Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

231–240 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#231
post #82

Earlier quoted context omitted.

Matthew Russell is the VP of Hosting at Namecheap https://www.namecheap.com/about/team.aspx

What if any fault does Namecheap take with the breach and what is being done to resolve it?

See my other comments in this thread

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#232
post #147

Earlier quoted context omitted.

The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?

> This isn't a problem for banks, why is it a problem for tech companies? Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies. Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech…

Banks don't try that hard. One of my bank is happy to resend me a password by snail mail with an account ID reset by phone.

Also, rechecking the ID of a user can be as simple as asking for a new token payment by the same credit card as used by the account. It's not infailable, the CC can be compromised as well, but it should be way better than what we have now.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#233
post #25

Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…

And the second lesson is "avoid weak passwords". He admitted it was cracked because of a weak password.

But Backups should be everyone's first priority. I'm sure many of the ransomware victims would have simply restored their machines from backup--if only they had them!

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#234
post #28

Earlier quoted context omitted.

I once lost my gandi.net password. It took sending copies of 2 photo id, and answering the phone listed in the who is database before they reset it. I just wish that their DNS updates were push through faster.

That's not good verification. It takes a couple of minutes to produce convincing fake ID scans, and they aren't going to have anything to verify them against. And presumably they wanted you to send those photos to them as an unencrypted email attachment, right?

Faking ID scans adds a whole layer of law enforcement on top. I'm uncertain about the situation in the US, but in germany the fake itself is punishable by law (up 10 ten years). It also creates more traces to look at and creates work. You'd also need much more information to create a convincing fake id scan of your intended victim. It's all about increasing the amount of work for the would be attacker.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#235
post #121

Earlier quoted context omitted.

3. Established procedure was not followed Wouldn't it make sense that support staff can only generate and send out password reset mails if the PIN/password has been entered into a form? I don't know the term for this - like "coded procedure". In this case, the support staff wouldn't even needed to be trusted in the first case.

This is a great point. The software should be modified to not allow the employee to even make any modifications to the account without the correct credentials.

Agreed, and we're looking to improve this area too.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#236

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…

You are really good at it

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#237
post #147

Earlier quoted context omitted.

The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?

> This isn't a problem for banks, why is it a problem for tech companies? Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies. Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech…

> Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID.

Not always true! Less than a month ago I needed to login to my Wells Fargo account. Unbeknownst to me, they had been doing some 'upgrades' and there were some glitches. After a frustrating period, I decide I'd just go to the physical branch 1/4 mile from my house and get this fixed!

On site, the bank personnel have access to exactly the same system that I did. (At least they knew there were glitches and sorta how to work around them.) I had two accounts, one for a credit card that I rarely used and my mortgage. Turns out, if you have a credit card then the new system requires a piece of information only found on the physical card - the onsite employees couldn't get around and neither could their call-in tech support!!!!

Point is - for log-in purposes - don't assume going to a physical branch will be any more helpful!

Since I didn't have the credit card with me ('cause rarely used) I canceled the rarely used credit card and was able to login shortly thereafter.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#238
post #172

Earlier quoted context omitted.

This works well until you get to the "Our site is so secure that we need you to answer three security questions from our canned list, and they can't all be the same string" geniuses. Such an antipattern.

For every site that does this, I have a blob of text in my password manager where I write down Q: what was your childhood best friend's last name? A: pathway-titian-slowly-quiver-kodiak-hue etc., even for fact-based things like "what city were you born in?" or "what street did you live on in 1995?".

Ah, but the anti-pattern folks have a way around that.

Drop-downs for answers. Just got this on United.com:

http://imgur.com/84l0CdU

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#240
post #18

What's this crowd think of this idea for solving this problem? 1) Offer an option to opt-out of all automated account recovery. If set, no more email resets, support PINs, or similar. This would be targeted at people truly care about security and have no issue with "forgetting passwords" (i.e. you use a password manager and you're not an idiot about backups). 2) Offer in-person, manual recovery. To participate in thi…

This is more or less how NearlyFreeSpeech works. You can set what level of identity proof you need to reset your password, or disable reset entirely. They seem pretty serious about it!
Post reply on HN