I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
Namecheap live chat social engineering leads to loss of 2 VPS
61–70 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#62Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
I think a better suggestion/wording (depending on your intent) re: backups would be "don't operate without independent backups".
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#63Does Namecheap claim to take backups? Even if they do you should be taking backups as well if you care about your data. I do agree with more login forms needing to support 2FA. At this point I wish almost everything did. It is a bit more hassle but is easy to manage for me at least.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#64Earlier quoted context omitted.
We offer full backups with all managed servers/services Self-managed a customer is responsible for their own backups. Just like with DO and that full server loss a couple of months back.
We who?
https://news.ycombinator.com/user?id=pg
https://news.ycombinator.com/user?id=dang
https://news.ycombinator.com/user?id=sama
Why is it so hard to put info in your profile or to put a footnote in your comments for the newbies? Would you have your business act this way? Reply to a person's inquiry and not say who you are and what you do? Of course not.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#65Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently.
EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology.
EDIT3: congrats to Tamar for being promoted to a Namecheap executive!
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#66Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#67STOP. USING. NAMECHEAP. Its been months since I wanted to write a detailed summary, but the notion that "namecheap is hackers best domain registrar" is not valid anymore! About year ago I noticed DNS changes on many of my there-parked domains. Upon reaching via Chat (no phone support so that angry customers cannot vent off) I was told that they cannot help me cause Im not the owner of the account! Upon full verificat…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#68the first error was buying server space from namecheap. good domain server but they get hit frequently being a midsize provider of services, they have enough bait and not enough people to protect it.
That doesn't really make sense. We're a great domain and hosting provider.
The domain registration process isn't automated from my experience but it works well. However, I think the meta is (I think many people will agree) to not mix domain and hosting with the same provider. For example, if you get your domain from namecheap, you should not do hosting at namecheap. Therefore, the argument is that if you want to buy a domain name from Namecheap (as they're pretty decent), you shouldn't do hosting there.
Sorry if I sound like a prick.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#69Is password recovery a bug or a feature? cloud providers seem on the fence about this. AWS has certainly had similar problems in the past.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#70On another note, there 2FA seems to broken as well. I once received a text about resetting my Instagram account from the same number that they send me to authenticate my login session. I've never had an Instagram account.
Namecheap uses the same 2FA provider as Tumblr, Yahoo, Microsoft, and a slew of other services.
I find it hard to believe Microsoft of all companies has outsourced two factor authentication.