Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

71–80 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#71
post #12

I for one haven't seen very many services that don't allow you to reset your 2fa if you control the attached email. Would anyone here seriously expect that someone in control of their email wouldn't be able to take control of associated accounts?

I think this is a very good point that I also overlooked when I first read the article. If someone hacked my gmail account, I honestly am not sure if there would be any account of mine that would be safe. Anyone using the Internet today has to put utmost care into protecting their email address and most email providers enable you to do that fairly easily. There was an article here a few months ago promoting logging i…

And this is an argument for making sure your email provider has two factor authentication to avoid having an external breach that could give someone access to accounts that do not support 2FA.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#72
post #57

So he is using 2FA for all the important accounts but for the most important one (the email which he used to register an account at all these services) he's using a weak pw and no 2FA? Am i missing something here? Yes they did not follow protocol but why would one not use 2FA for such an important email addy?

I thought the same thing! Although he is definitely right to complain about Namecheap, the biggest takeaway is, your email is the most important service you have on the internet:

> I’m pretty careful to use 2FA for any service that I consider important

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#73

the first error was buying server space from namecheap. good domain server but they get hit frequently being a midsize provider of services, they have enough bait and not enough people to protect it.

That doesn't really make sense. We're a great domain and hosting provider.

I don't use their hosting, but I have a lot of domains with them. Anytime I've had an issue with the settings on a domain, they've been quickly resolved.

Just a few weeks ago I was getting a domain set up with Amazon SES, and one Daria P. helped interpret Amazon's docs to get it verified with them, and explained how I was using the dig command incorrectly to inspect the domain's settings. It's rare you see a support person do that at any company.

And, of course, they did ask for a support PIN.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#74
post #66

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

If 3 is possible, how are we to believe 2?

I guess take Matt up on his offer where he said this: "Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place."

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#75
post #67

STOP. USING. NAMECHEAP. Its been months since I wanted to write a detailed summary, but the notion that "namecheap is hackers best domain registrar" is not valid anymore! About year ago I noticed DNS changes on many of my there-parked domains. Upon reaching via Chat (no phone support so that angry customers cannot vent off) I was told that they cannot help me cause Im not the owner of the account! Upon full verificat…

Namecheap has had two factor authentication and was the first provider to have it. Knowing public whois would not grant someone access to anyone's account at Namecheap. They'd still need to know your Namecheap username, your password, and your PIN, and if you had 2FA, that would need to be provided as well.

... unless their Ukraine-based customer support that sometimes doesn't speak English is intimidated enough.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#76
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

We have had this at Amazon AWS. We had 2FA, one phone call was enough to disable 2FA. The only thing they asked were the last four digits of our credit card.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#77
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code.

Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support.

The support guy was like chortle what was your security passcode? I had no idea. He tried giving some hints. I said it has literally been 10 years, I am never going to remember. So he went ahead and rest my password. He told me for the record my security code was "I am the nacho king", but I would be prompted to change it at next login.

So could I have social engineered a 10 year old MTGO account? Yes. But without it, I would have been locked out. I was NOT going to remember some stupid passcode kid me set on a game account.

And apparently I am the nacho King.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#78
post #59

Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place.

Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. What do you use to tell whether a chat session is a genuine user or someone successfully using a social engineering attack against your chat operatives? If the answer is "nothing" then you can't know if this is an isolated event or how many of your chat sessions go without a glitch.

There are identification methods requested via chat. Matt invited you to try it. Go for it.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#79

Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place.

Have you considered making this something that can't be done manually?

First of I can social engineer one of your staff. Regardless of how much you train them. I could also bribe your staff or try to get you to hire a plant. Yea that last one is far fetched but just making a point that as long as someone can manually do these things someone will.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#80
post #61
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

Even better, have the option to disable tech support and get an alert if a reset is requested with the metadata related to the party making the request.

Fairly common for enterprise type apps to have a list of preapproved contact points, not on the list they won't even talk to you. Maybe other places could take this up... not foolproof, but at least adds another layer to the challenge.
Post reply on HN