Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

121–130 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#121

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

3. Established procedure was not followed Wouldn't it make sense that support staff can only generate and send out password reset mails if the PIN/password has been entered into a form? I don't know the term for this - like "coded procedure". In this case, the support staff wouldn't even needed to be trusted in the first case.

This is a great point. The software should be modified to not allow the employee to even make any modifications to the account without the correct credentials.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#122
post #97

Earlier quoted context omitted.

Fairly common for enterprise type apps to have a list of preapproved contact points, not on the list they won't even talk to you. Maybe other places could take this up... not foolproof, but at least adds another layer to the challenge.

I've personally gotten past lists like that a number of times simply by stating that person is not on staff any more, I'm their replacement; legitimately did replace the old point of contact. Getting people to do stuff on the phone is easy a huge amount of the time.

Indeed. "Oh, we have this completely impenetrable fortress, immune to any sort of attack." "Let me in, pretty pretty please." "Okay."

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#123

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service.

My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then.

Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over time!). I filled in "Dave" ... and the site gave me an error "Your answer must be at least 6 characters."

Doh!

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#124

So I just was about the enable 2FA on namecheap but at least from the description it only supports SMS I'm traveling constantly. I always have a different country's SIM in my phone meaning I can't receive SMSs to a static number. Is SMS only 2FA acceptable?

A few ideas: * If they happen to be using authy for 2FA and you have the Authy app on your phone, it will use that instead of sending an SMS. You could also just have it send to Authy's Chrome extension. * Consider setting up a Google Voice number to receive the SMS.

no, no authy option

Google voice ok, but given google hasn't updated google voice in like 3 years I expect they'll announce it being discontinued soon.

Any other options?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#125
post #18

What's this crowd think of this idea for solving this problem? 1) Offer an option to opt-out of all automated account recovery. If set, no more email resets, support PINs, or similar. This would be targeted at people truly care about security and have no issue with "forgetting passwords" (i.e. you use a password manager and you're not an idiot about backups). 2) Offer in-person, manual recovery. To participate in thi…

We do something similar at Silent Circle. In your recovery options, there's a page with a high-entropy secret key and a QR code that you can print out to use if you ever forget your password. There's also a checkbox that says "don't ever recover this account" (i.e. the "I have a password database on Dropbox") checkbox. Checking that box actually disables password resets on the admin interface, so your account is pret…

OT question about Silent Circle: I was just looking at your website, and I noticed that you cannot ship to PO Boxes. Is this a security feature (eg, no government knowledge of the recipient) or a logistics issue (eg, FedEx/UPS can't deliver to PO Boxes). I would imagine it is pretty hard to get service for your SIM card without revealing your identity to degree.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#126

Earlier quoted context omitted.

I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…

Everyone should practice a good backup routine and take responsibility for backups.

Agreed. However, is this messaged anywhere in your documentation or setup instructions? Do you provide instructions how how to set this up with a 3rd party or list of 3rd parties?

Although backups are #1 item on any list of best practices, making an easy, and tested, implementation method would be a good practice on your part.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#127

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…

Low end hosting doesn't generally have backups, because it's well, cheap. Extra overheads make the price increase, then you're not cheap and can't compete at that end.

Usually there are backup options included in the plan for upsell possibilities with these kinds of providers. Really, you should not expect a service that has 'cheap' in the name to offer any kind of backup.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#128

Earlier quoted context omitted.

Everyone should practice a good backup routine and take responsibility for backups.

This is not good damage control/PR. You are letting ego get in the way.

I respectfully disagree. I'm here, along with Tamar, reviewing and considering each point posted. There's some good suggestions and we're listening.

The opposite of what I'm suggesting is that people - individuals/companies - do not look after their own backups. That's a dangerous precedent.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#129

As someone in the domain registrar industry, are there any features beyond 2FA that you would like to see implemented by registrars? More bluntly, what is it that you think your current registrar is lacking? I read a few comments on Gandi and support of GPG keys. I'm guessing this is what you're referring to: https://wiki.gandi.net/en/gandi/documents

I have seen some registrars offer USB devices that must be plugged into a laptop in order to gain access to an account.

Hey Bill - when I was remote staff at AOL in the 90s, we had SecurIDs too (which is basically a key fob with 6 numbers that changed every 60 seconds, pretty reminiscent of 2FA on phones/Authy/Google Authenticator). Problem is if you lose that, you're not able to get into your account...

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#130
Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards.

This means there can't be any "impedance" mismatching that can be used from one service to another. For example, one company gives out the last 4 digits of the credit card, and the other uses the last 4 as security info.

What we need is a uniform security standard and training for ALL customer support personnel so that you can use Apple to break into Amazon, or Digital Ocean or Namecheap. The staff need to be trained to never succumb to social engineering ever, and in fact make it impossible for 1st line support to reset anything. Have any security information get passed up to second tier support who are extremely well-trained. Etc.

And have this standardized so that there is incentive for customers to look for this certification so that we don't have to keep suffering the same mistakes over and over again.

Post reply on HN