Naoki Hiroshima was lucky enough to snag a one-character Twitter username: @N. Over the years, he'd been offered large sums -- as much as $50,000 -- for the name, but he kept it. Then, according to a horrifying first-person account, a hacker socially engineered the last four digits of his credit-card out of Paypal, used that information to seize control of his Godaddy account, and threated to trash all of Hiroshima's websites unless Hiroshima transferred @N to the hacker. The hacker also seized control of Hiroshima's Facebook account. The attack took place over the Martin Luther King, Jr day holiday, and Hiroshima couldn't get his case escalated to anyone at Twitter, Godaddy or Paypal while it was taking place, and so he lost his domain. All three companies now say that they're looking into his story. Hiroshima offers some helpful advice on avoiding his fate (use two-factor authentication, mostly).
I'd add that it's generally good practice to avoid Godaddy, because they're SOPA-supporting sellout scum, and they suck.
I later learned that the attacker had compromised my Facebook account in order to bargain with me. I was horrified to learn what had happened when friends began asking me about strange behavior on my Facebook account.
I received an email from my attacker at last. The attacker attempted to extort me with the following message.
From: SOCIAL MEDIA KING
To: <*****@*****.***> Naoki Hiroshima
Date: Mon, 20 Jan 2014 15:55:43 -0800
I’ve seen you spoke with an accomplice of mine, I would just like to inform you that you were correct, @N was the target. it appears extremely inactive, I would also like to inform you that your GoDaddy domains are in my possession, one fake purchase and they can be repossessed by godaddy and never seen again D:
I see you run quite a few nice websites so I have left those alone for now, all data on the sites has remained intact. Would you be willing to compromise? access to @N for about 5minutes while I swap the handle in exchange for your godaddy, and help securing your data?
How I Lost My $50,000 Twitter Username [Naoki Hiroshima/Medium]
(via Hacker News)
(Image: Blackmail, a Creative Commons Attribution Share-Alike (2.0) image from jeanette4's photostream)
The Internet Archive’s Brewster Kahle writes, “We founded a credit union to build a new path after the banking debacle of 2008 and it’s been crushed by federal regulators. The regulators close 200-300 credit unions every year, and have been since their founding of the NCUA in 1970. Only a couple are allowed to start […]
A leaked recording made of a conference call hosted by the Edison Electric Institute, which lobbies for the power industry, reveals lobbyists for high pollution companies talking about how they can exploit the Syrian refugee crisis to get a rider inserted into a pending bill that would kill the EPA’s Waters of the United States […]
The barb in trade agreements’ tail is the Investor State Dispute Settlement (ISDS) system, which lets companies sue governments to repeal rules that interfere with their profitability. It’s let tobacco giants fight anti-smoking campaigns, and now it’s letting fisheries attack rules aimed at preventing the wholesale slaughter of dolphins.
Don’t get handcuffed by Apple’s standard 3-foot Lightning cord (that you’ve most likely already lost), treat yourself to 10 feet of luxurious charging convenience. The Colossal is certified by Apple for its high-end quality, and designed to support full use of your phone while you power up. You can also get it in a 2-pack […]
Today and tomorrow only we are offering an additional 15% off the entire Boing Boing store (some exclusions may apply). Simply use coupon code: BLACKFRIDAY at checkout! Below are a few of our favorites from the store: First Generation Lytro 16GB Camera: The First Consumer Camera to Capture the Entire Light FieldAdobe Training Videos: Lifetime Subscription: 6,000+ Adobe […]
Today only in the Boing Boing Store we are offering an extra 15% off of the below VPN deals just use coupon code: VPN15 at checkout. proXPN VPN: Premium Lifetime Subscription Surf the web with ultimate peace of mind – both at home and on the road – over proXPN’s fully-encrypted, lightning-fast servers. Your lifetime premium subscription […]