Earlier quoted context omitted.
We have had this at Amazon AWS. We had 2FA, one phone call was enough to disable 2FA. The only thing they asked were the last four digits of our credit card.
That is a little unnerving if true.
Namecheap live chat social engineering leads to loss of 2 VPS
151–160 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#152Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…
There is no reason for Namecheap to have a human in the loop for this, at this stage.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#153Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
This is not the correct solution. What's to prevent the next new person from making the same mistake?
If it shouldn't happen, don't make it possible to happen. Put in place a technical solution that doesn't allow it happen. And if there is some special case where it still needs to be possible, make it that it needs a secondary signoff from a senior team member.
People will always be fallible.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#154All I had to do was tell the chat operator I was having some issue with .htaccess and .htpasswd until they offered to delete it temporarily. In the few minutes between them deleting it and reuploading it, you're free to do whatever you want.
I reported this and was told it was resolved (I guess with new policies).
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#155I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#156Earlier quoted context omitted.
> Kevin Mitnick publicized it and went to jail (unjustly) You're joking right? He even fully admits that he did what they accused him of doing.
Ever heard of a plea deal? He was obligated to 'admit wrongdoing' in order to get a reduced sentence. Sure, he could have stuck to his guns, but, jail has very bad internet.
I'd definitely agree that the solitary confinement was cruel and unusual. I'd also agree that the law wasn't mature enough when he was charged so he was charged with proxy-laws.
But ultimately he did do what they said he did, and some of it was pretty messed up. He would definitely be charged today with computer crimes (or generic crimes) for many of his exploits at the time.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#157Earlier quoted context omitted.
We offer full backups with all managed servers/services Self-managed a customer is responsible for their own backups. Just like with DO and that full server loss a couple of months back.
> We offer full backups with all managed servers/services Are those backups purgeable from the account control panel? Honestly I'm not a huge fan of same-provider backup solutions. It seems like asking a fox to guard your sheep.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#158As someone in the domain registrar industry, are there any features beyond 2FA that you would like to see implemented by registrars? More bluntly, what is it that you think your current registrar is lacking? I read a few comments on Gandi and support of GPG keys. I'm guessing this is what you're referring to: https://wiki.gandi.net/en/gandi/documents
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#159The only solution is to remove these sort of powers from your general tech support guy and let them in the hands of a few highly technical, well trained, well paid staff members (presumably managers?). Of course, I made the blind assumption that your average support staff member is not paranoid enough, but based on my acquaintance with a few guys in the business it seems to me that the salary is not high enough to expect well trained technical stuff doing support.
I might be wrong, and in that case I would gladly know which companies employ such well trained staff, so that I can move my servers there.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#160Earlier quoted context omitted.
It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…
The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?