Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

201–210 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#201

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

With #3 - ideally your systems should not allow you to break established procedure. Mitigate the risk by not giving the support staff tools to shoot yourself in the foot so easily. This could be achieved with peer verification or some other mechanism (lots of ways if you think it through).

Yes, learning experiences are had when things happen like this. We look to the future, not to the past, to ensure the same mistakes do not recur.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#202
post #64

Earlier quoted context omitted.

We who?

Example of on HN expecting everyone (newbies and all) to know who you are. This happens with DANG and SAMA comments as well. Back when PG used to comment also happened. Look at their profiles, really no explanation of who they are here: https://news.ycombinator.com/user?id=pg https://news.ycombinator.com/user?id=dang https://news.ycombinator.com/user?id=sama Why is it so hard to put info in your profile or to put a f…

He posted this down the thread which starts with:

> Disclaimer: I'm CIO @ Namecheap

https://news.ycombinator.com/item?id=11479810

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#203
post #27

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

> Established procedure was not followed Why have a procedure if your support doesn't follow it? Even if you have a procedure, everything falls apart when it isn't followed. This is the same as having no procedure at all.

People make mistakes. The customer support person was probably just trying to be helpful and not fully aware of all the ramifications. This is unfortunate but presumably there has been some retraining.

Note: I have no direct or indirect relationship with Namecheap at all.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#204
post #161

Earlier quoted context omitted.

With a bank you go into a branch, and show them your driver's license/other official ID, and don't lose access to all your money... It's harder online when you don't have the same ability to interact face to face.

When you are locked out of AWS you must sign an affidavit and provide photo ID. Seems similar to me.

Amazon has the resources to go through intensive identity verification processes. And so do banks.

Most tech companies (especially startups) don't.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#205
Incidents like this remind me of Blizzard's policies vis-a-vie their 2-factor auth system.

I don't know if it's changed since this happened, but in the early-ish days my friend's phone broke and he lost his ability to generate 2FA codes. Blizzard was happy to remove his 2FA once he had made a photocopy of at least one (maybe two?) forms of ID and (I think?) some evidence he owned the credit card paying for the account. Once he mailed that in to Blizzard hq, some human confirmed the info and they removed the 2FA. If Blizzard can do that, and they're protecting MMO characters, certainly other providers can do so as well (maybe for an increased fee as I realize it's more expensive than online chat).

IIRC, people hacking into Blizzard games resorted to compromising users' computers and capturing the 2FA codes in flight - then logging in and changing the credentials before the user could react. That's a much higher bar to clear than the one here.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#206

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

Matthew, It sounds like you are confirming that this incident did happen and it was your fault for not following your procedures. I am not a lawyer, but since there was signification loss, it would probably be in your best interest to offer better reparations. OpenDomain has several domains that are on NameCheap - I will transfer them immediately since it appears you do not care about customers.

OpenDomain -

We have apologized, admitted mistakes, and made tremendous internal change to move on for the better. We would not do that or even post here if we didn't care.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#207
post #25

Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…

Did you make it through to the part of the article where he says "my biggest personal lesson is to make off-host backups"? Not sure why you're making this post.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#208
post #161
post #147

Earlier quoted context omitted.

The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?

With a bank you go into a branch, and show them your driver's license/other official ID, and don't lose access to all your money... It's harder online when you don't have the same ability to interact face to face.

I have a few bank accounts with banks that don't have branches. To "verify" your Id they ask you questions from your credit report - which can be problematic. "What was the payment and term on a loan you had 5 years ago?" Fuck if I ever knew what the payment or term was, I didn't care when I took out the loan, I had my own payment schedule (I think if you can't pay back a loan [with the exception of a mortgage] in a year or two you really can't afford the loan...). Some of the stuff I just plain can't remember!

The best was when they asked me which model of car I had owned... and listed two cars that I had owned... I could only select one.

These records can be flat out wrong too. The DMV associates a car with my address that I don't own, for example. I think this happened because the owner never changed their address with the DMV. Or someone could have just fat fingered something which gets populated to other databases with data sharing.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#209
post #64

Earlier quoted context omitted.

Example of on HN expecting everyone (newbies and all) to know who you are. This happens with DANG and SAMA comments as well. Back when PG used to comment also happened. Look at their profiles, really no explanation of who they are here: https://news.ycombinator.com/user?id=pg https://news.ycombinator.com/user?id=dang https://news.ycombinator.com/user?id=sama Why is it so hard to put info in your profile or to put a f…

given the context of the reply, any person of average intelligence should be able to figure it out (or just google)

Well I read the reply :

"we offer service X"

could be from anybody trying to say they offer the service, not obvious at all it is a representative of Namecheap

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#210

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…

Thanks for edit2 :) I see us having used the word "mistake" many times here! But yes, we apologize that this happened as well.
Post reply on HN