Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

11–20 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#13
I'd love to have an option on services where I define a X-hour wait period for manual password resets. That is, "oh, I've lost my email account and I need to reset a password so I have to access my account through pleading over Live Chat... they can do that but there's an X-hour wait period before you will gain access to the account."

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#17
post #6
post #2

The most significant security problem with Namecheap is really this: It only takes a 4 digit PIN to perform any action on an account through live chat (which seems to be outsorced to Eastern Europe), even if the account is protected with a 2FA... All you need is the PIN, and an attacker can do anything to the account. Sometimes you get what you pay for.

If I wanted more security on my account, is there a different service I should be using?

I once lost my gandi.net password. It took sending copies of 2 photo id, and answering the phone listed in the who is database before they reset it.

I just wish that their DNS updates were push through faster.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#18
What's this crowd think of this idea for solving this problem?

1) Offer an option to opt-out of all automated account recovery. If set, no more email resets, support PINs, or similar. This would be targeted at people truly care about security and have no issue with "forgetting passwords" (i.e. you use a password manager and you're not an idiot about backups).

2) Offer in-person, manual recovery. To participate in this you'd need to pre-register with full contact details (name/address/etc) of the valid people who could use this feature. The person would have to physically come to the office of the company, present two (or more) forms of identification. To add further security, you could add a mandatory wait period between initiating a reset and it taking effect (ex: min 7 days). That way a combination of fake ids and social engineering could (in theory) be stopped by getting an alert that "You initiated a manual reset of your XYZ account. Did you actually do this??"

EDIT: For #2 you could also add a non-trivial fee (say $500) that would need to be charged and cleared in advance of the person showing up.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#19
post #2

The most significant security problem with Namecheap is really this: It only takes a 4 digit PIN to perform any action on an account through live chat (which seems to be outsorced to Eastern Europe), even if the account is protected with a 2FA... All you need is the PIN, and an attacker can do anything to the account. Sometimes you get what you pay for.

> Sometimes you get what you pay for.

So what expensive provider do you recommend instead?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#20
post #2

The most significant security problem with Namecheap is really this: It only takes a 4 digit PIN to perform any action on an account through live chat (which seems to be outsorced to Eastern Europe), even if the account is protected with a 2FA... All you need is the PIN, and an attacker can do anything to the account. Sometimes you get what you pay for.

[deleted]
Post reply on HN