Earlier quoted context omitted.
Matthew Russell is the VP of Hosting at Namecheap https://www.namecheap.com/about/team.aspx
What if any fault does Namecheap take with the breach and what is being done to resolve it?
Namecheap live chat social engineering leads to loss of 2 VPS
231–240 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#232Earlier quoted context omitted.
The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?
> This isn't a problem for banks, why is it a problem for tech companies? Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies. Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech…
Also, rechecking the ID of a user can be as simple as asking for a new token payment by the same credit card as used by the account. It's not infailable, the CC can be compromised as well, but it should be way better than what we have now.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#233Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
But Backups should be everyone's first priority. I'm sure many of the ransomware victims would have simply restored their machines from backup--if only they had them!
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#234Earlier quoted context omitted.
I once lost my gandi.net password. It took sending copies of 2 photo id, and answering the phone listed in the who is database before they reset it. I just wish that their DNS updates were push through faster.
That's not good verification. It takes a couple of minutes to produce convincing fake ID scans, and they aren't going to have anything to verify them against. And presumably they wanted you to send those photos to them as an unencrypted email attachment, right?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#235Earlier quoted context omitted.
3. Established procedure was not followed Wouldn't it make sense that support staff can only generate and send out password reset mails if the PIN/password has been entered into a form? I don't know the term for this - like "coded procedure". In this case, the support staff wouldn't even needed to be trusted in the first case.
This is a great point. The software should be modified to not allow the employee to even make any modifications to the account without the correct credentials.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#236Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#237Earlier quoted context omitted.
The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?
> This isn't a problem for banks, why is it a problem for tech companies? Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies. Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech…
Not always true! Less than a month ago I needed to login to my Wells Fargo account. Unbeknownst to me, they had been doing some 'upgrades' and there were some glitches. After a frustrating period, I decide I'd just go to the physical branch 1/4 mile from my house and get this fixed!
On site, the bank personnel have access to exactly the same system that I did. (At least they knew there were glitches and sorta how to work around them.) I had two accounts, one for a credit card that I rarely used and my mortgage. Turns out, if you have a credit card then the new system requires a piece of information only found on the physical card - the onsite employees couldn't get around and neither could their call-in tech support!!!!
Point is - for log-in purposes - don't assume going to a physical branch will be any more helpful!
Since I didn't have the credit card with me ('cause rarely used) I canceled the rarely used credit card and was able to login shortly thereafter.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#238Earlier quoted context omitted.
This works well until you get to the "Our site is so secure that we need you to answer three security questions from our canned list, and they can't all be the same string" geniuses. Such an antipattern.
For every site that does this, I have a blob of text in my password manager where I write down Q: what was your childhood best friend's last name? A: pathway-titian-slowly-quiver-kodiak-hue etc., even for fact-based things like "what city were you born in?" or "what street did you live on in 1995?".
Drop-downs for answers. Just got this on United.com:
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#239Re: Namecheap live chat social engineering leads to loss of 2 VPS
#240What's this crowd think of this idea for solving this problem? 1) Offer an option to opt-out of all automated account recovery. If set, no more email resets, support PINs, or similar. This would be targeted at people truly care about security and have no issue with "forgetting passwords" (i.e. you use a password manager and you're not an idiot about backups). 2) Offer in-person, manual recovery. To participate in thi…