Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
3. Established procedure was not followed Wouldn't it make sense that support staff can only generate and send out password reset mails if the PIN/password has been entered into a form? I don't know the term for this - like "coded procedure". In this case, the support staff wouldn't even needed to be trusted in the first case.
Namecheap live chat social engineering leads to loss of 2 VPS
121–130 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#122Earlier quoted context omitted.
Fairly common for enterprise type apps to have a list of preapproved contact points, not on the list they won't even talk to you. Maybe other places could take this up... not foolproof, but at least adds another layer to the challenge.
I've personally gotten past lists like that a number of times simply by stating that person is not on staff any more, I'm their replacement; legitimately did replace the old point of contact. Getting people to do stuff on the phone is easy a huge amount of the time.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#123Earlier quoted context omitted.
It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…
I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.
My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then.
Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over time!). I filled in "Dave" ... and the site gave me an error "Your answer must be at least 6 characters."
Doh!
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#124So I just was about the enable 2FA on namecheap but at least from the description it only supports SMS I'm traveling constantly. I always have a different country's SIM in my phone meaning I can't receive SMSs to a static number. Is SMS only 2FA acceptable?
A few ideas: * If they happen to be using authy for 2FA and you have the Authy app on your phone, it will use that instead of sending an SMS. You could also just have it send to Authy's Chrome extension. * Consider setting up a Google Voice number to receive the SMS.
Google voice ok, but given google hasn't updated google voice in like 3 years I expect they'll announce it being discontinued soon.
Any other options?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#125What's this crowd think of this idea for solving this problem? 1) Offer an option to opt-out of all automated account recovery. If set, no more email resets, support PINs, or similar. This would be targeted at people truly care about security and have no issue with "forgetting passwords" (i.e. you use a password manager and you're not an idiot about backups). 2) Offer in-person, manual recovery. To participate in thi…
We do something similar at Silent Circle. In your recovery options, there's a page with a high-entropy secret key and a QR code that you can print out to use if you ever forget your password. There's also a checkbox that says "don't ever recover this account" (i.e. the "I have a password database on Dropbox") checkbox. Checking that box actually disables password resets on the admin interface, so your account is pret…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#126Earlier quoted context omitted.
I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…
Everyone should practice a good backup routine and take responsibility for backups.
Although backups are #1 item on any list of best practices, making an easy, and tested, implementation method would be a good practice on your part.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#127Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…
Usually there are backup options included in the plan for upsell possibilities with these kinds of providers. Really, you should not expect a service that has 'cheap' in the name to offer any kind of backup.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#128Earlier quoted context omitted.
Everyone should practice a good backup routine and take responsibility for backups.
This is not good damage control/PR. You are letting ego get in the way.
The opposite of what I'm suggesting is that people - individuals/companies - do not look after their own backups. That's a dangerous precedent.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#129As someone in the domain registrar industry, are there any features beyond 2FA that you would like to see implemented by registrars? More bluntly, what is it that you think your current registrar is lacking? I read a few comments on Gandi and support of GPG keys. I'm guessing this is what you're referring to: https://wiki.gandi.net/en/gandi/documents
I have seen some registrars offer USB devices that must be plugged into a laptop in order to gain access to an account.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#130This means there can't be any "impedance" mismatching that can be used from one service to another. For example, one company gives out the last 4 digits of the credit card, and the other uses the last 4 as security info.
What we need is a uniform security standard and training for ALL customer support personnel so that you can use Apple to break into Amazon, or Digital Ocean or Namecheap. The staff need to be trained to never succumb to social engineering ever, and in fact make it impossible for 1st line support to reset anything. Have any security information get passed up to second tier support who are extremely well-trained. Etc.
And have this standardized so that there is incentive for customers to look for this certification so that we don't have to keep suffering the same mistakes over and over again.