Earlier quoted context omitted.
its better verification than most will require.
Most will require a password reset email, I'd say that's significantly better than asking for ID scans. Edit: Since I'm getting some downvotes I'd really like to know how one could possibly argue that asking for ID scans is better than email resets. You can't really forge the ability to receive email at an address, but you can very easily replace the name on an ID scan.
Namecheap live chat social engineering leads to loss of 2 VPS
241–250 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#242Earlier quoted context omitted.
What if any fault does Namecheap take with the breach and what is being done to resolve it?
See my other comments in this thread
Am I missing something, or is Namecheap saying they didn't do anything wrong?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#243Earlier quoted context omitted.
Eh.. I don't really agree that this is victim blaming. But then again, I find that I disagree with most uses of the phrase "victim blaming". Pointing out that somebody did something sub-optimal, while still acknowledging the mis-deeds, mistakes, etc. of other parties, is not "victim blaming" in my book. It's just pointing out the truth. I mean, if you go for a stroll through the roughest neighborhood in town, unarmed…
>I mean, if you go for a stroll through the roughest neighborhood in town, unarmed, by yourself, at night, and you get mugged, is it wrong to point out that going for that walk was stupid? Yes, this is the textbook example of victim blaming. Placing any amount of blame on the person who is the victim in this situation is saying that they don't have the right to walk down a street and not be mugged. I am admittedly no…
Then "victim blaming" is a meaningless concept and we should quit using it. Because if I choose to do something stupid, I do bear some responsibility for the outcome, even if somebody else violates my rights. That doesn't absolve the other party of course, which is my point. That is, you can blame the perpetrator of a crime while also pointing out that the victim could (possibly should) have done things differently.
Placing any amount of blame on the person who is the victim in this situation is saying that they don't have the right to walk down a street and not be mugged.
It isn't "blame" for the actions of the other person. Why wouldn't you point out the stupidity of knowingly putting yourself in a dangerous situation?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#244Earlier quoted context omitted.
I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.
AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#245Earlier quoted context omitted.
That's not good verification. It takes a couple of minutes to produce convincing fake ID scans, and they aren't going to have anything to verify them against. And presumably they wanted you to send those photos to them as an unencrypted email attachment, right?
Faking ID scans adds a whole layer of law enforcement on top. I'm uncertain about the situation in the US, but in germany the fake itself is punishable by law (up 10 ten years). It also creates more traces to look at and creates work. You'd also need much more information to create a convincing fake id scan of your intended victim. It's all about increasing the amount of work for the would be attacker.
That's why nobody has ever used a fake ID at a bar!
> but in germany the fake itself is punishable by law (up 10 ten years).
https://dejure.org/gesetze/StGB/267.html 5 years.
But producing fake scans isn't covered by this law, scans aren't even an official document. In fact, it is illegal for a german company to ask you to send them scans of official documents.
> You'd also need much more information to create a convincing fake id scan of your intended victim
To fake a good enough passport scan you'd need your victims name. That's all the rep is going to have.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#246Earlier quoted context omitted.
The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?
> This isn't a problem for banks, why is it a problem for tech companies? Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies. Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#247Earlier quoted context omitted.
I had a similar thing happen with my Battle.net account. I forgot to transfer over my authenticator backup code when I switched password managers last time. I had to send them a photo of my driver's license next to my face and another one of it next to a physical newspaper with the date on it. This seems like a much better process for recovering accounts that matter.
So what do you think happened to those photos? Some people would be happy to pay for a leaked copy of those photos, for use with any other company that would accept only the "face/license" photo as sufficient proof.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#248Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
And although it's not you area, can I just say that Namecheap's website is just way too slow since the redesign? I appreciate that you even did a redesign, but for some reason it's one of the slowest websites around. I don't know if it's because of the large images you use on your pages or what's the problem, but I suggest you fix it. It may be losing you customers. A web services company's site should be snappy.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#249Earlier quoted context omitted.
Most will require a password reset email, I'd say that's significantly better than asking for ID scans. Edit: Since I'm getting some downvotes I'd really like to know how one could possibly argue that asking for ID scans is better than email resets. You can't really forge the ability to receive email at an address, but you can very easily replace the name on an ID scan.
Did you read the article? I ask because one of the problems was a compromised email account.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#250Earlier quoted context omitted.
This seems very easy to bypass.
Very easy? I'd say "possible" at best . And now you've got access to a battle.net account. Took a heck of a lot more work than asking someone for username/pass in a live chat, and what you gained access to is worth a heck of a lot less. Plus Blizzard actually does keep backups and records and will be able to fix the situation for the account owner. I'd be surprised if ever a Blizzard account was compromised by someon…
There's services on the darknet where you can buy these fake Id picture/scans as well.