{"id":8393,"date":"2014-01-29T11:59:08","date_gmt":"2014-01-29T16:59:08","guid":{"rendered":"http:\/\/mjtsai.com\/blog\/?p=8393"},"modified":"2021-07-03T14:19:26","modified_gmt":"2021-07-03T18:19:26","slug":"twitter-username-stolen-thanks-to-paypal-and-godaddy","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2014\/01\/29\/twitter-username-stolen-thanks-to-paypal-and-godaddy\/","title":{"rendered":"Twitter Username Stolen Thanks to PayPal and GoDaddy"},"content":{"rendered":"<p><a href=\"https:\/\/medium.com\/p\/24eb09e026dd\">Naoki Hiroshima<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=7141532\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/medium.com\/p\/24eb09e026dd\"><p>I tried to log in to my GoDaddy account, but it didn&rsquo;t work. I called GoDaddy and explained the situation. The representative asked me the last 6 digits of my credit card number as a method of verification. This didn&rsquo;t work because the credit card information had already been changed by an attacker. In fact, all of my information had been changed. I had no way to prove I was the real owner of the domain name.<\/p><\/blockquote>\n<p>He recommends two-factor authentication, not storing credit card information with your accounts (to prevent it from being used for fraudulent verification), and not using a custom domain for your e-mail address of record.<\/p>\n<p>Update (2014-01-30): GoDaddy requires a valid payment method for each domain. So you cannot actually remove your credit card information (unless you replace it with your bank information), and you cannot enter an invalid card number. You can, however, have your card issuer generate a single-use number and enter that, even if the number has already been used elsewhere.<\/p>\n<p>Update (2014-01-31): <a href=\"https:\/\/www.paypal-forward.com\/leadership\/paypal-takes-your-security-seriously\/\">PayPal<\/a> \n(via <a href=\"http:\/\/thenextweb.com\/insider\/2014\/01\/29\/paypal-denies-providing-payment-information-hacker-hijacked-50000-twitter-username\/\">Emil Protalinski<\/a> and <a href=\"https:\/\/news.ycombinator.com\/item?id=7150158\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.paypal-forward.com\/leadership\/paypal-takes-your-security-seriously\/\"><p>PayPal did not divulge any credit card details related to this account.<\/p><\/blockquote>\n<p><a href=\"http:\/\/hackticool.com\/post\/75171875746\">Josh Bryant<\/a>:<\/p>\n<blockquote cite=\"http:\/\/hackticool.com\/post\/75171875746\"><p>I read this tonight, and sadly, the story was all to familiar to me. My version also has a few implications that are far worse.<\/p><\/blockquote>\n<p>Update (2014-02-26): <a href=\"http:\/\/thenextweb.com\/twitter\/2014\/02\/26\/happy-ending-n-restored-rightful-owner\/\">Josh Ong<\/a> (via <a href=\"http:\/\/daringfireball.net\/linked\/2014\/02\/26\/twitter-n\">John Gruber<\/a>):<\/p>\n<blockquote cite=\"http:\/\/thenextweb.com\/twitter\/2014\/02\/26\/happy-ending-n-restored-rightful-owner\/\"><p>It remains to be seen what exactly took place behind the scenes at <a href=\"http:\/\/thenextweb.com\/insider\/2014\/01\/29\/paypal-denies-providing-payment-information-hacker-hijacked-50000-twitter-username\/\">PayPal<\/a> and <a href=\"http:\/\/thenextweb.com\/insider\/2014\/01\/30\/godaddy-accepts-partial-responsibility-social-engineering-attack-ns-customer-account\/#!xyscM\">GoDaddy<\/a>, and why it took so long for <a href=\"http:\/\/thenextweb.com\/twitter\/2014\/01\/30\/the-original-owner-of-n-still-hasnt-got-his-twitter-account-back-someone-else-snapped-it-up\/\">Twitter<\/a> to decide to return the account to its original owner, at least we&rsquo;ve arrived at a happy resolution for this particular saga.<\/p><\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Naoki Hiroshima (via Hacker News): I tried to log in to my GoDaddy account, but it didn&rsquo;t work. I called GoDaddy and explained the situation. The representative asked me the last 6 digits of my credit card number as a method of verification. This didn&rsquo;t work because the credit card information had already been changed [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-07-03T18:19:29Z","apple_news_api_id":"0a03eb8c-2bcc-4f41-b807-c2e3f2863ae7","apple_news_api_modified_at":"2021-07-03T18:19:29Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/ACgPrjCvMT0G4B8Lj8oY65w","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[19,728,747,170,48,49,2090],"class_list":["post-8393","post","type-post","status-publish","format-standard","hentry","category-technology","tag-amazon","tag-domain-name-system-dns","tag-godaddy","tag-paypal","tag-security","tag-twitter","tag-two-factor-authentication-2fa"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/8393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=8393"}],"version-history":[{"count":7,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/8393\/revisions"}],"predecessor-version":[{"id":33015,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/8393\/revisions\/33015"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=8393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=8393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=8393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}