Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

291–300 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#291

Earlier quoted context omitted.

Too bad you can't ask for the CVV code, and run a dummy $1 transaction. Anyone could have the last four of the card number, but the person is much more likely to have the card itself with the CVV. Disclaimer: I use AWS extensively. Please do this.

Call 1: "Hey, we just got a new credit card, can you put it on our account?" Call 2: "I just locked myself out of the account, can you reset it for me."

If you're using the payment method as auth, you should be locking it out as an auth method for X days after a change has been made, and emailing/SMSing the contact regarding the change.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#292
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

I agree on the 'customer support backdoor,' with some caveats. I worked for a small IT Services provider, and we a policy of "don't do dangerous stuff that an unknown party asks for unless a known party verifies it." But sometimes someone gets fired, and there are no known parties, especially with cloud services. I realize there has to be a way to work around 2FA, for situations like loss of device, terminations, etc…

Conflict Crusher, wow that takes me back! Back to that awful Visual Basic UI with random windows metafiles for backgrounds, what was I thinking.. :). Great to hear that I helped you on your path to become a programmer! Modding games inspired me a lot too, especially Quake and TA.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#293
post #267
post #196

Earlier quoted context omitted.

Namecheap has security notifications that inform you of login attempts. https://www.namecheap.com/support/knowledgebase/article.aspx...

This is more about preventing the social engineering attacks. The example you're replying to is where the actual user logged in 20 minutes ago, while the attacker is trying to claim to customer service that they forgot the password. If customer service were looking at login attempts, they would see that it doesn't make sense for the user to not know their password, when clearly they provided it to the site just 20 mi…

I'm aware. This is an isolated comment about other security mechanisms that are in place for the user (not for the support staff).

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#294
post #196

Earlier quoted context omitted.

This is an excellent point. > "You forgot the password that you've logged in with multiple times... including 20 minutes ago." That should raise a flag.

Namecheap has security notifications that inform you of login attempts. https://www.namecheap.com/support/knowledgebase/article.aspx...

One of the most frustrating things for support or customer service personnel to do is respond to something other than what was said.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#295

Earlier quoted context omitted.

People make mistakes. The customer support person was probably just trying to be helpful and not fully aware of all the ramifications. This is unfortunate but presumably there has been some retraining. Note: I have no direct or indirect relationship with Namecheap at all.

Sure, but retraining doesn't change the fact that people make mistakes, so it doesn't really solve the problem at all.

Sure it does. People in positions like this are required to learn. If they repeat serious mistakes like this, they're not the right fit for the job.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#296

Earlier quoted context omitted.

AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…

I'm always amazed at how little thought seems to go into these questions. My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus. One of the questions was "What's your favorite summer activity?" Her answer was, "Swimming." Yeah, that's going to add about one bit of entropy to most people's accounts, you idiots. Another favorite is "middle name of your youngest child…

Best way to handle these are to use a random string for all the answers if you can, and if they let you create your own questions use more random strings; same goes for login names.

What city was my dad born in? xGU,wT&Yvcn6vr?]#,mE of course.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#297

Since the CIO (and another employee) are here. Why are you not offering support for Google Authenticator? Last time someone asked for it was 2 years ago[1] and still no sign of the feature. Cheap prices are good to have but combining that with more security can only add value. [1]: https://www.namecheap.com/support/knowledgebase/article.aspx...

It's in the works. We're aware of the request.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#298
post #268

The real problem here is customer support not following established procedures. Maybe simulated social engineering attacks to test compliance should be part of SOP, like some companies do simulated phishing attacks.

Yes, and this matter has been appropriately handled. We'll be doing a lot more to ensure it doesn't recur.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#299

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

I had a similar situation just recently with an old Gmail account. Despite knowing the password, Gmail wants me to answer the security question or log in from a place I logged in ten years ago or list folder names (which didn't exist the last time I used that account) or ...

The whole point of this misery was to recover my Steam account to play a few games. Fortunately, Steam lets you recover your account if you can provide proof of ownership (like CD keys of physical copies).

I don't want Google to be the safekeeper of my digital identity.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#300

Earlier quoted context omitted.

AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…

I'm always amazed at how little thought seems to go into these questions. My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus. One of the questions was "What's your favorite summer activity?" Her answer was, "Swimming." Yeah, that's going to add about one bit of entropy to most people's accounts, you idiots. Another favorite is "middle name of your youngest child…

I can't reply to the sister comment for some reason, so I'll piggyback on the parent.

I always fill these with awkward or absurd questions/anwers that would be amusing if a human operator ever needs to verify them. E.g.

Would you like to go on a date with me?

What color pants am I wearing?

What is the square root of insanity?

Obviously you need to store these in a password database in order to remember them, which kind of defeats the purpose. If I have to choose from predefined questions, it goes along these lines.

Q: What was your mothers maiden name?

A: Why, are you stalking her?

Q: Where were you born?

A: Oh I can't remember, it's been so long!

Post reply on HN