Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

301–310 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#301
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

That's crazy that customer service was able to turn off 2 factor!

Godaddy has gotten really good at preventing social engineering stacks like this. I use 2 factor authentication for my account and customer service can't event talk to me till I give them the code. Don't have that? Need to send them my drivers license and other proof to get the account reset.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#303
post #57

So he is using 2FA for all the important accounts but for the most important one (the email which he used to register an account at all these services) he's using a weak pw and no 2FA? Am i missing something here? Yes they did not follow protocol but why would one not use 2FA for such an important email addy?

Correct. I'm surprised no one else has mentioned no 2FA for the email. The email being compromised opened the door to this happening.

The email being compromised opened the door to his email being compromised. The door to his Namecheap account being compromised was apparently already wide open.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#304
post #155

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

One option is to look at when the user last logged in. I would be a lot less pissed if an account that I've never touched in 10 years got compromised... I'm probably going to remember my info for recent accounts and want it to be difficult to social engineering those

> I would be a lot less pissed if an account that I've never touched in 10 years got compromised

Depends on what that account controlled.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#305

Earlier quoted context omitted.

Correct. I'm surprised no one else has mentioned no 2FA for the email. The email being compromised opened the door to this happening.

The email being compromised opened the door to his email being compromised. The door to his Namecheap account being compromised was apparently already wide open.

No, OP didn't have 2FA enabled on their namecheap account. It was namecheap's fault for improper handling of the social engineering attack but OP could have protected themselves by having 2FA

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#306
post #28

Earlier quoted context omitted.

I once lost my gandi.net password. It took sending copies of 2 photo id, and answering the phone listed in the who is database before they reset it. I just wish that their DNS updates were push through faster.

That's not good verification. It takes a couple of minutes to produce convincing fake ID scans, and they aren't going to have anything to verify them against. And presumably they wanted you to send those photos to them as an unencrypted email attachment, right?

That was a few years back when another well-known registrar only required the last 4 digit of the customer's credit card, and would even help them guess if they didn't remember.

I sent the ids by fax (yeah a few years back, I still had a fax machine).

I thought asking for id's + phoning on the number listed in the whois database was a good cross check, especially back then.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#307
post #296

Earlier quoted context omitted.

I'm always amazed at how little thought seems to go into these questions. My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus. One of the questions was "What's your favorite summer activity?" Her answer was, "Swimming." Yeah, that's going to add about one bit of entropy to most people's accounts, you idiots. Another favorite is "middle name of your youngest child…

Best way to handle these are to use a random string for all the answers if you can, and if they let you create your own questions use more random strings; same goes for login names. What city was my dad born in? xGU,wT&Yvcn6vr?]#,mE of course.

I did that to my payroll account to try and prevent this very issue.

Little did I know that it's one of those services you need the password (I had written that down at the time as it was temporary) AND these questions that are usually used for password resets.

I don't think that will ever get fixed until I change jobs again.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#308
post #296

Earlier quoted context omitted.

I'm always amazed at how little thought seems to go into these questions. My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus. One of the questions was "What's your favorite summer activity?" Her answer was, "Swimming." Yeah, that's going to add about one bit of entropy to most people's accounts, you idiots. Another favorite is "middle name of your youngest child…

Best way to handle these are to use a random string for all the answers if you can, and if they let you create your own questions use more random strings; same goes for login names. What city was my dad born in? xGU,wT&Yvcn6vr?]#,mE of course.

Until someone says "I know my dad was born in Minneapolis, what does it say??" and the customer service representative replies "Huh, it looks like the answer is just gibberish...", "Ah! I must have just mashed on my keyboard when I made the account, sorry about that!!", "No problem, your password is now reset to foobar".

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#309

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…

That's impressive, can you teach me to write like you?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#310
post #227

Earlier quoted context omitted.

I don't see how that can be the biggest lesson. Someone at the service provider bypassed their own protocols in order to hand control of the system over to an unauthorized user. Even with local backups he would have needed to restore the servers because Namecheap royally screwed up. Yes, you should always have more backups than you need. But wouldn't you be moving to a different provider after something like this any…

Yes, I would move. Impossible to do without the data, which is why it was the biggest takeaway to me.

Understood. I guess my point is that almost every data story can end with "should have had better backups" as the lesson.
Post reply on HN