Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There usually isn't activity on dead people's accounts that are memorialized. I'd be incredibly heartbroken if someone took my deceased younger brother's accounts because he's "inactive".


I'm sorry for your loss.

I know Facebook and Twitter have memorialised account options which prevent them being taken over. I wonder how many other sites are so considerate.

Here in the UK, it is common for phone numbers to be recycled. Which is distressing when you start receiving text messages from a dead relative.


Another anecdote: a friend recently had a stroke and was unable to use his phone or computer for many months. I'm sure his grieving, caregiving family members were not thinking about the ToS specifics of his social media accounts to make sure he didn't lose his memories and identity online.

I think it'd be helpful to have a better definition of "inactive." If the user hasn't posted anything ever, and they don't respond, then sure, that's hard to defend. I think that's fair. But if the user has posted content/code/whatever, it's unfair at best and ethically reprehensible at worst, especially in cases where there isn't a memorialized option, to take over their account just because they don't respond to an email within the window of the ToS. There are lots of things that are technically allowed by law or policy that don't make one that takes advantage of them any less of a subjectively terrible person.

If you had approached this from a perspective of "look what can happen to your account" as a security research experiment, that would have been received better than "look at all the people, including those deceased/incapacitated people whose loved ones may be heartbroken, that lost their accounts to me so that I can have a vanity username."


Perhaps I should have made myself more clear in the blog post.

NPM - the account had no activity on it. No code, no linked accounts, and no avatar.

SoundCloud - completely dormant account. They'd posted no content. They had no public activity.

Telegram - user didn't appear responsive. I hold my hands up on this one, it might have been someone using the account.

Those were the only three accounts I could claim. I was not able to claim any accounts which were in use, or had content on them.

And, like you, I think these services should have a better way of protecting accounts.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: