Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

211–220 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#211
post #172

Earlier quoted context omitted.

Security questions should be treated as secondary password fields, since they are that. Use Diceware for a good tradeoff between entropy and memorability/pronounceability or more complex random passwords and store them in a safe place.

This works well until you get to the "Our site is so secure that we need you to answer three security questions from our canned list, and they can't all be the same string" geniuses. Such an antipattern.

For every site that does this, I have a blob of text in my password manager where I write down

Q: what was your childhood best friend's last name? A: pathway-titian-slowly-quiver-kodiak-hue

etc., even for fact-based things like "what city were you born in?" or "what street did you live on in 1995?".

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#212
post #172

Earlier quoted context omitted.

Security questions should be treated as secondary password fields, since they are that. Use Diceware for a good tradeoff between entropy and memorability/pronounceability or more complex random passwords and store them in a safe place.

This works well until you get to the "Our site is so secure that we need you to answer three security questions from our canned list, and they can't all be the same string" geniuses. Such an antipattern.

I had something along those lines tryin to log in to mojang on a new computer. "We've not seen you log into this pc before (although I had on that IP), please answer these three security questions. Of course I don't remember so I just reset them. I imagine the new answers and the old answers had a lot in common - they were composed primarily of expletives.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#213

Earlier quoted context omitted.

"Better be safe than sorry" - namecheap for when you lose your stuff on their services. I don't think the best way to respond to a public vent is "Here's what you should have done instead". Responses might be technically correct but they lack empathy for the customer.

"Hard drives never fail" - kelukelugames

Doh.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#214
post #151
post #85

Earlier quoted context omitted.

That is a little unnerving if true.

Just confirmed with our CTO. He was able to turn MFA off on our root AWS account over the phone.

Huh. I'm going to say thanks to HN, and this comment chain, for bringing this to light. That seems kind of insane.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#215

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I had a similar thing happen with my Battle.net account. I forgot to transfer over my authenticator backup code when I switched password managers last time. I had to send them a photo of my driver's license next to my face and another one of it next to a physical newspaper with the date on it. This seems like a much better process for recovering accounts that matter.

So what do you think happened to those photos?

Some people would be happy to pay for a leaked copy of those photos, for use with any other company that would accept only the "face/license" photo as sufficient proof.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#216
post #78
post #59

Earlier quoted context omitted.

Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. What do you use to tell whether a chat session is a genuine user or someone successfully using a social engineering attack against your chat operatives? If the answer is "nothing" then you can't know if this is an isolated event or how many of your chat sessions go without a glitch.

There are identification methods requested via chat. Matt invited you to try it. Go for it.

Parent's point was, how do you tell whether or not your rep was socially engineered? Only some mistakes get complained about. If you don't have such a method then your "10000 sessions a day without a problem" number is fantasy.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#217

1. using a weak password for an important e-mail address 2. not deleting the mail with the login information 3. not having a backup Yeah. This was just as much your fault.

You misread the article at a very basic level if you think 2 is related to anything

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#218
post #19

Earlier quoted context omitted.

> Sometimes you get what you pay for. So what expensive provider do you recommend instead?

https://www.gandi.net/

But their DNS zone update latency is so high considering the slightly higher price :(

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#220

Earlier quoted context omitted.

The issue is that Namecheap was the one that fucked up here, and now is not the time to emphasize "you should really be prepared for us fucking up in this manner". It's victim blaming. It looks shitty. The argument I refer to isn't "you should have offsite backups". The argument is that Namecheap is implicitly victim blaming, and they're not going to convince many people that they aren't.

Eh.. I don't really agree that this is victim blaming. But then again, I find that I disagree with most uses of the phrase "victim blaming". Pointing out that somebody did something sub-optimal, while still acknowledging the mis-deeds, mistakes, etc. of other parties, is not "victim blaming" in my book. It's just pointing out the truth. I mean, if you go for a stroll through the roughest neighborhood in town, unarmed…

>I mean, if you go for a stroll through the roughest neighborhood in town, unarmed, by yourself, at night, and you get mugged, is it wrong to point out that going for that walk was stupid?

Yes, this is the textbook example of victim blaming. Placing any amount of blame on the person who is the victim in this situation is saying that they don't have the right to walk down a street and not be mugged. I am admittedly not the best at describing this because up until recently I had the same thought process as you. I would encourage you to find better explanations than what I can offer and be willing to have your beliefs challenged.

Post reply on HN