Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

161–170 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#161
post #147

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?

With a bank you go into a branch, and show them your driver's license/other official ID, and don't lose access to all your money...

It's harder online when you don't have the same ability to interact face to face.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#162

Earlier quoted context omitted.

I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…

Low end hosting doesn't generally have backups, because it's well, cheap. Extra overheads make the price increase, then you're not cheap and can't compete at that end. Usually there are backup options included in the plan for upsell possibilities with these kinds of providers. Really, you should not expect a service that has 'cheap' in the name to offer any kind of backup.

Furthermore, is Namecheap authorized to copy their clients' data by their terms of service? If not, automatic backups may bypass totally-reasonable expectations that other users have. Backups can potentially be a threat vector, for example. There might be many reasons why one of Namecheap's clients might say "you copied this data?! and now I have no control of the environment the backup lives in?!"...

An example would be if some service stored credit card information temporarily while waiting for transactions etc. to process but then purged each record after two weeks later. A compromise of the backups containing, say, weekly snapshots could then contain 90% of a client's ever-stored financial information whereas a compromise of the main site might only reveal a couple percent of them.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#163
post #147

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?

Well you can go to the bank with your ID if everything else fails

Of course that might not be even necessary as there have been reports of people withdrawing money or wiring it somewhere with not even that (but the bank has legal responsibility)

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#164

Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…

While "security specialists" are using last digits of CC and mother's maiden name as secure info I'm not holding my breath

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#165
Okay, so just for fun, I tried to do the same with my Google Account: Login: my email address Password: forgot it

"Please note that without your phone, the recovery procedure will take 3 to 5 days". hopefully, this means that there will be many many checks to avoid social engineering

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#166
post #147

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?

I agree. With banks, if you need to prove identity remotely, you need to get a medallion signature and a notary. Takes time and money. I assume that web businesses would be happy to have to do that in return for robust security not easily broke via social engineering. I think it would even be a competitive advantage. If you want cheap and easy (and insecure) then you can use a competitors offering.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#167
post #161
post #147

Earlier quoted context omitted.

The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?

With a bank you go into a branch, and show them your driver's license/other official ID, and don't lose access to all your money... It's harder online when you don't have the same ability to interact face to face.

When you are locked out of AWS you must sign an affidavit and provide photo ID. Seems similar to me.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#168

Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…

As a business, it costs more to piss off your customers regularly because they can't get into their accounts than it does to refund the rare victim of social engineering.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#169

Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…

Talking about Kevin Minnick, I can really recommend his book Ghost in the Wires, both for the story and the numerous great examples of social engineering https://henrikwarne.com/2015/12/27/social-engineering-from-k...

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#170
post #74
post #66

Earlier quoted context omitted.

If 3 is possible, how are we to believe 2?

I guess take Matt up on his offer where he said this: "Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place."

I love this. Am I wrong or is it "if you don't believe me, try the social engineering hack yourself!"
Post reply on HN