Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

61–70 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#61
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

Even better, have the option to disable tech support and get an alert if a reset is requested with the metadata related to the party making the request.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#62
post #25

Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…

By "off-host" do you mean physical VPS host or hosting company?

I think a better suggestion/wording (depending on your intent) re: backups would be "don't operate without independent backups".

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#63
post #9

Does Namecheap claim to take backups? Even if they do you should be taking backups as well if you care about your data. I do agree with more login forms needing to support 2FA. At this point I wish almost everything did. It is a bit more hassle but is easy to manage for me at least.

This was a self-managed server. Managed services at Namecheap have backups.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#64

Earlier quoted context omitted.

We offer full backups with all managed servers/services Self-managed a customer is responsible for their own backups. Just like with DO and that full server loss a couple of months back.

We who?

Example of on HN expecting everyone (newbies and all) to know who you are. This happens with DANG and SAMA comments as well. Back when PG used to comment also happened. Look at their profiles, really no explanation of who they are here:

https://news.ycombinator.com/user?id=pg

https://news.ycombinator.com/user?id=dang

https://news.ycombinator.com/user?id=sama

Why is it so hard to put info in your profile or to put a footnote in your comments for the newbies? Would you have your business act this way? Reply to a person's inquiry and not say who you are and what you do? Of course not.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#65

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

I love namecheap but 5 sounds like victim blaming. Come on.

EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently.

EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology.

EDIT3: congrats to Tamar for being promoted to a Namecheap executive!

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#66

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

If 3 is possible, how are we to believe 2?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#67

STOP. USING. NAMECHEAP. Its been months since I wanted to write a detailed summary, but the notion that "namecheap is hackers best domain registrar" is not valid anymore! About year ago I noticed DNS changes on many of my there-parked domains. Upon reaching via Chat (no phone support so that angry customers cannot vent off) I was told that they cannot help me cause Im not the owner of the account! Upon full verificat…

Namecheap has had two factor authentication and was the first provider to have it. Knowing public whois would not grant someone access to anyone's account at Namecheap. They'd still need to know your Namecheap username, your password, and your PIN, and if you had 2FA, that would need to be provided as well.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#68

the first error was buying server space from namecheap. good domain server but they get hit frequently being a midsize provider of services, they have enough bait and not enough people to protect it.

That doesn't really make sense. We're a great domain and hosting provider.

This isn't your part of the business but there is room for improvement when it comes to kb articles in domain https://www.namecheap.com/support/knowledgebase/article.aspx...

The domain registration process isn't automated from my experience but it works well. However, I think the meta is (I think many people will agree) to not mix domain and hosting with the same provider. For example, if you get your domain from namecheap, you should not do hosting at namecheap. Therefore, the argument is that if you want to buy a domain name from Namecheap (as they're pretty decent), you shouldn't do hosting there.

Sorry if I sound like a prick.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#70
post #49
post #7

On another note, there 2FA seems to broken as well. I once received a text about resetting my Instagram account from the same number that they send me to authenticate my login session. I've never had an Instagram account.

Namecheap uses the same 2FA provider as Tumblr, Yahoo, Microsoft, and a slew of other services.

What do you mean by "provider"?

I find it hard to believe Microsoft of all companies has outsourced two factor authentication.

Post reply on HN