Earlier quoted context omitted.
Too bad you can't ask for the CVV code, and run a dummy $1 transaction. Anyone could have the last four of the card number, but the person is much more likely to have the card itself with the CVV. Disclaimer: I use AWS extensively. Please do this.
Call 1: "Hey, we just got a new credit card, can you put it on our account?" Call 2: "I just locked myself out of the account, can you reset it for me."
Namecheap live chat social engineering leads to loss of 2 VPS
291–300 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#292I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
I agree on the 'customer support backdoor,' with some caveats. I worked for a small IT Services provider, and we a policy of "don't do dangerous stuff that an unknown party asks for unless a known party verifies it." But sometimes someone gets fired, and there are no known parties, especially with cloud services. I realize there has to be a way to work around 2FA, for situations like loss of device, terminations, etc…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#293Earlier quoted context omitted.
Namecheap has security notifications that inform you of login attempts. https://www.namecheap.com/support/knowledgebase/article.aspx...
This is more about preventing the social engineering attacks. The example you're replying to is where the actual user logged in 20 minutes ago, while the attacker is trying to claim to customer service that they forgot the password. If customer service were looking at login attempts, they would see that it doesn't make sense for the user to not know their password, when clearly they provided it to the site just 20 mi…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#294Earlier quoted context omitted.
This is an excellent point. > "You forgot the password that you've logged in with multiple times... including 20 minutes ago." That should raise a flag.
Namecheap has security notifications that inform you of login attempts. https://www.namecheap.com/support/knowledgebase/article.aspx...
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#295Earlier quoted context omitted.
People make mistakes. The customer support person was probably just trying to be helpful and not fully aware of all the ramifications. This is unfortunate but presumably there has been some retraining. Note: I have no direct or indirect relationship with Namecheap at all.
Sure, but retraining doesn't change the fact that people make mistakes, so it doesn't really solve the problem at all.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#296Earlier quoted context omitted.
AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…
I'm always amazed at how little thought seems to go into these questions. My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus. One of the questions was "What's your favorite summer activity?" Her answer was, "Swimming." Yeah, that's going to add about one bit of entropy to most people's accounts, you idiots. Another favorite is "middle name of your youngest child…
What city was my dad born in? xGU,wT&Yvcn6vr?]#,mE of course.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#297Since the CIO (and another employee) are here. Why are you not offering support for Google Authenticator? Last time someone asked for it was 2 years ago[1] and still no sign of the feature. Cheap prices are good to have but combining that with more security can only add value. [1]: https://www.namecheap.com/support/knowledgebase/article.aspx...
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#298The real problem here is customer support not following established procedures. Maybe simulated social engineering attacks to test compliance should be part of SOP, like some companies do simulated phishing attacks.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#299Earlier quoted context omitted.
It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…
I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.
The whole point of this misery was to recover my Steam account to play a few games. Fortunately, Steam lets you recover your account if you can provide proof of ownership (like CD keys of physical copies).
I don't want Google to be the safekeeper of my digital identity.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#300Earlier quoted context omitted.
AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…
I'm always amazed at how little thought seems to go into these questions. My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus. One of the questions was "What's your favorite summer activity?" Her answer was, "Swimming." Yeah, that's going to add about one bit of entropy to most people's accounts, you idiots. Another favorite is "middle name of your youngest child…
I always fill these with awkward or absurd questions/anwers that would be amusing if a human operator ever needs to verify them. E.g.
Would you like to go on a date with me?
What color pants am I wearing?
What is the square root of insanity?
Obviously you need to store these in a password database in order to remember them, which kind of defeats the purpose. If I have to choose from predefined questions, it goes along these lines.
Q: What was your mothers maiden name?
A: Why, are you stalking her?
Q: Where were you born?
A: Oh I can't remember, it's been so long!