Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

171–180 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#171

Earlier quoted context omitted.

It's not an argument you're going to win. Unless you sign up for a managed service that claims to include backups or whatever, you are responsible for your own backups. What's controversial about that?

The issue is that Namecheap was the one that fucked up here, and now is not the time to emphasize "you should really be prepared for us fucking up in this manner". It's victim blaming. It looks shitty. The argument I refer to isn't "you should have offsite backups". The argument is that Namecheap is implicitly victim blaming, and they're not going to convince many people that they aren't.

Eh.. I don't really agree that this is victim blaming. But then again, I find that I disagree with most uses of the phrase "victim blaming". Pointing out that somebody did something sub-optimal, while still acknowledging the mis-deeds, mistakes, etc. of other parties, is not "victim blaming" in my book. It's just pointing out the truth.

I mean, if you go for a stroll through the roughest neighborhood in town, unarmed, by yourself, at night, and you get mugged, is it wrong to point out that going for that walk was stupid? Saying so doesn't mean the the mugger isn't guilty or that what happened is right in any sense. It's just acknowledging reality.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#172

Earlier quoted context omitted.

AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…

Security questions should be treated as secondary password fields, since they are that. Use Diceware for a good tradeoff between entropy and memorability/pronounceability or more complex random passwords and store them in a safe place.

This works well until you get to the "Our site is so secure that we need you to answer three security questions from our canned list, and they can't all be the same string" geniuses. Such an antipattern.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#173

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

> 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved This is not the correct solution. What's to prevent the next new person from making the same mistake? If it shouldn't happen, don't make it possible to happen. Put in place a technical solution that doesn't allow it happen. And if there is some special case where it still needs to be possible…

That's part of the whole issue. It wasn't simply an issue of retraining. The entire company is well aware of this issue and is using it to improve, not simply to reprimand a single person.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#174

Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…

I like this idea. If you want to work as a CS rep and handle password resets, you need to have XYZ 1.0 security training, regardless of the company.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#175
post #155

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

One option is to look at when the user last logged in. I would be a lot less pissed if an account that I've never touched in 10 years got compromised... I'm probably going to remember my info for recent accounts and want it to be difficult to social engineering those

This is an excellent point.

> "You forgot the password that you've logged in with multiple times... including 20 minutes ago."

That should raise a flag.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#176
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I had a similar thing happen with my Battle.net account. I forgot to transfer over my authenticator backup code when I switched password managers last time. I had to send them a photo of my driver's license next to my face and another one of it next to a physical newspaper with the date on it. This seems like a much better process for recovering accounts that matter.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#177
post #117

Earlier quoted context omitted.

I don't think it was personal, simply a reminder that it always helps to have good backup procedures in place. Even my managed services have offsite backups. Better be safe than sorry, I always say.

"Better be safe than sorry" - namecheap for when you lose your stuff on their services. I don't think the best way to respond to a public vent is "Here's what you should have done instead". Responses might be technically correct but they lack empathy for the customer.

That comment I made refers to data integrity across platforms. You should be smart about data, no matter where it arises, if it is important to you.

For example, let me give you a look at what my Windows hard drive looks like.

My important files are stored locally, on Dropbox, and on CrashPlan. Some is also on Google Drive. I also run an offsite backup of my own to another local Linux box.

Don't make this specific to Namecheap, @kelukelugames. It's always smart to have good recovery systems in place. If you care that much about your data, you will protect it at whatever cost.

So yeah, I repeat, better to be safe than sorry. Your mileage may vary.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#178
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

What was SingleHop's response to this when you made them aware? We have servers with them.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#179
post #64

Earlier quoted context omitted.

We who?

Example of on HN expecting everyone (newbies and all) to know who you are. This happens with DANG and SAMA comments as well. Back when PG used to comment also happened. Look at their profiles, really no explanation of who they are here: https://news.ycombinator.com/user?id=pg https://news.ycombinator.com/user?id=dang https://news.ycombinator.com/user?id=sama Why is it so hard to put info in your profile or to put a f…

given the context of the reply, any person of average intelligence should be able to figure it out (or just google)

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#180

Earlier quoted context omitted.

Ever heard of a plea deal? He was obligated to 'admit wrongdoing' in order to get a reduced sentence. Sure, he could have stuck to his guns, but, jail has very bad internet.

I meant in his book and speeches he has since given he has admitted doing more or less what they accused him of doing. I'd definitely agree that the solitary confinement was cruel and unusual. I'd also agree that the law wasn't mature enough when he was charged so he was charged with proxy-laws. But ultimately he did do what they said he did, and some of it was pretty messed up. He would definitely be charged today w…

I would imagine owning up to his "crimes" helps his business / brand. If he disclaimed all credit, he would be seen less an an expert in his field of work.

https://www.mitnicksecurity.com

Post reply on HN