thatuser Posted January 29, 2014 Posted January 29, 2014 How i lost my $50,000 twitter username i think this is ridiculous, security should be 1000000 x better, wouldn't expect it from paypal.
featured_spectre Posted January 29, 2014 Posted January 29, 2014 That is a good read. Definitely wouldn't expect that from a company such as paypal.
AngryTechnician Posted January 29, 2014 Posted January 29, 2014 I would. I stopped trusting PayPal a long time ago. Thery tout it as a safer way to buy but you actually have fewer consumer protections when buying something via PayPal then just buying it on credit card. Even if you have 2FA enabled they allow you to bypass it with security questions, and many of their security questions are the sort of "mothers maiden name" rubbish (the answer to which is on public record, for crying out loud. Pro tip: use made-up answers to these that only you know).
X-13 Posted January 29, 2014 Posted January 29, 2014 Pro tip: use made-up answers to these that only you know This is what I do. Hasn't caused any problems so far. [i'm surprised I remember them...]
AMLinington Posted January 29, 2014 Posted January 29, 2014 This article horrified me. I actually feel sick now.
localzuk Posted January 29, 2014 Posted January 29, 2014 That's horrendous. I hope Paypal and Godaddy sort it out and compensate him, and that Twitter recover his handle!
witch Posted January 29, 2014 Posted January 29, 2014 I have to have a whole scenario in my head - my mum's name, where I went to school etc etc in order to remember the fake securit answers It works though
Dos_Box Posted January 29, 2014 Posted January 29, 2014 Unfortunately consumer security must apply to lowers standards than those we are used to in IT. Besides, who uses GoDaddy and surely they had a backup of their work off-server. I would have gone 'nah' kept the Twitter tag and sorted it all out with PayPal and GoDaddy. You can get there eventually, especially if you have an evidence trail. Besides, if their Twitter tag has been extorted out of them then surely it would be easy to recover it legally and prosecute (if possible) those responsible.
localzuk Posted January 29, 2014 Posted January 29, 2014 Besides, who uses GoDaddy and surely they had a backup of their work off-server. They have 31% of the market with ICANN - by far the largest share. So, a heck of a lot of people do it. I would have gone 'nah' kept the Twitter tag and sorted it all out with PayPal and GoDaddy. You can get there eventually, especially if you have an evidence trail. Besides, if their Twitter tag has been extorted out of them then surely it would be easy to recover it legally and prosecute (if possible) those responsible. Indeed. I'd guess this would be a case for the FBI to deal with!
Oaktech Posted January 29, 2014 Posted January 29, 2014 GoDaddy has a market share because their service is fast, acceptably cheap, and easily accessible. I use them!
Tesla Posted January 29, 2014 Posted January 29, 2014 Very good read, what worries me is that the attacker knew about the workarounds, so must have been done before to other users.
d0pefish Posted January 29, 2014 Posted January 29, 2014 I'd have thought with those emails showing he was extorted in to it that would be proof enough (OK I know emails can be faked, but in this case to what gain). He could also draw on the proof of credit card details being changed, account info being changed to prove it was extorted. With this being in the US (I assume) he'll no doubt sue the relevant companies and make money. Plus, the username wasn't technically worth $50k. It might have been at that point in time one person offered him that amount, but surely it is only worth what someone is willing to pay at the present time.
Arcath Posted January 29, 2014 Posted January 29, 2014 This isnt a new flaw either, this article from 2012 had the same entry point: How Apple and Amazon Security Flaws Led to My Epic Hacking | Gadget Lab | Wired.com Amazon gave out the last 4 credit card digits and apple took them as proof.
CAM Posted January 29, 2014 Posted January 29, 2014 (edited) Hmmm, and there was me thinking of moving most of my online life to my own domain. I better check with CSN as to how attack-proof I am. :/ Just updated my SOA TTL to a week... Edited January 29, 2014 by CAM
Danp Posted January 29, 2014 Posted January 29, 2014 Not quite the same money involved, but I had 100 domain names 'stolen' from me in a similar scam about 5 years ago lost the domains and the money
Arthur Posted January 29, 2014 Posted January 29, 2014 Amazon gave out the last 4 credit card digits and Apple took them as proof. The owner of the Twitter username @jb had exactly the same thing happen to them. Amazon were to blame again. I’m @jb on both Twitter and Instagram. So you can imagine my username is a very heavy target. It used to be primarily because of the Jonas Brothers but of course now it’s all related to Justin Bieber. As you can imagine, with the marketing power behind his name, there’s thousands if not more companies/hackers/etc… who’d love to get their grubby hands on it for profit. It started when I received a forgot password email from Amazon. Forgot password emails are regular for me, because of my @jb username, but this was the first I had ever received from Amazon. “Why in the world would someone want that?” Twitter released feature awhile back ago that turns off the forgot password feature unless you have some specific information about the person. This was a godsend. Unfortunately Instagram has yet to implement something similar. I of course ignored the first email from Amazon like I normally do with any forgot password emails I get that I didn't initiate. Imagine my surprise when I received a second email about an hour later saying that my password had been successfully changed! I also had 3 fresh forgot password emails from Apple. It was clear I was being targeted.
thatuser Posted January 29, 2014 Author Posted January 29, 2014 Thats actually nice to hear, hopefully they have an explanation!
Arthur Posted January 30, 2014 Posted January 30, 2014 (edited) Here's GoDaddy's statement (via TechCrunch). GoDaddy admits hacker’s social engineering led it to divulge info in @N Twitter account hack GoDaddy Chief Information Security Office Todd Redfoot issued TechCrunch the following statement about the hack: Our review of the situation reveals that the hacker was already in possession of a large portion of the customer information needed to access the account at the time he contacted GoDaddy. The hacker then socially engineered an employee to provide the remaining information needed to access the customer account. The customer has since regained full access to his GoDaddy account, and we are working with industry partners to help restore services from other providers. Enabling two-factor authentication on your GoDaddy account seems to be a bit of a waste of time if the hacker can just call customer support and gain access to your domains. Enabling Two-Step Authentication « GoDaddy Edited January 30, 2014 by Arthur
thatuser Posted January 30, 2014 Author Posted January 30, 2014 A Little update from paypal here [h=2]PayPal Takes Your Security Seriously[/h]
Arthur Posted February 26, 2014 Posted February 26, 2014 Twitter restores $50,000 @N username to its owner « Ars Technica
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now