Then I can come back here and post nasty comments about squatters.
Then I can come back here and post nasty comments about squatters.
The guy has given a clear and convincing story of what happened. I'm sure that it would be pretty easy for someone on Twitter's security team (assuming that they have one) to verify that the username was taken when he said it was.
I don't know what I find more shocking -- that PayPal would actually give the last four digits of a credit-card number to a complete stranger, that GoDaddy would let someone guess a two-digit number, or that a credit-card number is all you need to identify yourself. (In Israel, it's common for companies to ask for the last four digits of your credit card number in addition to other details, but never on its own.)
Actually, I'm willing to believe just about anything about GoDaddy. But PayPal is known for being surprisingly harsh and paranoid about security, shutting down accounts and holding money when they suspect problems. It's sad and rather surprising to me that they're willing to give out such information so easily, unless you specifically ask them not to. Shouldn't it be the other way around, that they refuse to provide such details unless you allow them to?
I really hope that Twitter and PayPal apologize profusely to this author, and undo the damage they've done as best as possible.
Twitter should look into what happened in this specific case, and somehow (if the posting is right) return the username to its original owner.
But there does seem to be something terribly broken here if it's possible for someone to get another person's Twitter account, and for it to take a full investigation to get it back to the original owner. And for not having better procedures in place, I think that an apology wouldn't be unreasonable.
In general, it seems to me that demonstrating empathy for your customers is a pretty reasonable strategy. Even if they didn't do anything wrong, and before they have finished this investigation, they can show that they care about the people using their system.
I don't think that Twitter could go wrong by saying, "We now see that we need to make it harder for scammers to switch the ownership of a Twitter account, and are looking into how to do so without hurting our legitimate users."
Just for the record, I have no reason to believe he's saying anything less than the truth - but I can't fault Twitter for basically presuming malice until they have conclusively documented the opposite.
The grandfather post is referencing asymmetric warfare[0] which would be a pretty decent name for what could happen. I don't think he just threw some cliches into a sentence.
Perhaps he has something against GoDaddy (many do) and/or PayPal (again, many do) so took the opportunity to make them look bad by making sure that their effective complicity in the hack is well known.