TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How I Lost My $50,000 Twitter Username

1043 pointsby micahgoulartover 11 years ago

78 comments

chavesnover 11 years ago
Why would a company <i>ever ever ever</i> accept 6 digits of a credit card number as a way to authenticate an identity??<p>Credit card numbers are not secure. Therefore, they should not <i>ever</i> be accepted as authentication. Especially only 6 digits of it! This is by far the most shocking part of this story. As if I needed another reason to despise GoDaddy.<p>[Edited to add] I would sure love to see a scarlet letter list of companies which allow such practices, so I can never use them.
评论 #7142718 未加载
评论 #7143962 未加载
评论 #7142943 未加载
评论 #7142755 未加载
评论 #7143982 未加载
评论 #7142639 未加载
markdownover 11 years ago
I feel bad for this guy, and twitter needs to do the right thing and return to him his handle.<p>Then I can come back here and post nasty comments about squatters.
评论 #7142646 未加载
评论 #7142723 未加载
评论 #7142966 未加载
评论 #7142666 未加载
Bluestrike2over 11 years ago
Heads really ought to start rolling at PayPal. Their general approach to security is, quite frankly, appalling.<p>Is there any possible rational for Paypal to give the last four digits of his card number to &quot;him&quot; over the phone? Given that they&#x27;re routinely used for verification, it&#x27;s as if they&#x27;ve never heard of social engineering. It&#x27;s simply inexcusable.<p>And it&#x27;s almost as bad as the ridiculous &quot;Log In Without Your PayPal Security Key&quot; option that lets you bypass 2-factor auth and head straight to the ultra-secure world of the ridiculous security questions such as the ever-popular &quot;what city were you born [that&#x27;s also listed on Facebook]&quot; and what not. I still can&#x27;t believe they think that&#x27;s a good idea.
评论 #7142780 未加载
评论 #7142200 未加载
georgemcbayover 11 years ago
Seems like Twitter could easily verify the story based on their own logs and then restore access to his N account. He doesn&#x27;t mention pursuing that, though.
评论 #7141731 未加载
评论 #7142110 未加载
评论 #7141786 未加载
ck2over 11 years ago
This story is horrifying because PayPal was the enabler.<p><i>PayPal gave the attacker the last four digits of my credit card number over the phone</i><p>That person should lose their job if it is not PayPal policy.<p>I really hope by some small chance the person that did this gets some serious prison time, if not for this then anything else prior or down the road. Then maybe one of those mornings they wake up in prison they can ponder if it was all worth it.
评论 #7143333 未加载
评论 #7143930 未加载
fjcaetanoover 11 years ago
I believe that it is ISO 9001 (quality assurance) that states that a company must be able to audit any stored data and data changes dating back some time. Judging by Paypal (specially for being a financial company), Twitter (for being an open capital company), and GoDaddy&#x27;s size they may all comply to ISO 9001, but I&#x27;m just guessing.<p>Anyhow, if any of them actually comply to ISO 9001, it is possible to audit previous data to establish the true identity of the owner in some arbitrary date before any of this happened.<p>Quite possibly, to avoid unnecessary user annoyance, these companies will only subject themselves to the effort of analyzing that data under court order, so it&#x27;s fair to suppose there is need to open a judicial process. Therefore, I believe it&#x27;s possible to regain access to everything that was supposedly stolen, even though it may take quite some time.
lancewiggsover 11 years ago
Everyone looks bad here, but I want to focus on Twitter. For me this case is yet another demonstration that Twitter sees its customers as advertisers and places low priority on the community.<p>I pay Twitter nothing, and yet the service is valuable to me. So instead of continuously crippling the service in the name of goodness knows what, why not actually charge users for a premium experience. Things like customer service that works, a gold member status flag, controls on swapping account ownership, analytics and so on. Offer 3 paid levels - personal, business and corporate, and obviously keep the free level forever. Once revenue comes from customers, then perhaps it will help in understanding that while other revenue night be larger, the true value of Twitter is derived from the community.
评论 #7144967 未加载
评论 #7143348 未加载
评论 #7142559 未加载
micahgoulartover 11 years ago
An interesting point made was to avoid using custom domains for the login emails, since a DNS takeover would compromise your accounts tied to that email.
评论 #7142549 未加载
评论 #7143416 未加载
评论 #7142475 未加载
评论 #7141992 未加载
评论 #7141777 未加载
评论 #7142424 未加载
评论 #7142326 未加载
评论 #7142280 未加载
philliphaydonover 11 years ago
Ditch GoDaddy - They are a terrible company.<p>Also considering closing my paypal account now.
评论 #7141925 未加载
评论 #7142005 未加载
评论 #7143993 未加载
codezeroover 11 years ago
One thing that people should realize in why Twitter may not respond to these kinds of issues, or may be slow to respond, is that it&#x27;s probably true that lots of people buy and sell Twitter accounts, and people may report them stolen when in fact they&#x27;ve already sold them to someone.<p>This kind of thing happened a lot in MMO games which is why they try to push account security into your hands so they don&#x27;t have to attempt to arbitrate in deals that may or may not have happened outside of their sphere of control.
评论 #7142717 未加载
brown9-2over 11 years ago
Why is anyone still using GoDaddy?
评论 #7141732 未加载
评论 #7141704 未加载
评论 #7142207 未加载
评论 #7144113 未加载
评论 #7142514 未加载
650REDHAIRover 11 years ago
I felt very angry and uncomfortable reading that. I can&#x27;t imagine being in a helpless position like that.
Dnguyenover 11 years ago
I lost a nice handle (@Houselogic) a few years back. Sent Twitter all the proof and email trail and everything, but they were useless. Every time I email their support, it&#x27;s a new ticket and I have to explain the whole situation again and again. I gave up after two years.
nogridbagover 11 years ago
Slightly OT, but someone registered a Twitter account with my primary e-mail address. I received a &quot;Confirm your e-mail account&quot; email with a link &quot;Not My Account&quot;. That link brings me to a page that says &quot;Sorry, that page doesn’t exist!&quot;.<p>There doesn&#x27;t appear to be any way to contact Twitter about this.<p>Shortly after, I received a second email &quot;Welcome to Twitter, &lt;username&gt;&quot;<p>Going to: <a href="https://support.twitter.com/forms/impersonation" rel="nofollow">https:&#x2F;&#x2F;support.twitter.com&#x2F;forms&#x2F;impersonation</a><p>..and selecting &quot;Someone is using my email address without my permission.&quot; tells me to submit a general support ticket. That&#x27;s fine except none of the general categories has anything to do with this problem and choosing &quot;My issue is not in the list&quot; simply redirects me immediately to the root support page. I submitted a ticket with a different topic and have not heard back from them in a week and expect I never will.
评论 #7144781 未加载
seniorsassycatover 11 years ago
I found it interesting how open the attacker was about how they did it.
评论 #7141895 未加载
blueskin_over 11 years ago
Don&#x27;t use GoDaddy. Simple as that.<p>If that hadn&#x27;t happened, he&#x27;d still have his twitter account.<p>&gt;If I were using an @gmail.com email address for my Facebook login, the attacker would not have been able to access my Facebook account.<p>Just google and the NSA then. Also, Gmail has an exposed password reset and social-engineerable support. A server running Postfix&#x2F;Exim doesn&#x27;t.<p>I&#x27;d consider a domain with a <i>good</i> registrar far more secure than google.
dmakover 11 years ago
And we all know how this would end. GoDaddy and Paypal will try to make this right because of the negative publicity. Why does it always take a post like this to call for help?
评论 #7142353 未加载
Shankover 11 years ago
I don&#x27;t understand why Twitter doesn&#x27;t have the standard 30 day wait period on handle changes that most sites have. For a while it was a standard to not let old usernames be available until 30&#x2F;60&#x2F;90 days after a change, so that in the event that this kind of thing happened, it could be reclaimed with ease as soon as the GoDaddy account is in his possession.
konkloneover 11 years ago
This is a terrifying story, and I&#x27;m very glad Hiroshima wrote it, because I didn&#x27;t have two factor auth turned on with my domain provider. Now I do!<p>It seems like if he&#x27;d had 2FA turned on with GoDaddy, this may not have happened. So rather than use @gmail.com addresses to register for things, as he recommends, just turn on 2FA with your provider. And if your provider doesn&#x27;t support it, leave them and tell them why.<p>The admonition to use a @gmail.com address was annoying enough that I actually put up a response blog post just on this point: <a href="https://konklone.com/post/protect-your-domain-name-with-two-factor-authentication" rel="nofollow">https:&#x2F;&#x2F;konklone.com&#x2F;post&#x2F;protect-your-domain-name-with-two-...</a>
maxk42over 11 years ago
Someone tracked down the hacker: <a href="http://www.reddit.com/r/hacking/comments/1whk3a/tracking_the_hacker_of_the_50000_twitter_handle/" rel="nofollow">http:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;hacking&#x2F;comments&#x2F;1whk3a&#x2F;tracking_the...</a>
pykover 11 years ago
No lawyer? Any reason why none was mentioned? Extortion is serious federal crime (across state lines, multiple companies, even clear admission of guilt). At the least it would get GoDaddy&#x27;s attention vs. just asking nicely.
评论 #7145796 未加载
评论 #7142291 未加载
kristiandupontover 11 years ago
&gt;Using my Google Apps email address with a custom domain feels nice but it has a chance of being stolen if the domain server is compromised.<p><i>Sigh</i> I use Google Apps <i>exactly</i> so that I have control over the domain and aren&#x27;t subject to the good will of Google. I had never thought of this particular problem. Now I don&#x27;t know what to do.
评论 #7144474 未加载
评论 #7144867 未加载
评论 #7144984 未加载
WAover 11 years ago
Reminds me of harvesting ICQ numbers. There was a time when you could search 6-digit ICQ numbers for expired freemail addresses like Hotmail (they deleted your account after a while), register that freemail address and reset your ICQ number password to get a brand &quot;new&quot; 6-digit number. I think this doesn&#x27;t work anymore, since most freemail hosters don&#x27;t &quot;free&quot; expired email addresses but keep them locked.<p>It still works if you find an expired domain name, register the domain name and then do the whole password-reset procedure. Might be cheaper to buy a 6 digit number on eBay though :)
评论 #7142691 未加载
bredrenover 11 years ago
This is a scary story!<p>Focusing on the Twitter handle sale part: I have the twitter handle @jetsetter, and have been offered multiple thousands of dollars for it (guess who!).<p>Unfortunately, selling a twitter handle is against TOS. Only @israel has been officially allowed to transfer hands for money, that I&#x27;m aware of.<p>So trying to broker the sale of a twitter account can allow the buyer to report your &#x27;behavior&#x27; to twitter. They can seize the account and make it so no one has it, which may be what the buyer prefers to you having it.<p>So no matter the price you could command, it isn&#x27;t like you could just list @n up for sale and make it rain.
评论 #7141976 未加载
评论 #7142239 未加载
评论 #7142297 未加载
评论 #7141919 未加载
评论 #7141967 未加载
benatkinover 11 years ago
It&#x27;s sad, but twitter&#x27;s not transferring it back in a week&#x27;s time gives me more confidence in twitter, not less. There isn&#x27;t any evidence of the stealing of the domain names and the extortion available besides OP&#x27;s copies of the email messages and information that GoDaddy won&#x27;t provide. With the value twitter ID has, twitter shouldn&#x27;t do anything without clear evidence.<p>He might have been able to get it back if it was his trademark or even name that he lost and not some witty username.
评论 #7142261 未加载
评论 #7143916 未加载
patrickwisemanover 11 years ago
Have you reported it to someone with prosecution powers?<p><a href="http://www.fbi.gov/about-us/investigate/cyber" rel="nofollow">http:&#x2F;&#x2F;www.fbi.gov&#x2F;about-us&#x2F;investigate&#x2F;cyber</a><p><a href="http://www.ic3.gov/default.aspx" rel="nofollow">http:&#x2F;&#x2F;www.ic3.gov&#x2F;default.aspx</a>
harryhover 11 years ago
Who are people&#x27;s current favorite domain registrars? I&#x27;ve been with name.com for the last year or so and have been happy, but I&#x27;m always curios to hear from others.
评论 #7141971 未加载
评论 #7141846 未加载
评论 #7141820 未加载
评论 #7142586 未加载
评论 #7142293 未加载
评论 #7141803 未加载
评论 #7150089 未加载
评论 #7144428 未加载
评论 #7143260 未加载
评论 #7141978 未加载
评论 #7143220 未加载
评论 #7141969 未加载
评论 #7145849 未加载
owenwilover 11 years ago
Wow, this is both interesting and terrifying. I have a two character Twitter handle that I use actively and it makes me worry that one day I might be targeted too using a similar method, although so far I&#x27;ve had no problems.
评论 #7141880 未加载
Oculusover 11 years ago
If the author is reading, did you end up getting back your @n username? If so, did you simply go to Twitter and explain to them the whole story?
评论 #7141682 未加载
评论 #7141876 未加载
hoektoeover 11 years ago
Just find it interesting to see how different the conversation on the same topic is over at reddit, <a href="http://www.reddit.com/r/technology/comments/1wfwfp/how_i_lost_my_50000_twitter_username/" rel="nofollow">http:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;technology&#x2F;comments&#x2F;1wfwfp&#x2F;how_i_los...</a>
评论 #7142456 未加载
nevi-meover 11 years ago
My custom domain address was stolen with the Dropbox data leak, got so much spam that I set my Gmail to pull my mails via POP3. Then I changed everything to use my Gmail, and locked down my Gmail account.<p>I&#x27;ve heard people go on about how Google (and I suppose other corporations) are evil, and how they are rolling their own custom mail solutions etc. It&#x27;s times like these that people lose important things.<p>Also, I really don&#x27;t understand why US companies must store credit card details. I understand the convenience, but there&#x27;s been a lot of security compromises to let this practice continue. In South Africa online retailers don&#x27;t store CC info, yet we aren&#x27;t being brought to our knees by inconvenience.<p>At least the attacker mentioned his methods, so GoDaddy and PayPal can educate their staff better.
评论 #7145621 未加载
评论 #7142180 未加载
zzzeekover 11 years ago
what&#x27;s more likely, someone hacks your domain name &#x2F; DNS gaining control of your MX records or someone hacks your username @gmail.com?
评论 #7141787 未加载
评论 #7141842 未加载
zaidfover 11 years ago
I have a four letter twitter handle(zaid) and I probably average a half dozen forgot-password requests daily...many of them people in the middle east with the same name as me trying to take over my account.<p>I&#x27;ve had two users offer to buy my username.
mrbillover 11 years ago
It&#x27;s not a $50K Twitter username unless someone actually paid $50K for it at one point, is it?<p>&quot;Not accepting an offer of $50K for a twitter username I didn&#x27;t use&quot; doesn&#x27;t really count...
评论 #7141973 未加载
评论 #7142140 未加载
评论 #7142015 未加载
vysakh0over 11 years ago
Since medium also depends on Twitter, his page is no longer available. I checked @N_is_stolen page, it is fresh. So, all his posts in medium is gone, just because there is a change in username?
lucaspillerover 11 years ago
&gt; But guessing 2 digits correctly isn’t that easy, right?<p>The first few digits of card numbers refer to the provider (Visa, Amex, etc) [0]. Given that Paypal gave the last four digits of the card, I&#x27;m surprised they wouldn&#x27;t give out the provider as well, so guessing this would be even easier.<p>[0] <a href="https://github.com/stripe/jquery.payment/blob/master/src/jquery.payment.coffee#L11" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;stripe&#x2F;jquery.payment&#x2F;blob&#x2F;master&#x2F;src&#x2F;jqu...</a>
评论 #7142662 未加载
rdlover 11 years ago
The advice to use @gmail.com vs. a custom domain name seems kind of questionable if you use a reasonably secure registrar. Not GoDaddy.<p>Using an unusual&#x2F;unknown address for account validation mails (maybe with forwarding of other communications) probably would make sense, though. And&#x2F;or sites coming up with a better account-recovery procedure, perhaps outsourced to a startup.<p>There&#x27;s probably a market for a super-secure email address for account login mails, but that isn&#x27;t a free gmail account.
rodrigocoelhoover 11 years ago
Namecheap posted a tweet[1] with an offer to move domains out of GoDaddy:<p><i>How we make sure that you don&#x27;t lose your $50,000 Twitter username: <a href="http://ow.ly/t4yR8" rel="nofollow">http:&#x2F;&#x2F;ow.ly&#x2F;t4yR8</a> $5.99 domain transfers with code BYEBYEGD</i><p>[1] <a href="https://twitter.com/Namecheap/status/428555697882935296" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;Namecheap&#x2F;status&#x2F;428555697882935296</a>
yaegerover 11 years ago
What I take away from this is that:<p>a) Two Factor should be mandatory and as soon as it is, any representative of the company MUST insist that a reset cannot be done over the phone. It should be highly suspicious if someone comes up and says &quot;Hi, I lost my email account access AND my phone so could you please reset my password via phone now?&quot;<p>b) If not Two Factor, the security questions should also be mandatory. No other &quot;data&quot; like past addresses or cc numbers should suffice to reset over the phone if the person doesn&#x27;t know the answers to all security questions.<p>And, speaking of these questions, of course they should be stuff that <i>you</i> know and cannot be &quot;guessed&quot; by anyone who is able to read your facebook page or similar. Maybe even some non nonsensical thing like &quot;Favorite Food&quot; - &quot;Horse Droppings&quot;. As long as you remember this, nobody should be able to &quot;hack&quot; that over the phone. Even if you go on and on on facebook about how you &quot;could eat your way through a giant bowl of pasta you love it so much&quot;
评论 #7144427 未加载
abusover 11 years ago
Why does anyone believe the hacker&#x27;s story of how he did it? It&#x27;s possible he told the truth but it&#x27;s likely he did not.
jdrenterprisesover 11 years ago
I&#x27;m not a programming expert, nor a process expert, but the way I see it...<p>... there has got to be a multi-stage process for authentication that does NOT use any CC or SSN. Of course, the responsibility lies with the account owner for maintaining passwords&#x2F;authentication information.<p>If you lose the information, no way to recover it.<p>I say this because it seems (again, I&#x27;m not an expert) that these thieves use social engineering mostly in the &quot;data recovery&quot; stage of the process.<p>The only way to tighten that from my perspective is to put maximum responsibility on the account owner to keep their logins, passwords (again, for multi-stage authentication), and such on hand. Don&#x27;t have a need to recover your info, and others can&#x27;t use the recovery process to get to your account.<p>I guess it wouldn&#x27;t be a perfect scenario but... this, or lose @N.<p>I am sorry to hear there are companies allowing these practices, though... sad.
erikbover 11 years ago
Is it not possible to use the last bills as verification of who you are? screenshot of the bank statements and asking GoDaddy to verify their bank data and you&#x27;ve shown that it is in fact you who paid the bills.<p>Also if account data is changed they MUST keep a log of what your data was before. At least anything beside passwords.
joshmlewisover 11 years ago
I could be wrong but what is the value of a stolen Twitter handle? Just like a stolen car or phone if someone starts using it won&#x27;t it be obvious that it&#x27;s the thief or the thieves buyer? That&#x27;s like stealing a Porsche and then showing it off downtown in front of everyone.
评论 #7142010 未加载
smarticianover 11 years ago
That reminds me, a few months ago I had a weird Twitter experience. Someone gained access to my rarely used Twitter account @smartician and started posting spam. Somehow Twitter noticed, reset the password and notified me via email. I have no idea how that was possible.
评论 #7142808 未加载
评论 #7142620 未加载
评论 #7144523 未加载
EAover 11 years ago
Up until late 2013, it was very easy to social engineer your way past Customer Sales Rep call screens to gain access to an AT&amp;T account once you put together a few pieces of personal data (which was even easier to obtain) of the account owner. You didn&#x27;t need to know the account password to gain access if you had other pieces of information. Those bits of information leak out through other service providers and are sometimes available through State and Federal Government systems.<p>That meant that anyone using SMS via AT&amp;T for two-factor auth was vulnerable.<p>The extra layer of security is only enabled if you call AT&amp;T and ask them to further protect your account from future changes.
Brandorkover 11 years ago
I have seen great articles that document the best practices, patterns and anti-patterns for authentication within an application or storing passwords etc. But where is the gold standard for authenticating people over the phone?<p>Good Developers understand how critical it is to handle authentication and password storage well. It can be complicated thing and is very easy to screw up.<p>But all that goes out the window when somebody calls the support line. There needs to be just as much scrutiny placed on over the phone authentication as there is within an application. The problem is likely that those over the phone patterns&#x2F;anti-patterns are not well documented and available.
Tepixover 11 years ago
I read the article. Sounds like an epic fail by GoDaddy, I blame them for 99% of what happened. Glad I&#x27;m not a customers of theirs... Oh btw, try to find a registrar that does 2factor authentication!
评论 #7143012 未加载
RawDataover 11 years ago
So who are you planning on suing? PayPal, godaddy, twitter, or all three?
评论 #7142194 未加载
seanlinmtover 11 years ago
Interesting that GoDaddy does not keep an audit trail for account detail changes that might help detect malicious activity. I guess they&#x27;ll rather lose customers and reputation than do this.
评论 #7142041 未加载
outerickyover 11 years ago
Regardless of how this all went down, and is responsible... It is still theft right? Falsifying ones identity and taking possession of @n is stealing and should be covered under some law, no?
quackerhackerover 11 years ago
I feel so bad for Naoki that he was compromised in this scary manner. While the hacker did con his way on the phone for personal information, at the minimum, it&#x27;s...hmmm....not nice...but &quot;informative&#x2F;narcissistic,&quot; of the hacker to describe his method to the victim.<p>Makes me happy that companies are moving towards text authentication since emails are easy (or at least well practiced) to compromise.<p>Note: Time to change my Time To Lives on my MX records and up my security.
benjamtaover 11 years ago
Crumbs, this makes interesting reading - clearly lots of failings by the companies involved here.<p>However. If someone were to steal a physical asset in order to extort something else out of me I would go immediately to the police. I&#x27;d have thought I&#x27;d do the same if the assets involved were digital.<p>I&#x27;ve no idea if a criminal offence was committed in what ever jurisdiction this happened. But I&#x27;d have thought extortion is illegal is many parts of the world?
kskover 11 years ago
The &quot;we take X seriously at Y company&quot; line is so tired. These companies are so incompetent that it would be funny if not for people getting screwed IRL.
betenoireover 11 years ago
What was up with the part with the facebook message? Why would the attacker tip him off rather than just take what he came for? Or did I read that wrong?
评论 #7142421 未加载
评论 #7142129 未加载
pistleover 11 years ago
You can sell twitter @&#x27;s now? #itsNotWorth50k<p>Follow us at @N on twitter.<p>Looks like a typo. Imparts zero cred since 99.999% of people will not take your ability to &quot;possess&quot; a short twitter account name as helpful for whatever else you may be trying to do.<p>As far as the &quot;Sorry I am so technically gifted. Let me tell you what you should do to prevent me next time...&quot; thing, what kind of cartoon caper is this?
enscrover 11 years ago
Can&#x27;t you sue paypal or godaddy ? Or better yet, both. Shouldn&#x27;t be hard to track down the attacker either if you report the crime.
ChrisArchitectover 11 years ago
pretty freaky stuff. Also, what was the attacker so interested in the @N for anyways? future investment in case some big company&#x2F;celeb comes along wanting the username? Seems so crazy to go after it...... if Twitter can&#x27;t sort this out, can&#x27;t we all just shame the acct into inactivity... Is squatting on it worth all this Mitnick-attack-work?
评论 #7141824 未加载
nitinagover 11 years ago
No domain registrar should be taking the last four of your credit card number as proof of account identity or ownership. We certainly don&#x27;t. Have you confirmed they reset the password based on just the last four of the credit card OR was your account&#x27;s email address itself comprised, allowing them to reset the password via your email address?
sdaityariover 11 years ago
Serious lapses on the parts of PayPal and GoDaddy. Ironically, there are sites which even refuse to identify the real person - like this one posted on HN a few days back(<a href="http://kevinchen.co/blog/square-identity-verification/" rel="nofollow">http:&#x2F;&#x2F;kevinchen.co&#x2F;blog&#x2F;square-identity-verification&#x2F;</a>)
downandoutover 11 years ago
Was @n private before? It is now. If this kid is trying to sell the handle to someone, the buyer is likely in for a rude awakening if and when Twitter does the right thing and returns it.
mannatover 11 years ago
Woah ! What a story. You can trust nobody. Well hope that twitter people are reading this and can understand how badly they are trolled. All the best buddy. All the best.
Ryelover 11 years ago
I&#x27;m still wondering WHY the hacker took a twitter handle and why he didn&#x27;t blackmail his victim into keeping quiet.<p>$50k is hardly worth such a bold crime with no exit strategy.
评论 #7142465 未加载
klapinat0rover 11 years ago
In case OP reads HN: If your websites are hosted with GoDaddy, I would consider them compromised aswel.<p>He may say that he has left them alone, but you have no chance of knowing.
edemover 11 years ago
This was the last straw. I&#x27;m moving away from GoDaddy.
jimwalshover 11 years ago
Yet another example of a compromised GoDaddy account and someone potentially losing their domain. Yet people continue to use GoDaddy time and time again.
评论 #7147286 未加载
vladtaltosover 11 years ago
besides the obvious stupidity of the parties involved, why would anyone pay for such an uninformative handle 50k ? @N ? seriously -- doesn&#x27;t spam occur for twitter feeds yet ? I remember when google started off they didn&#x27;t allow you to have email addresses less than 6 characters to avoid spam...<p>btw, @! google search returns 0 results. interesting... hmm, twitter apparently allows alphanumeric handles only...
amrita1306over 11 years ago
Thats awful.. I use both GoDaddy and Paypal for my website and this has certainly made me a more cautious of securing sensitive information
barlescabbageover 11 years ago
What if this whole story was a lie? What if it was the hacker&#x27;s final attempt to steal the @n twitter name.
评论 #7162510 未加载
bevacquaover 11 years ago
<a href="http://xkcd.com/1279/" rel="nofollow">http:&#x2F;&#x2F;xkcd.com&#x2F;1279&#x2F;</a>
callesggover 11 years ago
Don&#x27;t use godady is what I would take away from the story.
ivanbrussikover 11 years ago
story archived here in case it did&#x2F;does go down:<p><a href="http://pastebin.com/g7R6Ren2" rel="nofollow">http:&#x2F;&#x2F;pastebin.com&#x2F;g7R6Ren2</a>
GunlogAlmover 11 years ago
Why on earth are people still using GoDaddy?
owens99over 11 years ago
I hope Twitter can help this guy somehow.
twiceover 11 years ago
This is quite frustrating even to read!
estsover 11 years ago
It was like I read some scary book.
poopsintubover 11 years ago
$50,000 twitter username. Sigh...
metaphormover 11 years ago
this story reeks of fake to me.<p>what sane person doesn&#x27;t call the FBI when an attacker blatantly commits fraud against them, admits to it, and then commits extortion based on the successful fraud? Furthermore, what kind of attacker explains how they attacked? Thats ludicrous.<p>this has got to be some kind of roundabout way of advertising for the various competitors of godaddy mentioned in the post.
pmoriciover 11 years ago
Another reason to use Bitcoin. No credit card number to give away to the attacker and identity can be verified by signing a message with a private key instead of guessing at personal information.
评论 #7142387 未加载