Earlier quoted context omitted.
Everyone should practice a good backup routine and take responsibility for backups.
Agreed. However, is this messaged anywhere in your documentation or setup instructions? Do you provide instructions how how to set this up with a 3rd party or list of 3rd parties? Although backups are #1 item on any list of best practices, making an easy, and tested, implementation method would be a good practice on your part.
Namecheap live chat social engineering leads to loss of 2 VPS
191–200 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#192Earlier quoted context omitted.
I hate to break it to you, but "uniform" security standards that are out there in the open would be like a whole can of worms. That is like showing someone "here's a lock and what's inside of it." In time, someone will pick that lock. Uniformity is what you don't need, nor would you want to know the nuances of how security and privacy are handled at a company so that you know exactly what holes need to be exposed. Yo…
You're basically advocating for security through obscurity. A standardized process design could be carefully examined and improved to plug the holes, so all you're left with are implementation bugs. You'll never get there with a thousand disparate processes: they'll have design and implementation bugs, as well situations where system compromises data used to secure another. Plus, standardized processes would allow im…
I know, this is an issue some would disagree with. I do not think it's safe to standardize at all.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#193I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
We have had this at Amazon AWS. We had 2FA, one phone call was enough to disable 2FA. The only thing they asked were the last four digits of our credit card.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#194Earlier quoted context omitted.
I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…
Low end hosting doesn't generally have backups, because it's well, cheap. Extra overheads make the price increase, then you're not cheap and can't compete at that end. Usually there are backup options included in the plan for upsell possibilities with these kinds of providers. Really, you should not expect a service that has 'cheap' in the name to offer any kind of backup.
They never spell this out for you though, usually they imply that their service is just as good as their pricier rivals. As a result, many people get burnt before they get savvy. Some never get savvy, they just get turned off to the industry.
Not sure what the alternative is. I suspect a company that did clearly spell out their pros and cons would risk having stunted growth or go out of business entirely.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#195Earlier quoted context omitted.
... unless their Ukraine-based customer support that sometimes doesn't speak English is intimidated enough.
If you have specific information, you are welcome to contact us with full details. Policies and procedures are in place to ensure no one falls victim to social engineering and as you call it, "intimidation."
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#196Earlier quoted context omitted.
One option is to look at when the user last logged in. I would be a lot less pissed if an account that I've never touched in 10 years got compromised... I'm probably going to remember my info for recent accounts and want it to be difficult to social engineering those
This is an excellent point. > "You forgot the password that you've logged in with multiple times... including 20 minutes ago." That should raise a flag.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#197I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
I realize there has to be a way to work around 2FA, for situations like loss of device, terminations, etc, but that should have some known policy way of verifying (say, you must send a notarized or local equivalent letter, or appear in person somehow) identity, especially for a cloud service.
(Totally incidental and you perhaps won't see this, but, r1ch, Conflict Crusher was instrumental in 15 year old me learning how to mod TA, which led me to learn how write BOS scripts, which led me to realize that I liked this programming thing, which led me to my current career/way to support my family. Thanks! :) )
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#198Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#199Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…
> Kevin Mitnick publicized it and went to jail (unjustly) You're joking right? He even fully admits that he did what they accused him of doing.
(the book is great, by the way, highly recommended)
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#200Earlier quoted context omitted.
It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…
The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?
Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies.
Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech company isn't going to have people sat ready who are capable of accurately verifying this information.
The other problem is PR: due to the lack of another option the average person who is locked out of their account will instantly turn to twitter/facebook/any-where-else-they-can-post and scream as loud as they can that they've been mistreated by company X. Many other average persons will take this at face value without checking the fats and start avoiding company X, or worse bombarding them with communication in support of the inconvenienced user.