Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

51–60 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#51
The lesson here is you should always keep your own off-site backups - especially if you don't pay for a 'managed' server.

There will always be rare occasions such as this, but considering how many customers Namecheap handle, I don't think we should be seriously concerned. I'm pretty confident lessons will be learned.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#52
post #27

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

> Established procedure was not followed Why have a procedure if your support doesn't follow it? Even if you have a procedure, everything falls apart when it isn't followed. This is the same as having no procedure at all.

Hopefully because the majority will follow it? We have no statistics on this, just this one case that failed.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#55
post #37
post #26

Earlier quoted context omitted.

They're cool until they start holding your domains hostage and demanding that you email them a scan of your passport.

> email them a scan of your passport What? Why do they do this?

Apparently, OP wanted to transfer the domain from Gandi.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#56

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

3. Established procedure was not followed

Wouldn't it make sense that support staff can only generate and send out password reset mails if the PIN/password has been entered into a form? I don't know the term for this - like "coded procedure".

In this case, the support staff wouldn't even needed to be trusted in the first case.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#57
So he is using 2FA for all the important accounts but for the most important one (the email which he used to register an account at all these services) he's using a weak pw and no 2FA? Am i missing something here? Yes they did not follow protocol but why would one not use 2FA for such an important email addy?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#59

Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place.

Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch.

What do you use to tell whether a chat session is a genuine user or someone successfully using a social engineering attack against your chat operatives? If the answer is "nothing" then you can't know if this is an isolated event or how many of your chat sessions go without a glitch.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#60
STOP. USING. NAMECHEAP.

Its been months since I wanted to write a detailed summary, but the notion that "namecheap is hackers best domain registrar" is not valid anymore!

About year ago I noticed DNS changes on many of my there-parked domains. Upon reaching via Chat (no phone support so that angry customers cannot vent off) I was told that they cannot help me cause Im not the owner of the account! Upon full verification even with CC on file and telling them purchase history going back to 2009, I was still denied the access. As it turned out, all hacker needed to know is my public WHOIS info to take over my account!! That was insane! Only continuance of threats from my side that I will plaster it all over the net made them change their mind, which again is a breach of trust - what if I was actually the hacker??

What really made me start moving domains to NameSilo (Im not affiliated) is that upon doing a thorough research, I found many cases where Namecheap gives up on fighting for peoples domain! I seen names like nanotmz where company was building some sort of magnetic devices and TMZ came in and threat to sue Namecheap if they dont shut the domain down. That's where I found similar cases for NameSilo and learnt that they stand their ground and would not give up on your domains, even if are threatened with legal action.

I'm out of Namecheap completely as of last month with last SSL expiring.

Post reply on HN