must be assumed to be in bad faith when they call. A representative with this mindset would not let a caller start guessing the "password".
- twice 13y agoThis is quite frustrating even to read!
- benjamta 13y agoCrumbs, this makes interesting reading - clearly lots of failings by the companies involved here. However. If someone were to steal a physical asset in order to extort something else out of me I would go immediately to the police. I'd have thought I'd do the same if the assets involved were digital. I've no idea if a criminal offence was committed in what ever jurisdiction this happened. But I'd have thought extortion is illegal is many parts of the world?
- klapinat0r 13y agoIn case OP reads HN: If your websites are hosted with GoDaddy, I would consider them compromised aswel. He may say that he has left them alone, but you have no chance of knowing.
- moeffju 13y agoIt doesn’t even take that much. Twitter simply took @mattness from me – without notifying me – because they claimed it was unused. That was a few weeks before I was ready to launch my redesigned website… I wrote to twitter support and they basically told me that well, it didn’t look like the account in question had my email address on it. Unregulated centralized name registries are not a good thing.
- abus 13y agoWhy does anyone believe the hacker's story of how he did it? It's possible he told the truth but it's likely he did not.
- outericky 13y agoRegardless of how this all went down, and is responsible... It is still theft right? Falsifying ones identity and taking possession of @n is stealing and should be covered under some law, no?
- EA 13y agoUp until late 2013, it was very easy to social engineer your way past Customer Sales Rep call screens to gain access to an AT&T account once you put together a few pieces of personal data (which was even easier to obtain) of the account owner. You didn't need to know the account password to gain access if you had other pieces of information. Those bits of information leak out through other service providers and are sometimes available through State and Federal Government systems. That meant that anyone using SMS via AT&T for two-factor auth was vulnerable. The extra layer of security is only enabled if you call AT&T and ask them to further protect your account from future changes.
- kristiandupont 13y ago>Using my Google Apps email address with a custom domain feels nice but it has a chance of being stolen if the domain server is compromised. Sigh I use Google Apps exactly so that I have control over the domain and aren't subject to the good will of Google. I had never thought of this particular problem. Now I don't know what to do.
- cbhl 13y agoThis really boils down to who is a better sysadmin-- you or the Google SREs. Choose reliable and paranoid providers that actually verify your identity before shenanigans and you can mitigate the entry vector.
- konklone 13y agoYeah, I disagree with Naoki's conclusion. I'm pretty sure he just didn't have 2FA turned on with GoDaddy (which I understand - I didn't think to turn 2FA on with my provider until I read his story). The admonition to use a @gmail.com address was annoying enough to me that I responded with a blog post: https://konklone.com/post/protect-your-domain-name-with-two-factor-authentication https://konklone.com/post/protect-your-domain-name-with-two-...
- tedchs 13y agoThe real solution is to use a DNS registrar and DNS hosting that properly verifies your identity before allowing changes. Google Apps has nothing to do with it, and in fact has enabled 2-factor auth for a long time. Everyone should be using it.
- patrickwiseman 13y agoHave you reported it to someone with prosecution powers? http://www.fbi.gov/about-us/investigate/cyber http://www.fbi.gov/about-us/investigate/cyber http://www.ic3.gov/default.aspx http://www.ic3.gov/default.aspx
- barlescabbage 13y agoWhat if this whole story was a lie? What if it was the hacker's final attempt to steal the @n twitter name.
- wallzz 13y agoyou need to stop watching movies!
- nogridbag 13y agoSlightly OT, but someone registered a Twitter account with my primary e-mail address. I received a "Confirm your e-mail account" email with a link "Not My Account". That link brings me to a page that says "Sorry, that page doesn’t exist!". There doesn't appear to be any way to contact Twitter about this. Shortly after, I received a second email "Welcome to Twitter, <username>" Going to: https://support.twitter.com/forms/impersonation https://support.twitter.com/forms/impersonation ..and selecting "Someone is using my email address without my permission." tells me to submit a general support ticket. That's fine except none of the general categories has anything to do with this problem and choosing "My issue is not in the list" simply redirects me immediately to the root support page. I submitted a ticket with a different topic and have not heard back from them in a week and expect I never will.
- vehementi 13y agoDoesn't this mean your email account is compromised?
- nogridbag 13y agoI doubt it. I have two factor auth set up on my email. Looking at the timestamps, the Welcome email was sent the same minute as the "Please confirm" email, so it's possible the Twitter account is not live and this was just an automatic welcome e-mail. Still, it would be nice if the "Not My Account" link actually worked properly or there was some way to contact support about it.
- andreasvc 13y agoMaybe the "Please confirm" mail was fake and actually meant to get you to click on the "Not My Account" link ...
- metaphorm 13y agothis story reeks of fake to me. what sane person doesn't call the FBI when an attacker blatantly commits fraud against them, admits to it, and then commits extortion based on the successful fraud? Furthermore, what kind of attacker explains how they attacked? Thats ludicrous. this has got to be some kind of roundabout way of advertising for the various competitors of godaddy mentioned in the post.
- konklone 13y agoThis is a terrifying story, and I'm very glad Hiroshima wrote it, because I didn't have two factor auth turned on with my domain provider. Now I do! It seems like if he'd had 2FA turned on with GoDaddy, this may not have happened. So rather than use @gmail.com addresses to register for things, as he recommends, just turn on 2FA with your provider. And if your provider doesn't support it, leave them and tell them why. The admonition to use a @gmail.com address was annoying enough that I actually put up a response blog post just on this point: https://konklone.com/post/protect-your-domain-name-with-two-factor-authentication https://konklone.com/post/protect-your-domain-name-with-two-...
- owens99 13y agoI hope Twitter can help this guy somehow.
- jdrenterprises 13y agoI'm not a programming expert, nor a process expert, but the way I see it... ... there has got to be a multi-stage process for authentication that does NOT use any CC or SSN. Of course, the responsibility lies with the account owner for maintaining passwords/authentication information. If you lose the information, no way to recover it. I say this because it seems (again, I'm not an expert) that these thieves use social engineering mostly in the "data recovery" stage of the process. The only way to tighten that from my perspective is to put maximum responsibility on the account owner to keep their logins, passwords (again, for multi-stage authentication), and such on hand. Don't have a need to recover your info, and others can't use the recovery process to get to your account. I guess it wouldn't be a perfect scenario but... this, or lose @N. I am sorry to hear there are companies allowing these practices, though... sad.
- rodrigocoelho 13y agoNamecheap posted a tweet[1] with an offer to move domains out of GoDaddy: How we make sure that you don't lose your $50,000 Twitter username: http://ow.ly/t4yR8 http://ow.ly/t4yR8 $5.99 domain transfers with code BYEBYEGD [1] https://twitter.com/Namecheap/status/428555697882935296 https://twitter.com/Namecheap/status/428555697882935296
- pistle 13y agoYou can sell twitter @'s now? #itsNotWorth50k Follow us at @N on twitter. Looks like a typo. Imparts zero cred since 99.999% of people will not take your ability to "possess" a short twitter account name as helpful for whatever else you may be trying to do. As far as the "Sorry I am so technically gifted. Let me tell you what you should do to prevent me next time..." thing, what kind of cartoon caper is this?
- rdl 13y agoThe advice to use @gmail.com vs. a custom domain name seems kind of questionable if you use a reasonably secure registrar. Not GoDaddy. Using an unusual/unknown address for account validation mails (maybe with forwarding of other communications) probably would make sense, though. And/or sites coming up with a better account-recovery procedure, perhaps outsourced to a startup. There's probably a market for a super-secure email address for account login mails, but that isn't a free gmail account.
- amrita1306 13y agoThats awful.. I use both GoDaddy and Paypal for my website and this has certainly made me a more cautious of securing sensitive information
- jimwalsh 13y agoYet another example of a compromised GoDaddy account and someone potentially losing their domain. Yet people continue to use GoDaddy time and time again.
- lurkinggrue 13y agoIt was worth ditching GoDaddy just so I wouldn't have to use that horrible interface ever again.
- ests 13y agoIt was like I read some scary book.
- maxk42 13y agoSomeone tracked down the hacker: http://www.reddit.com/r/hacking/comments/1whk3a/tracking_the_hacker_of_the_50000_twitter_handle/ http://www.reddit.com/r/hacking/comments/1whk3a/tracking_the...
- Brandork 13y agoI have seen great articles that document the best practices, patterns and anti-patterns for authentication within an application or storing passwords etc. But where is the gold standard for authenticating people over the phone? Good Developers understand how critical it is to handle authentication and password storage well. It can be complicated thing and is very easy to screw up. But all that goes out the window when somebody calls the support line. There needs to be just as much scrutiny placed on over the phone authentication as there is within an application. The problem is likely that those over the phone patterns/anti-patterns are not well documented and available.