Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

31–40 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#31
Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#32
post #18

What's this crowd think of this idea for solving this problem? 1) Offer an option to opt-out of all automated account recovery. If set, no more email resets, support PINs, or similar. This would be targeted at people truly care about security and have no issue with "forgetting passwords" (i.e. you use a password manager and you're not an idiot about backups). 2) Offer in-person, manual recovery. To participate in thi…

We do something similar at Silent Circle. In your recovery options, there's a page with a high-entropy secret key and a QR code that you can print out to use if you ever forget your password.

There's also a checkbox that says "don't ever recover this account" (i.e. the "I have a password database on Dropbox") checkbox. Checking that box actually disables password resets on the admin interface, so your account is pretty much dead if you lose the password.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#34
post #23
post #13

I'd love to have an option on services where I define a X-hour wait period for manual password resets. That is, "oh, I've lost my email account and I need to reset a password so I have to access my account through pleading over Live Chat... they can do that but there's an X-hour wait period before you will gain access to the account."

Which is great until the customer actually needs to access the account. $CUSTOMER calls in, their nameservers are down and nobody has the account password. Do you think the management at $CUSTOMER is going to accept "hey we need to wait 6 hours to get our site back up because namecheap wont allow us in"?

Let the customer set it during sign-up as part of the password reset process. You set up your email address and password, let them choose $HOURS for last-line-of-defense password reset.

I don't see any perfect answer here. Ultimately you need a way to recover your account when you've lost all of the "somethings you have" and you've lost your "something you know", but then that allows a social engineer access to do the same. So let the user decide during sign-up.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#35
post #25

Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…

We offer full backups with all managed servers/services

Self-managed a customer is responsible for their own backups. Just like with DO and that full server loss a couple of months back.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#37
post #26

Earlier quoted context omitted.

https://www.gandi.net/

They're cool until they start holding your domains hostage and demanding that you email them a scan of your passport.

> email them a scan of your passport

What? Why do they do this?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#38
post #26

Earlier quoted context omitted.

https://www.gandi.net/

They're cool until they start holding your domains hostage and demanding that you email them a scan of your passport.

Without context, anybody could say the same thing about anything. Care to share more?

I personally haven't had this happen to me. I've hosted dozens of domains with gandi, under a variety of different TLDs, and can only recommend them.

Cons: Slow website. Bad UX all over the admin/purchasing interface. Feels like they're not doing anything to improve that.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#39
post #28

Earlier quoted context omitted.

I once lost my gandi.net password. It took sending copies of 2 photo id, and answering the phone listed in the who is database before they reset it. I just wish that their DNS updates were push through faster.

That's not good verification. It takes a couple of minutes to produce convincing fake ID scans, and they aren't going to have anything to verify them against. And presumably they wanted you to send those photos to them as an unencrypted email attachment, right?

its better verification than most will require.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#40
post #26

Earlier quoted context omitted.

https://www.gandi.net/

They're cool until they start holding your domains hostage and demanding that you email them a scan of your passport.

They publish a GPG key to use for this purpose, which puts them leaps and bounds ahead of most other hosting/domain providers who do identify verification.
Post reply on HN