Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

241–250 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#241
post #47

Earlier quoted context omitted.

its better verification than most will require.

Most will require a password reset email, I'd say that's significantly better than asking for ID scans. Edit: Since I'm getting some downvotes I'd really like to know how one could possibly argue that asking for ID scans is better than email resets. You can't really forge the ability to receive email at an address, but you can very easily replace the name on an ID scan.

Did you read the article? I ask because one of the problems was a compromised email account.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#242
post #82

Earlier quoted context omitted.

What if any fault does Namecheap take with the breach and what is being done to resolve it?

See my other comments in this thread

I've reviewed all 16 of your comments on the page and beyond sawing a single person at Namecheap didn't follow policy and blaming the user in question, I don't see anywhere that you've stated there's an issue with controls.

Am I missing something, or is Namecheap saying they didn't do anything wrong?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#243

Earlier quoted context omitted.

Eh.. I don't really agree that this is victim blaming. But then again, I find that I disagree with most uses of the phrase "victim blaming". Pointing out that somebody did something sub-optimal, while still acknowledging the mis-deeds, mistakes, etc. of other parties, is not "victim blaming" in my book. It's just pointing out the truth. I mean, if you go for a stroll through the roughest neighborhood in town, unarmed…

>I mean, if you go for a stroll through the roughest neighborhood in town, unarmed, by yourself, at night, and you get mugged, is it wrong to point out that going for that walk was stupid? Yes, this is the textbook example of victim blaming. Placing any amount of blame on the person who is the victim in this situation is saying that they don't have the right to walk down a street and not be mugged. I am admittedly no…

Yes, this is the textbook example of victim blaming.

Then "victim blaming" is a meaningless concept and we should quit using it. Because if I choose to do something stupid, I do bear some responsibility for the outcome, even if somebody else violates my rights. That doesn't absolve the other party of course, which is my point. That is, you can blame the perpetrator of a crime while also pointing out that the victim could (possibly should) have done things differently.

Placing any amount of blame on the person who is the victim in this situation is saying that they don't have the right to walk down a street and not be mugged.

It isn't "blame" for the actions of the other person. Why wouldn't you point out the stupidity of knowingly putting yourself in a dangerous situation?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#244

Earlier quoted context omitted.

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…

Favorite restaurant! What percent of the full business name did you use? Did you capitalize all the letters the same way or in a consistent predictable way? Did you add a word to meet the minimum character/word count? Did you actually have a favorite when you made this? Is your favorite restaurant public information?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#245
post #28

Earlier quoted context omitted.

That's not good verification. It takes a couple of minutes to produce convincing fake ID scans, and they aren't going to have anything to verify them against. And presumably they wanted you to send those photos to them as an unencrypted email attachment, right?

Faking ID scans adds a whole layer of law enforcement on top. I'm uncertain about the situation in the US, but in germany the fake itself is punishable by law (up 10 ten years). It also creates more traces to look at and creates work. You'd also need much more information to create a convincing fake id scan of your intended victim. It's all about increasing the amount of work for the would be attacker.

>Faking ID scans adds a whole layer of law enforcement on top.

That's why nobody has ever used a fake ID at a bar!

> but in germany the fake itself is punishable by law (up 10 ten years).

https://dejure.org/gesetze/StGB/267.html 5 years.

But producing fake scans isn't covered by this law, scans aren't even an official document. In fact, it is illegal for a german company to ask you to send them scans of official documents.

> You'd also need much more information to create a convincing fake id scan of your intended victim

To fake a good enough passport scan you'd need your victims name. That's all the rep is going to have.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#246
post #147

Earlier quoted context omitted.

The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?

> This isn't a problem for banks, why is it a problem for tech companies? Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies. Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech…

There are quite a few banks that don't have physical locations you can go to.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#247

Earlier quoted context omitted.

I had a similar thing happen with my Battle.net account. I forgot to transfer over my authenticator backup code when I switched password managers last time. I had to send them a photo of my driver's license next to my face and another one of it next to a physical newspaper with the date on it. This seems like a much better process for recovering accounts that matter.

So what do you think happened to those photos? Some people would be happy to pay for a leaked copy of those photos, for use with any other company that would accept only the "face/license" photo as sufficient proof.

I think having a recent date on the newspaper prevents reuse of the images. I'm not a Photoshop expert, so maybe that's trivial to change. When I look at my support ticket history on the website, the ticket attachments are gone, so hopefully they're shredded after the support person views them.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#248

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

Regardless, to fix this PR disaster, I suggest you add some strong and perhaps just as importantly modern security features in the future that would regain you good will with HN types (and therefore everyone else).

And although it's not you area, can I just say that Namecheap's website is just way too slow since the redesign? I appreciate that you even did a redesign, but for some reason it's one of the slowest websites around. I don't know if it's because of the large images you use on your pages or what's the problem, but I suggest you fix it. It may be losing you customers. A web services company's site should be snappy.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#249
post #47

Earlier quoted context omitted.

Most will require a password reset email, I'd say that's significantly better than asking for ID scans. Edit: Since I'm getting some downvotes I'd really like to know how one could possibly argue that asking for ID scans is better than email resets. You can't really forge the ability to receive email at an address, but you can very easily replace the name on an ID scan.

Did you read the article? I ask because one of the problems was a compromised email account.

I did. It doesn't change anything, email is still a way better verification method than ID scans that the company will be unable to authenticate.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#250

Earlier quoted context omitted.

This seems very easy to bypass.

Very easy? I'd say "possible" at best . And now you've got access to a battle.net account. Took a heck of a lot more work than asking someone for username/pass in a live chat, and what you gained access to is worth a heck of a lot less. Plus Blizzard actually does keep backups and records and will be able to fix the situation for the account owner. I'd be surprised if ever a Blizzard account was compromised by someon…

I don't know what battle.net is so I was speaking generally. Since pictures don't have security features on them it wouldn't be too difficult to photocopy your own id, change the name/address, print it out and glue it on a plastic card. You now have an Id that looks good enough for photo verification. It's a lot of work but if the steaks are high then it will be done. There's also the case when these pictures get leaked, there's a lot of people who have scans of my id. Or just photoshop the pic after its taken.

There's services on the darknet where you can buy these fake Id picture/scans as well.

Post reply on HN