Shits & giggles for the rest of us

I’m not going to post everything that has been going on yesterday and today (yet) as the hackers are reading my Tumblr.  I have to share some amusing and quite public links.

Meet my hacker “Isolate.” This is the person who hacked most of my digital life so he could try to sell @ruby for $80. I alerted Twitter about his account this over an hour ago. It’s obviously fine with them to hack other people’s accounts AND brag about it with their service. 

image

Poor guy is concerned that I am giving some clueless teenager credit for his brilliant social engineering hack. Don’t worry d00d, it’s pretty obvious when you read the conversations at Hack Forums where Isolate first asks what it’s worth (the page has been removed, but I saved it), then trades it to —— J —— (Jacob Glickman) for a YouTube ID. Then —— J —— tries to sell it even though the other hackers are telling him that it belongs to someone else (me) and even tell him to read my Tumblr.

Jacob then contacted me offering to get me back the account. He even tried to get me to e-mail him by putting his address in my Twitter bio. Not only was it not his to give, he would never have been able to restore my posts and followers, as Twitter eventually rightfully did.

Here is the best of all, —— J —— now files a complaint against Isolate for ripping him off! Have fun, you guys!

I’m baaack!

Last night at about 12:30 am I recovered access to my web hosting account at Dreamhost. This contains personal and professional websites and e-mail accounts for me, and several former clients and employers. Importantly, this allowed me to get back the only address through which Twitter would talk to me.

So early this morning I was able to recover access to @ruby, hurrah. There’s a little bug where on my profile I have no followers nor following:

But on my followers page, I see all the correct numbers:

Hopefully this will all be cleared up soon. I cannot strongly enough express my gratitude to all the people that spoke out and even fought for me in the last couple of days. 

Stay tuned for future posts about the losers who did this. I have some really funny e-mails and things to share. 

@ruby for sale

A few people now have contacted me about the hacker forum where my Twitter name (with no tweets and no followers) is now available for the low, low price of $70!

image

You have to register on the forum to see it, but the URL is http://www.hackforums.net/showthread.php?tid=3508538 in case you’re curious.

My friend Christina actually logged in. She says the person selling it presents as a 17 year old male form NY, and he says the person who hacked me traded the ID to him. Then my friend Jackson also logged in to the forum and took these amazing screenshots:

Really, Twitter?

You don’t think you can do anything about this? Cause you’re not sure if the account maybe doesn’t belong to the person in control of it? Really???

Thanks to Travis C for the tip about the new Twitter bio.

In case anyone is curious, I’m not going to buy my own account back from some juvenile criminal. Twitter needs to do right and restore this account properly.

Tickets, please

A few folks have asked for my support ticket numbers with Twitter and Dreamhost to follow up. I’m a little nervous about posting them publicly as the hacker might try to engineer that against me.

If you have a contact at either company and would like the ticket number, either comment on this post and I’ll reply to you at the e-mail on your Disqus account, or use Tumblr’s Ask-me-a-question thingy and I’ll send them privately (if I know you).

One last try

Hello, friends. Many of you have helped me by reaching out to your personal contacts who work at Twitter or Dreamhost, and some have even written angry letters to them. I appreciate this support. Although it hasn’t had any visible impact yet, there must be a point at which it can break through the wall.

I can understand that they don’t know if I’m really me, but many of you actually know me. You are friends here in NC, you are colleagues in nonprofit tech, and you have been following me on Twitter for 6 years or more. And you know that I would never do this:

image

When my account used to look almost like this (the screenshot was taken after the hacking started, but before the account was wiped out):

image

As I posted earlier, my next step is going to be contacting the FBI and it really does not sound like fun. I can barely keep up with my life as it is (family, job, changing passwords on every account ever, etc.) without making a campaign out of this, so I need your help. I’d like to ask everyone to make one last attempt to reach some human beings at Twitter and especially at Dreamhost. Even if you don’t know anyone who can intervene directly, just retweet/share the link to this page.

Background:

Ever since reading last year about the epic hacking of Mat Honan , all for his short Twitter ID “@Mat” I have been worried the same thing might happen to me. Fortunately, I haven’t handed over quite as much of my life to Apple as Mat had done. But I still get nervous whenever people try to hack into my Twitter account, which has been tried repeatedly. Twitter has always ignored my requests for attention to this.

That shit did hit the fan this weekend. I managed to restore several key accounts and nothing has been irreversibly damaged that I know of (yet). However, I am still locked out of Twitter and even worse my entire Dreamhost account (including domain names, e-mail addresses, and web sites) are in the hands of my hacker.

Catch 22

So Twitter will only respond to ruby@lotusmedia.org, which was associated with @ruby.  The hackers changed @ruby to @notrubyyo, and then deleted it. Who knows what address they have associated with the new @ruby account?

My Dreamhost account (which includes lotusmedia.org DNS) has been hacked and they are also not talking to me because I haven’t successfully proven who I am to them. (Only their customer of about 12 years.)  Their password reset only uses e-mail, no security questions or SMS back up.

Dreamhost are also much slower to respond when they think I’m not a customer so it’s taking forever to get anywhere, and they refuse to talk on the phone.

Dreamhost gives me the finger

After being a loyal customer for well over ten years, Dreamhost is apparently brushing me off like so much dandruff.  I can’t understand why they’re not concerned about a known malicious hacker having access to their web servers, DNS, e-mail servers, etc. 

As you have not provided the primary four digits of the account number in
question, I am unable to verify that this card is on file.

On Tue, 28 May 2013, you wrote:

> Hello? You stopped responding. I can’t express to you the level of
> additional damage that is possible while the hackers are in control of my
> web spaces and domain names!
>
> Would it be better to call? My number is XXX-XXX-XXXX.
>
> = Ruby

Unfortunately, due to documentation requirements, phone call back support
is unavailable for abuse and security related issues.

If you have any further questions regarding your DreamHost services,
submit a support request at any time.

Sincerely,

Erik N.

And since I can’t get to my address at ruby@lotusmedia.org, Twitter (where I have been a user since 2006) won’t even talk to me. No concern at all about the loss of 17k tweets and 3k followers. When I get home I will tear up the house trying to find whatever freaking credit card I’ve had on my Dreamhost account forever.