Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

221–230 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#221
post #195
post #115

Earlier quoted context omitted.

If you have specific information, you are welcome to contact us with full details. Policies and procedures are in place to ensure no one falls victim to social engineering and as you call it, "intimidation."

With respect, "policies and procedures" do not protect against social engineering. You need a technical barrier.

skj, there's a lot more to policy and procedure than just human intervention. We're fully aware of this valid concern and are committed to security on both human and technical sides.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#222

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I had a similar thing happen with my Battle.net account. I forgot to transfer over my authenticator backup code when I switched password managers last time. I had to send them a photo of my driver's license next to my face and another one of it next to a physical newspaper with the date on it. This seems like a much better process for recovering accounts that matter.

This seems very easy to bypass.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#223
post #25

Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…

Did you make it through to the part of the article where he says "my biggest personal lesson is to make off-host backups"? Not sure why you're making this post.

Which doesn't jive with the either the title, or conclusion of the post.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#224
post #184

Earlier quoted context omitted.

The issue is that Namecheap was the one that fucked up here, and now is not the time to emphasize "you should really be prepared for us fucking up in this manner". It's victim blaming. It looks shitty. The argument I refer to isn't "you should have offsite backups". The argument is that Namecheap is implicitly victim blaming, and they're not going to convince many people that they aren't.

It's not victim blaming. It's simply a reiteration that it helps to have this in place if you are specifically opting to rent/lease a server that does not offer it. Also, it's stated in the knowledgebase that it is advisable to set up server backups of your own if you do not have a managed server: https://www.namecheap.com/support/knowledgebase/article.aspx...

I don't believe you properly understand what victim blaming is or the argument I am making here, hence the reason I recommended you and your CIO don't bother continuing trying to discuss this. You're giving people reason to dislike Namecheap for no gain to yourself and your brand.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#225

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

Putting #1 as #1 looks like bitter deflection. You do it elsewhere in the thread too, saying that lack of 2fa on the email account opened the door to this. You should be well aware both that most security issues end up being perfect storm of circumstances, and that attackers can and will target multiple points in the chain. Relying on #1 as the spearhead of your apparent defense here is tantamount to admitting that you are relying on the security of people's email accounts as part of your own security process, which is wild.

You also didn't mention all the terrible things the OP pointed out that someone can do with just your password even when 2fa is enabled.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#226

Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…

> Kevin Mitnick publicized it and went to jail (unjustly) You're joking right? He even fully admits that he did what they accused him of doing.

Do you know anything about the case? They said he shouldn't even use the phone and spent time in solitary because they said he could cause a nuclear war. The entire case against him was horrifying to anyone that cares about human rights.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#227
post #25

Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…

I don't see how that can be the biggest lesson. Someone at the service provider bypassed their own protocols in order to hand control of the system over to an unauthorized user. Even with local backups he would have needed to restore the servers because Namecheap royally screwed up. Yes, you should always have more backups than you need. But wouldn't you be moving to a different provider after something like this any…

Yes, I would move. Impossible to do without the data, which is why it was the biggest takeaway to me.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#229

Earlier quoted context omitted.

When you are locked out of AWS you must sign an affidavit and provide photo ID. Seems similar to me.

Amazon has the resources to go through intensive identity verification processes. And so do banks. Most tech companies (especially startups) don't.

Doesn't this sound like something a startup can come in and alleviate? Anyone have any recommendations for identity verification as a service?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#230

Earlier quoted context omitted.

I had a similar thing happen with my Battle.net account. I forgot to transfer over my authenticator backup code when I switched password managers last time. I had to send them a photo of my driver's license next to my face and another one of it next to a physical newspaper with the date on it. This seems like a much better process for recovering accounts that matter.

This seems very easy to bypass.

Very easy? I'd say "possible" at best. And now you've got access to a battle.net account. Took a heck of a lot more work than asking someone for username/pass in a live chat, and what you gained access to is worth a heck of a lot less. Plus Blizzard actually does keep backups and records and will be able to fix the situation for the account owner.

I'd be surprised if ever a Blizzard account was compromised by someone sending in a false picture.

Post reply on HN