Earlier quoted context omitted.
If you have specific information, you are welcome to contact us with full details. Policies and procedures are in place to ensure no one falls victim to social engineering and as you call it, "intimidation."
With respect, "policies and procedures" do not protect against social engineering. You need a technical barrier.
Namecheap live chat social engineering leads to loss of 2 VPS
221–230 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#222Earlier quoted context omitted.
It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…
I had a similar thing happen with my Battle.net account. I forgot to transfer over my authenticator backup code when I switched password managers last time. I had to send them a photo of my driver's license next to my face and another one of it next to a physical newspaper with the date on it. This seems like a much better process for recovering accounts that matter.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#223Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
Did you make it through to the part of the article where he says "my biggest personal lesson is to make off-host backups"? Not sure why you're making this post.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#224Earlier quoted context omitted.
The issue is that Namecheap was the one that fucked up here, and now is not the time to emphasize "you should really be prepared for us fucking up in this manner". It's victim blaming. It looks shitty. The argument I refer to isn't "you should have offsite backups". The argument is that Namecheap is implicitly victim blaming, and they're not going to convince many people that they aren't.
It's not victim blaming. It's simply a reiteration that it helps to have this in place if you are specifically opting to rent/lease a server that does not offer it. Also, it's stated in the knowledgebase that it is advisable to set up server backups of your own if you do not have a managed server: https://www.namecheap.com/support/knowledgebase/article.aspx...
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#225Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
You also didn't mention all the terrible things the OP pointed out that someone can do with just your password even when 2fa is enabled.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#226Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…
> Kevin Mitnick publicized it and went to jail (unjustly) You're joking right? He even fully admits that he did what they accused him of doing.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#227Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
I don't see how that can be the biggest lesson. Someone at the service provider bypassed their own protocols in order to hand control of the system over to an unauthorized user. Even with local backups he would have needed to restore the servers because Namecheap royally screwed up. Yes, you should always have more backups than you need. But wouldn't you be moving to a different provider after something like this any…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#228Re: Namecheap live chat social engineering leads to loss of 2 VPS
#229Earlier quoted context omitted.
When you are locked out of AWS you must sign an affidavit and provide photo ID. Seems similar to me.
Amazon has the resources to go through intensive identity verification processes. And so do banks. Most tech companies (especially startups) don't.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#230Earlier quoted context omitted.
I had a similar thing happen with my Battle.net account. I forgot to transfer over my authenticator backup code when I switched password managers last time. I had to send them a photo of my driver's license next to my face and another one of it next to a physical newspaper with the date on it. This seems like a much better process for recovering accounts that matter.
This seems very easy to bypass.
I'd be surprised if ever a Blizzard account was compromised by someone sending in a false picture.