Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
With #3 - ideally your systems should not allow you to break established procedure. Mitigate the risk by not giving the support staff tools to shoot yourself in the foot so easily. This could be achieved with peer verification or some other mechanism (lots of ways if you think it through).
Namecheap live chat social engineering leads to loss of 2 VPS
201–210 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#202Earlier quoted context omitted.
We who?
Example of on HN expecting everyone (newbies and all) to know who you are. This happens with DANG and SAMA comments as well. Back when PG used to comment also happened. Look at their profiles, really no explanation of who they are here: https://news.ycombinator.com/user?id=pg https://news.ycombinator.com/user?id=dang https://news.ycombinator.com/user?id=sama Why is it so hard to put info in your profile or to put a f…
> Disclaimer: I'm CIO @ Namecheap
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#203Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
> Established procedure was not followed Why have a procedure if your support doesn't follow it? Even if you have a procedure, everything falls apart when it isn't followed. This is the same as having no procedure at all.
Note: I have no direct or indirect relationship with Namecheap at all.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#204Earlier quoted context omitted.
With a bank you go into a branch, and show them your driver's license/other official ID, and don't lose access to all your money... It's harder online when you don't have the same ability to interact face to face.
When you are locked out of AWS you must sign an affidavit and provide photo ID. Seems similar to me.
Most tech companies (especially startups) don't.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#205I don't know if it's changed since this happened, but in the early-ish days my friend's phone broke and he lost his ability to generate 2FA codes. Blizzard was happy to remove his 2FA once he had made a photocopy of at least one (maybe two?) forms of ID and (I think?) some evidence he owned the credit card paying for the account. Once he mailed that in to Blizzard hq, some human confirmed the info and they removed the 2FA. If Blizzard can do that, and they're protecting MMO characters, certainly other providers can do so as well (maybe for an increased fee as I realize it's more expensive than online chat).
IIRC, people hacking into Blizzard games resorted to compromising users' computers and capturing the 2FA codes in flight - then logging in and changing the credentials before the user could react. That's a much higher bar to clear than the one here.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#206Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
Matthew, It sounds like you are confirming that this incident did happen and it was your fault for not following your procedures. I am not a lawyer, but since there was signification loss, it would probably be in your best interest to offer better reparations. OpenDomain has several domains that are on NameCheap - I will transfer them immediately since it appears you do not care about customers.
We have apologized, admitted mistakes, and made tremendous internal change to move on for the better. We would not do that or even post here if we didn't care.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#207Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#208Earlier quoted context omitted.
The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?
With a bank you go into a branch, and show them your driver's license/other official ID, and don't lose access to all your money... It's harder online when you don't have the same ability to interact face to face.
The best was when they asked me which model of car I had owned... and listed two cars that I had owned... I could only select one.
These records can be flat out wrong too. The DMV associates a car with my address that I don't own, for example. I think this happened because the owner never changed their address with the DMV. Or someone could have just fat fingered something which gets populated to other databases with data sharing.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#209Earlier quoted context omitted.
Example of on HN expecting everyone (newbies and all) to know who you are. This happens with DANG and SAMA comments as well. Back when PG used to comment also happened. Look at their profiles, really no explanation of who they are here: https://news.ycombinator.com/user?id=pg https://news.ycombinator.com/user?id=dang https://news.ycombinator.com/user?id=sama Why is it so hard to put info in your profile or to put a f…
given the context of the reply, any person of average intelligence should be able to figure it out (or just google)
"we offer service X"
could be from anybody trying to say they offer the service, not obvious at all it is a representative of Namecheap
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#210Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…