Jump to content

Recommended Posts

Posted
I would. I stopped trusting PayPal a long time ago. Thery tout it as a safer way to buy but you actually have fewer consumer protections when buying something via PayPal then just buying it on credit card. Even if you have 2FA enabled they allow you to bypass it with security questions, and many of their security questions are the sort of "mothers maiden name" rubbish (the answer to which is on public record, for crying out loud. Pro tip: use made-up answers to these that only you know).
Posted
Pro tip: use made-up answers to these that only you know

 

This is what I do. Hasn't caused any problems so far. [i'm surprised I remember them...]

Posted

I have to have a whole scenario in my head - my mum's name, where I went to school etc etc in order to remember the fake securit answers

It works though :)

Posted

Unfortunately consumer security must apply to lowers standards than those we are used to in IT.

Besides, who uses GoDaddy and surely they had a backup of their work off-server.

I would have gone 'nah' kept the Twitter tag and sorted it all out with PayPal and GoDaddy. You can get there eventually, especially if you have an evidence trail.

Besides, if their Twitter tag has been extorted out of them then surely it would be easy to recover it legally and prosecute (if possible) those responsible.

Posted
Besides, who uses GoDaddy and surely they had a backup of their work off-server.

 

They have 31% of the market with ICANN - by far the largest share. So, a heck of a lot of people do it.

 

I would have gone 'nah' kept the Twitter tag and sorted it all out with PayPal and GoDaddy. You can get there eventually, especially if you have an evidence trail.

Besides, if their Twitter tag has been extorted out of them then surely it would be easy to recover it legally and prosecute (if possible) those responsible.

 

Indeed. I'd guess this would be a case for the FBI to deal with!

Posted

I'd have thought with those emails showing he was extorted in to it that would be proof enough (OK I know emails can be faked, but in this case to what gain). He could also draw on the proof of credit card details being changed, account info being changed to prove it was extorted.

With this being in the US (I assume) he'll no doubt sue the relevant companies and make money.

 

Plus, the username wasn't technically worth $50k. It might have been at that point in time one person offered him that amount, but surely it is only worth what someone is willing to pay at the present time.

Posted (edited)

Hmmm, and there was me thinking of moving most of my online life to my own domain. I better check with CSN as to how attack-proof I am. :/

 

Just updated my SOA TTL to a week...

Edited by CAM
Posted
Not quite the same money involved, but I had 100 domain names 'stolen' from me in a similar scam about 5 years ago :( lost the domains and the money
Posted
Amazon gave out the last 4 credit card digits and Apple took them as proof.

The owner of the Twitter username @jb had exactly the same thing happen to them. Amazon were to blame again. :eek:

 

I’m @jb on both Twitter and Instagram. So you can imagine my username is a very heavy target. It used to be primarily because of the Jonas Brothers but of course now it’s all related to Justin Bieber. As you can imagine, with the marketing power behind his name, there’s thousands if not more companies/hackers/etc… who’d love to get their grubby hands on it for profit.

 

It started when I received a forgot password email from Amazon. Forgot password emails are regular for me, because of my @jb username, but this was the first I had ever received from Amazon. “Why in the world would someone want that?” Twitter released feature awhile back ago that turns off the forgot password feature unless you have some specific information about the person. This was a godsend. Unfortunately Instagram has yet to implement something similar.

 

I of course ignored the first email from Amazon like I normally do with any forgot password emails I get that I didn't initiate. Imagine my surprise when I received a second email about an hour later saying that my password had been successfully changed! I also had 3 fresh forgot password emails from Apple. It was clear I was being targeted.

Posted (edited)

Here's GoDaddy's statement (via TechCrunch).

 

GoDaddy admits hacker’s social engineering led it to divulge info in @N Twitter account hack

 

GoDaddy Chief Information Security Office Todd Redfoot issued TechCrunch the following statement about the hack:

 

Our review of the situation reveals that the hacker was already in possession of a large portion of the customer information needed to access the account at the time he contacted GoDaddy. The hacker then socially engineered an employee to provide the remaining information needed to access the customer account. The customer has since regained full access to his GoDaddy account, and we are working with industry partners to help restore services from other providers.

 

Enabling two-factor authentication on your GoDaddy account seems to be a bit of a waste of time if the hacker can just call customer support and gain access to your domains.

 

Enabling Two-Step Authentication « GoDaddy

Edited by Arthur
  • 4 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...