Another credit-card-as-Authentication hack
This is a pretty
impressive social engineering story: an attacker compromised someone's
GoDaddy domain registration in order to change his e-mail address and
steal his Twitter handle. It's a complicated attack.
My claim was refused because I am not the "current
registrant." GoDaddy asked the attacker if it was ok to change account
information, while they didn't bother asking me if it was ok when the
attacker did it.
[...]
It's hard to decide what's more shocking, the fact that PayPal gave
the attacker the last four digits of my credit card number over the
phone, or that GoDaddy accepted it as verification.
The misuse of credit card numbers as authentication is also how Matt Honan got
hacked.
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.