Earlier quoted context omitted.
Just confirmed with our CTO. He was able to turn MFA off on our root AWS account over the phone.
Huh. I'm going to say thanks to HN, and this comment chain, for bringing this to light. That seems kind of insane.
Namecheap live chat social engineering leads to loss of 2 VPS
321–330 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#322Earlier quoted context omitted.
Best way to handle these are to use a random string for all the answers if you can, and if they let you create your own questions use more random strings; same goes for login names. What city was my dad born in? xGU,wT&Yvcn6vr?]#,mE of course.
Until someone says "I know my dad was born in Minneapolis, what does it say??" and the customer service representative replies "Huh, it looks like the answer is just gibberish...", "Ah! I must have just mashed on my keyboard when I made the account, sorry about that!!", "No problem, your password is now reset to foobar".
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#323Earlier quoted context omitted.
You can get AWS customer support to reset your password if you know the last 4 digits of the credit card used to pay for the account. This is the same info that's printed on any credit card receipt.
If they have your bank account number for whatever reason you can also use last 4 of the bank account number. Your bank account number is not secret by design and most people only have one.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#324I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
That's crazy that customer service was able to turn off 2 factor! Godaddy has gotten really good at preventing social engineering stacks like this. I use 2 factor authentication for my account and customer service can't event talk to me till I give them the code. Don't have that? Need to send them my drivers license and other proof to get the account reset.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#325Earlier quoted context omitted.
If I wanted more security on my account, is there a different service I should be using?
I once lost my gandi.net password. It took sending copies of 2 photo id, and answering the phone listed in the who is database before they reset it. I just wish that their DNS updates were push through faster.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#326As someone in the domain registrar industry, are there any features beyond 2FA that you would like to see implemented by registrars? More bluntly, what is it that you think your current registrar is lacking? I read a few comments on Gandi and support of GPG keys. I'm guessing this is what you're referring to: https://wiki.gandi.net/en/gandi/documents
Let users chose if their account can be recovered through a password reset form, let users leave 'secret memos' for support which can't be viewed on the site later, let the users decide if their accounts can be altered in any way by support staff, etc, etc.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#327Earlier quoted context omitted.
I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.
AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…
I gave the name, was asked to repeat it, so I did, they informed me I was wrong.
I still don't know if they had a name with a typo in the records, a maidem name, or maybe they didn't even have her name (don't remember telling the bank about marital status) and it was some sort of trick question where I was supposed to answer I'm single (even though I wasn't).
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#328Earlier quoted context omitted.
Very easy? I'd say "possible" at best . And now you've got access to a battle.net account. Took a heck of a lot more work than asking someone for username/pass in a live chat, and what you gained access to is worth a heck of a lot less. Plus Blizzard actually does keep backups and records and will be able to fix the situation for the account owner. I'd be surprised if ever a Blizzard account was compromised by someon…
It seems like a general principle that the less important something is, the better the security probably is. Steam, for example, is really paranoid, constantly asking for verification whenever it thinks I'm logging in from a new computer, bugging me nonstop to set up 2FA, e-mailing me with alerts, etc. Meanwhile my bank does straightforward username/password authentication, with the bonus that the password is case in…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#329Earlier quoted context omitted.
Very easy? I'd say "possible" at best . And now you've got access to a battle.net account. Took a heck of a lot more work than asking someone for username/pass in a live chat, and what you gained access to is worth a heck of a lot less. Plus Blizzard actually does keep backups and records and will be able to fix the situation for the account owner. I'd be surprised if ever a Blizzard account was compromised by someon…
It seems like a general principle that the less important something is, the better the security probably is. Steam, for example, is really paranoid, constantly asking for verification whenever it thinks I'm logging in from a new computer, bugging me nonstop to set up 2FA, e-mailing me with alerts, etc. Meanwhile my bank does straightforward username/password authentication, with the bonus that the password is case in…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#330I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
We have had this at Amazon AWS. We had 2FA, one phone call was enough to disable 2FA. The only thing they asked were the last four digits of our credit card.