How I got my username on nearly every site
shkspr.mobi
shkspr.mobi
And because of that you'll use it to acquire even more usernames.
You opened a dispute to take someone's chat/telegram name... Not cool. What if the person was active but just didn't want to reply to you? Why would they, you don't own the rights to that username. What if they were away for personal or health reasons temporarily?
You're not a brand. You're not a product. You're someone who has those letters in your name, just like I'm sure a lot of other people.
What gives you the right to claim those usernames more than anyone else? In some cases it seems what gives you the right is just the fact that you bothered support, or opened disputes, to give you a name on another service then used that fact to get more of them.
A lot of these seem like security nightmares. I'm glad someone did the research at this small expense.
These comments are barking up the wrong tree. Nobody here is lambasting these companies for having such horrifying policies that ensure anyone targeting you is basically guaranteed to snatch up your username.
If you want to keep your username, the lesson here is to read the T&Cs and comply with them.
And, as I say several times in the blog post, I don't have the right to those combination of letters.
And I'm not sure that abusing an unethical system waives you from the morality of your actions.
The only lesson you're giving here is about you. But hey, any publicity is good publicity right? You're enforcing your 'brand' after all. \s
Absolutely. You should never agree to something you haven't read.
I will not believe you if you state that you read the TOS for every site you register on, every program you install.
[2] https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2757465
It’s one thing to say “I’m raising a risk.” It’s another to blame the victim.
These services should publicise their name dispute policies more openly. But, ultimately, they can enforce their private property rights on the usernames they control.
You may not have written the policies, but you can certainly choose when to enforce them. You waited only a week for Soundcloud, even when you knew it was ridiculously short. For linkedin you went and 'politely' asked the active owner to transfer, telling him to his face he didn't have to, and when he refused you still went to check if you could force it by using a ToS.
Don't hide behind the policies, you are making the calls.
If somebody did that to me, I would be really upset. Therefore, I am not going to do that to somebody else, even if the terms and conditions of the site allow it to happen.
You should listen to your conscience when you "feel guilty" about something.
He was asking for something he was probably not entitled to, was open and honest about that fact and various services turned the usernames over to him.
Imagine what someone with ill intent and using fraudulent means could do.
All of that fluff does nothing to cover up what an absolute dick move this was.
What are you going to do to protect your accounts now you have that knowledge?
[Edit] Corrected typo in Terence's name.
If it was in isolation, say 'it takes 48 hours to take a username from SoundCloud' then I couldn't care less, but showing it happen on multiple sites and how they address it does make one think.
When YouTube first started giving out names, Google+ didn't exist.
Then there was the merger of Google accounts with YouTube, then there was the merger of Google+ profiles and posts with YouTube profiles and comments to inflate G+'s stats and force people to use it. Despite all that churn, I don't think old YouTube usernames from 2006 ever stopped working.
I'll correct the post. Thanks!
I imagine, somewhere, a family with a dead relative, 'Emily Dent' in my head-cannon, is trying to login to their edent to download the family album to no avail.
But, more seriously, I've only claimed inactive accounts. If There was activity on them - or any content - I'd be less inclined to proceed.
I know Facebook and Twitter have memorialised account options which prevent them being taken over. I wonder how many other sites are so considerate.
Here in the UK, it is common for phone numbers to be recycled. Which is distressing when you start receiving text messages from a dead relative.
I think it'd be helpful to have a better definition of "inactive." If the user hasn't posted anything ever, and they don't respond, then sure, that's hard to defend. I think that's fair. But if the user has posted content/code/whatever, it's unfair at best and ethically reprehensible at worst, especially in cases where there isn't a memorialized option, to take over their account just because they don't respond to an email within the window of the ToS. There are lots of things that are technically allowed by law or policy that don't make one that takes advantage of them any less of a subjectively terrible person.
If you had approached this from a perspective of "look what can happen to your account" as a security research experiment, that would have been received better than "look at all the people, including those deceased/incapacitated people whose loved ones may be heartbroken, that lost their accounts to me so that I can have a vanity username."
NPM - the account had no activity on it. No code, no linked accounts, and no avatar.
SoundCloud - completely dormant account. They'd posted no content. They had no public activity.
Telegram - user didn't appear responsive. I hold my hands up on this one, it might have been someone using the account.
Those were the only three accounts I could claim. I was not able to claim any accounts which were in use, or had content on them.
And, like you, I think these services should have a better way of protecting accounts.
I'm sure there are some accounts which appear inactive - but have the user regularly logging in an performing invisible actions like upvoting, private messaging etc. I would not expect those accounts to be recycled.
Then maybe they should include that in ToS, See how many signup.
Telegram - https://telegram.org/faq#usernames-and-t-me
NPM - https://www.npmjs.com/policies/disputes
Github - https://help.github.com/en/articles/name-squatting-policy
Most sites have similar wording.
The first paragraph of your post... "I quite often sign up to things just to snag the name."
GitHub: "GitHub account name squatting is prohibited."
Telegram: "we reserve the right to recall usernames assigned to unused bots and channels, as well as openly squatted usernames"
NPM: "Don't squat on package names, user names or organization names."
Dick move.
They often already claim ownership over every single byte you send them, disavow any responsibility for their actions, and in the cases where local laws force them to be responsible, will force arbitration on you. Half of my digital life would be lost right now if I did a $1 chargeback against Google and there is literally nothing I could do about it aside from proactive things like leaving their platform beforehand.
The funny thing is - dang (AKA gruseom) appropriated his username from a dormant account:
> To dispute a user name [...] After 4 weeks, if the owner has not responded, support will address your request. The ultimate outcome is at their discretion and judgement.
And this statement on squatting confirms that it would be 'extremely unlikely':
> We are extremely unlikely to transfer control of a user name, as it is totally valid to be an npm user and never publish any packages: for instance, you might be part of an organization or need read-only access to private packages. If a user has not logged into their account in a long time, we may consider transferring a name if it is requested by a new user.
I don't often wish for legislative resolutions to social ills, but if anything needed a law, it's this. Maybe California or the EU will take up the torch. Ideally both, I don't want companies evading these kinds of things by bifurcating their userbases.
I recommend you do the same.
Having a unified identity is a risk - but having a unique identity is not risk-free.
Looking at your .tel page i can tell that you don't have any issues with being tracked all over the internet.
For other stuff, I take your approach and use diverse aliases.
One of the first places this was recognized is email addresses. Reassign the email address username, and the new person might receive sensitive email intended for another person, and also impersonate them for some purposes, accidentally or intentionally.
(Additionally, today, with all the creepy mass intimate profiling that's going on, both parties linked to the same address could have their profiles tainted in ways undesirable to them.)
A service transferring usernames to another party, simply because that party would like to have that particular username (not because of some separate transfer of some functional role), seems questionable security. I'm surprised the first example from the article, NPM (who should be security-paranoid right now), would permit something like that, as a matter of policy, even if it wasn't obviously a direct threat in this instance. And then the next example -- Telegram -- is also a concern.
I use a unique email address and password for each account, and 2FA where possible. I don't think the public username being consistent is too much of a risk.
That said, I do also have random non-associated accounts, just like you.
I rarely go through these flows myself so I don't know what they reveal or are capable of. I'd rather be anonymous
A lot of the cases where a reset flow was initiated, the real goal seems to be to get email or SMS access. (IE, you may want to check your email provider for failed login attempts after a reset flow email.) Sometimes it is useful to check those flows yourself for such leaks and report it to site owners. (Though my experience so far, many of them seem nonplussed about it more often than not.)
Some of the reset flow emails at this point aren't even real, they are increasingly elaborate spear phishing schemes to get you to worry about your account security enough that you might follow a link directly from the email (to a phishing login) to "report that you did not request a reset" in some way or another.
Also, I'm sure some of them are initiated just for graffiti/broken-windows/anxiety-creation reasons. They want you to know they were trying to get your account.
ETA: Also, initiating password recovery flows can be a step in trying to social engineer access from a customer service rep. ("I started the recovery process, but never got the email." "Yes, I can see that you started the process, let me see what I can do...")
For example, someone camped on the twitter name for progscrape.com (twitter.com/progscrape) and then got it suspended. Twitter won't release a name like that unless you've specifically got a registered trademark. That's pretty expensive for a side-project.
There _should_ be a balance in releasing names in a global namespace, but it should err in the side of not taking names away from legitimate users.
A one-year waiting period is probably a decent balance.
This was sparked off by Tumblr emailing me asking if I was happy to relinquish an old, abandoned account.
Can we use our domain name as our username on twitter? Is dot a restricted character?
So no domain-names-as-usernames there.
Yet twitter never seems to release the inactive account, despite claiming they may permanently remove inactive accounts. I’ve reached out to the owner several times; no response. I’ve considered resorting to blackhat solutions and taking matters into my own hands.
In my case, my employer wanted an account which was inactive. We reached out to our brand partner (I think) and discussed it with them. They didn't tell us what methods they used to verify the account was dormant, but they did ask us to prove our trademark etc.
A few weeks later we got the account.
Now, that's with a fairly standard trademark dispute - it will probably be harder if you don't have a tm.