Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

281–290 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#281

Earlier quoted context omitted.

We have had this at Amazon AWS. We had 2FA, one phone call was enough to disable 2FA. The only thing they asked were the last four digits of our credit card.

Too bad you can't ask for the CVV code, and run a dummy $1 transaction. Anyone could have the last four of the card number, but the person is much more likely to have the card itself with the CVV. Disclaimer: I use AWS extensively. Please do this.

Call 1: "Hey, we just got a new credit card, can you put it on our account?"

Call 2: "I just locked myself out of the account, can you reset it for me."

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#282
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

This is why I think a manual disable is the best bet.

I backup my 2FA tokens using TiBu (encrypted locally and uploaded straight to cloud services). I'm 99.9% sure I'm never going to lose them.

I want an option in my panel that says "do not let me use support without providing a 2fa token".

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#283
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

What was SingleHop's response to this when you made them aware? We have servers with them.

I tried to call a few times and unfortunately kept getting disconnected from my VoIP line. I ended up using their live chat and the person I spoke to was very quick in recognizing it as a social engineering attack and worked with me to reset all my information.

Following up I had to reset my passwords a few more times to ensure the attacker's session was properly terminated. They identified the IPs accessing my account but they were all proxy IPs from Europe and Israel so not much could be done.

I still have the support tickets the attacker made, and I feel their support staff should have recognized it as a compromised account (they changed the name to "John Smith", bad spelling / grammar, asking to reset the root password, accidentally "lost" their private key and need password logins and root SSH enabling, etc).

Aside from this incident though I've been pretty happy there, the hardware is competitive, uptime is good and the network is solid which is all I really ask for with a server provider.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#284
post #206

Earlier quoted context omitted.

Matthew, It sounds like you are confirming that this incident did happen and it was your fault for not following your procedures. I am not a lawyer, but since there was signification loss, it would probably be in your best interest to offer better reparations. OpenDomain has several domains that are on NameCheap - I will transfer them immediately since it appears you do not care about customers.

OpenDomain - We have apologized, admitted mistakes, and made tremendous internal change to move on for the better. We would not do that or even post here if we didn't care.

The offer of a free year of hosting is nonetheless a paltry joke. The high road here is to acknowledge that customer may choose never to host with you again and still go above and beyond in attempting to make it right to them, e.g. by offering a full refund for the last year of hosting they'd paid for or the like.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#285

If you only use 2FA on ONE THING online, make it your email! How could you not consider your email the most important service of all? It is your identity!

I'm going to go ahead and say that he used an email service which does not offer 2FA since every email service that does support 2FA probably has a good brute force protection.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#286

Earlier quoted context omitted.

Too bad you can't ask for the CVV code, and run a dummy $1 transaction. Anyone could have the last four of the card number, but the person is much more likely to have the card itself with the CVV. Disclaimer: I use AWS extensively. Please do this.

Call 1: "Hey, we just got a new credit card, can you put it on our account?" Call 2: "I just locked myself out of the account, can you reset it for me."

[deleted]

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#287

Earlier quoted context omitted.

AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…

Favorite restaurant! What percent of the full business name did you use? Did you capitalize all the letters the same way or in a consistent predictable way? Did you add a word to meet the minimum character/word count? Did you actually have a favorite when you made this? Is your favorite restaurant public information?

This is why I set all my security question answers to a single answer for low security stuff and random pronounceable strings (in case I ever need to read them to a support person) stored in KeePass for high security stuff.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#288

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

Comcast's password recovery is pretty weak. I just did it last night. They ask for your zip code and your favorite sports team. If I have a Boston zip code there are likely only 4 options for favorite sports team.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#289

Earlier quoted context omitted.

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

Story time: I have been trying for 3 years to figure out what I wanted to hint at with "If it's not this one then it's the other one" as a secret question. I thought I was a clever boy not choosing the usual predetermined "what's your mother's name ?".

-1?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#290

So full of failure, this thread. No, it is never okay to compromise security just because "it's good when you forget your password". There should be no way around this for any reason; a bypass via SE or any other mechanism is a failure of the company, end of. If you forget your password or you do not have your 2FA/security questions available, tough, you should lose access. For the sake of "workarounds for legitimate…

>No, it is never okay to compromise security just because "it's good when you forget your password".

No one is arguing that.

Post reply on HN