Earlier quoted context omitted.
The namecheap CIO never uses the word mistake. The execs rarely show any remorse. Best case they delegate to underlings like the social media guru.
Let's not throw personal attacks at me (and the tongue-in-cheek "congrats for being promoted to executive!" comment). There's plenty of remorse and there's plenty of acknowledgment of mistakes here. That said, as we acknowledged elsewhere, we're responding to the matter across several different platforms and specifically say we're rushed in trying to get out some basic insights behind what happened and transpired. A…
Namecheap live chat social engineering leads to loss of 2 VPS
331–340 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#332Earlier quoted context omitted.
The namecheap CIO never uses the word mistake. The execs rarely show any remorse. Best case they delegate to underlings like the social media guru.
Let's not throw personal attacks at me (and the tongue-in-cheek "congrats for being promoted to executive!" comment). There's plenty of remorse and there's plenty of acknowledgment of mistakes here. That said, as we acknowledged elsewhere, we're responding to the matter across several different platforms and specifically say we're rushed in trying to get out some basic insights behind what happened and transpired. A…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#333Earlier quoted context omitted.
My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…
That's impressive, can you teach me to write like you?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#334Re: Namecheap live chat social engineering leads to loss of 2 VPS
#335Earlier quoted context omitted.
This works well until you get to the "Our site is so secure that we need you to answer three security questions from our canned list, and they can't all be the same string" geniuses. Such an antipattern.
I had something along those lines tryin to log in to mojang on a new computer. "We've not seen you log into this pc before (although I had on that IP), please answer these three security questions. Of course I don't remember so I just reset them. I imagine the new answers and the old answers had a lot in common - they were composed primarily of expletives.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#336I'd give money to a VPS, or what have you, that had a stated policy along the lines of, "here is a recovery key, here is the 2FA setup, here's how you recover your password with those items if you forget. If you call about account recovery and you do not have $REQUIRED_ITEMS, our service reps have been instructed to hang up on you. If you lose access to your account without $REQUIRED_ITEMS, you have lost access to yo…
From 2014: http://thenextweb.com/apple/2014/12/08/lost-apple-id-learnt-...
They no longer do this: https://support.apple.com/en-us/HT204921
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#337Re: Namecheap live chat social engineering leads to loss of 2 VPS
#338Earlier quoted context omitted.
Let's not throw personal attacks at me (and the tongue-in-cheek "congrats for being promoted to executive!" comment). There's plenty of remorse and there's plenty of acknowledgment of mistakes here. That said, as we acknowledged elsewhere, we're responding to the matter across several different platforms and specifically say we're rushed in trying to get out some basic insights behind what happened and transpired. A…
It's a common practice. I don't see how it is personally offensive to you. My description was for the CIO and execs in general, yet you insisted they were for you. So maybe you should stop making tongue-in-cheek comments. In fact, I am moving my domains off of Namecheap because I don't think Namecheap is very good at handling customer relations, particularly on social media.
To be fair, your third edit was only for me. And that was the only comment I was replying to.
As I said, we are working to respond to hundreds of comments across dozens of platforms. I certainly respect your distaste in the more rushed responses in order to address all of the deluge, and that is why we were also simultaneously working on a longer and more thoughtful response that speaks for all of us at the company via that blog post (in a far more emotional tone).
It certainly is difficult to envision the challenges of responding to dozens of responses if you're not in our shoes. But I genuinely thank you for the feedback - and we're noting this (as well as the feedback all have been sent to date; a lot of that was factored into policy adjustment and our blog response) for handling it differently next time.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#339I'd give money to a VPS, or what have you, that had a stated policy along the lines of, "here is a recovery key, here is the 2FA setup, here's how you recover your password with those items if you forget. If you call about account recovery and you do not have $REQUIRED_ITEMS, our service reps have been instructed to hang up on you. If you lose access to your account without $REQUIRED_ITEMS, you have lost access to yo…
I don't know... Apple did this for a while, and it backfired on them. The average user (even technically savvy user) simply wasn't competent enough to understand that they really truly would be locked out forever. From 2014: http://thenextweb.com/apple/2014/12/08/lost-apple-id-learnt-... They no longer do this: https://support.apple.com/en-us/HT204921
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#340Earlier quoted context omitted.
My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…
That's impressive, can you teach me to write like you?
* Actually apologize in a human way
* Show empathy by identifying the impact of what happened to customers (not your impact internally)
* State action items that you've created, even if they are just in 'evaluation' state
* Indicate that the specific incident in question is being handled outside of this forum
* Take responsibility for things even if you shouldn't "have to"