Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

41–50 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#41
post #26

Earlier quoted context omitted.

https://www.gandi.net/

They're cool until they start holding your domains hostage and demanding that you email them a scan of your passport.

I've had process issues like this with them; their CEO is responsive on email/Twitter and the email alias on this page: http://www.gandi.net/no-bullshit gets things fixed. They're not perfect, but they are quite human.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#42
post #25

Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…

Second biggest lesson here: do not use weak passwords for emails.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#43
post #25

Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…

We offer full backups with all managed servers/services Self-managed a customer is responsible for their own backups. Just like with DO and that full server loss a couple of months back.

We who?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#44

Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place.

>Also let me reiterate this is an isolated event.

Is it? Does that mean that my ability to reset your users solusvm passwords with or without 2fa constitutes as a 1337 0day?

Hey BTW, remember that time you got hacked through your support site and didn't tell anyone?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#45

the first error was buying server space from namecheap. good domain server but they get hit frequently being a midsize provider of services, they have enough bait and not enough people to protect it.

That doesn't really make sense. We're a great domain and hosting provider.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#46

Earlier quoted context omitted.

We offer full backups with all managed servers/services Self-managed a customer is responsible for their own backups. Just like with DO and that full server loss a couple of months back.

We who?

Matthew Russell is the VP of Hosting at Namecheap https://www.namecheap.com/about/team.aspx

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#47
post #28

Earlier quoted context omitted.

That's not good verification. It takes a couple of minutes to produce convincing fake ID scans, and they aren't going to have anything to verify them against. And presumably they wanted you to send those photos to them as an unencrypted email attachment, right?

its better verification than most will require.

Most will require a password reset email, I'd say that's significantly better than asking for ID scans.

Edit: Since I'm getting some downvotes I'd really like to know how one could possibly argue that asking for ID scans is better than email resets. You can't really forge the ability to receive email at an address, but you can very easily replace the name on an ID scan.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#48
post #12

I for one haven't seen very many services that don't allow you to reset your 2fa if you control the attached email. Would anyone here seriously expect that someone in control of their email wouldn't be able to take control of associated accounts?

I think this is a very good point that I also overlooked when I first read the article. If someone hacked my gmail account, I honestly am not sure if there would be any account of mine that would be safe. Anyone using the Internet today has to put utmost care into protecting their email address and most email providers enable you to do that fairly easily. There was an article here a few months ago promoting logging in via email token as the only way to log in instead using passwords. Because as you said, 99% of websites allow you to reset the password anyway if you control email, so why bother having insecure passwords? If I remember correctly then that article was fairly well received.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#49
post #7

On another note, there 2FA seems to broken as well. I once received a text about resetting my Instagram account from the same number that they send me to authenticate my login session. I've never had an Instagram account.

Namecheap uses the same 2FA provider as Tumblr, Yahoo, Microsoft, and a slew of other services.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#50
I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log you out of the portal, another big problem) so I immediately knew what was happening.

I wish there was a way to disable the "customer support backdoor" in all these kinds of services. I've started to deploy full disk encryption to all my servers now so if the attacker does manage to get into the management account the server itself is still protected from single user / rescue mode / etc.

Post reply on HN