Namecheap live chat social engineering leads to loss of 2 VPS
11–20 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#12Would anyone here seriously expect that someone in control of their email wouldn't be able to take control of associated accounts?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#13Re: Namecheap live chat social engineering leads to loss of 2 VPS
#14Re: Namecheap live chat social engineering leads to loss of 2 VPS
#15What legal consequences could there be for Namecheap, if any at all?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#16What legal consequences could there be for Namecheap, if any at all?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#17The most significant security problem with Namecheap is really this: It only takes a 4 digit PIN to perform any action on an account through live chat (which seems to be outsorced to Eastern Europe), even if the account is protected with a 2FA... All you need is the PIN, and an attacker can do anything to the account. Sometimes you get what you pay for.
If I wanted more security on my account, is there a different service I should be using?
I just wish that their DNS updates were push through faster.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#181) Offer an option to opt-out of all automated account recovery. If set, no more email resets, support PINs, or similar. This would be targeted at people truly care about security and have no issue with "forgetting passwords" (i.e. you use a password manager and you're not an idiot about backups).
2) Offer in-person, manual recovery. To participate in this you'd need to pre-register with full contact details (name/address/etc) of the valid people who could use this feature. The person would have to physically come to the office of the company, present two (or more) forms of identification. To add further security, you could add a mandatory wait period between initiating a reset and it taking effect (ex: min 7 days). That way a combination of fake ids and social engineering could (in theory) be stopped by getting an alert that "You initiated a manual reset of your XYZ account. Did you actually do this??"
EDIT: For #2 you could also add a non-trivial fee (say $500) that would need to be charged and cleared in advance of the person showing up.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#19The most significant security problem with Namecheap is really this: It only takes a 4 digit PIN to perform any action on an account through live chat (which seems to be outsorced to Eastern Europe), even if the account is protected with a 2FA... All you need is the PIN, and an attacker can do anything to the account. Sometimes you get what you pay for.
So what expensive provider do you recommend instead?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#20The most significant security problem with Namecheap is really this: It only takes a 4 digit PIN to perform any action on an account through live chat (which seems to be outsorced to Eastern Europe), even if the account is protected with a 2FA... All you need is the PIN, and an attacker can do anything to the account. Sometimes you get what you pay for.