Namecheap live chat social engineering leads to loss of 2 VPS
31–40 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#32What's this crowd think of this idea for solving this problem? 1) Offer an option to opt-out of all automated account recovery. If set, no more email resets, support PINs, or similar. This would be targeted at people truly care about security and have no issue with "forgetting passwords" (i.e. you use a password manager and you're not an idiot about backups). 2) Offer in-person, manual recovery. To participate in thi…
There's also a checkbox that says "don't ever recover this account" (i.e. the "I have a password database on Dropbox") checkbox. Checking that box actually disables password resets on the admin interface, so your account is pretty much dead if you lose the password.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#332. not deleting the mail with the login information
3. not having a backup
Yeah. This was just as much your fault.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#34I'd love to have an option on services where I define a X-hour wait period for manual password resets. That is, "oh, I've lost my email account and I need to reset a password so I have to access my account through pleading over Live Chat... they can do that but there's an X-hour wait period before you will gain access to the account."
Which is great until the customer actually needs to access the account. $CUSTOMER calls in, their nameservers are down and nobody has the account password. Do you think the management at $CUSTOMER is going to accept "hey we need to wait 6 hours to get our site back up because namecheap wont allow us in"?
I don't see any perfect answer here. Ultimately you need a way to recover your account when you've lost all of the "somethings you have" and you've lost your "something you know", but then that allows a social engineer access to do the same. So let the user decide during sign-up.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#35Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
Self-managed a customer is responsible for their own backups. Just like with DO and that full server loss a couple of months back.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#36Re: Namecheap live chat social engineering leads to loss of 2 VPS
#37Re: Namecheap live chat social engineering leads to loss of 2 VPS
#38Earlier quoted context omitted.
https://www.gandi.net/
They're cool until they start holding your domains hostage and demanding that you email them a scan of your passport.
I personally haven't had this happen to me. I've hosted dozens of domains with gandi, under a variety of different TLDs, and can only recommend them.
Cons: Slow website. Bad UX all over the admin/purchasing interface. Feels like they're not doing anything to improve that.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#39Earlier quoted context omitted.
I once lost my gandi.net password. It took sending copies of 2 photo id, and answering the phone listed in the who is database before they reset it. I just wish that their DNS updates were push through faster.
That's not good verification. It takes a couple of minutes to produce convincing fake ID scans, and they aren't going to have anything to verify them against. And presumably they wanted you to send those photos to them as an unencrypted email attachment, right?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#40Earlier quoted context omitted.
https://www.gandi.net/
They're cool until they start holding your domains hostage and demanding that you email them a scan of your passport.