Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

341–350 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#341

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

Matthew, It sounds like you are confirming that this incident did happen and it was your fault for not following your procedures. I am not a lawyer, but since there was signification loss, it would probably be in your best interest to offer better reparations. OpenDomain has several domains that are on NameCheap - I will transfer them immediately since it appears you do not care about customers.

Tell me one registrar where you can be sure that this will not happen and I will move my domains today. I wouldn't even care if I have to pay 100$ per year for a domain.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#342
post #64

Earlier quoted context omitted.

Example of on HN expecting everyone (newbies and all) to know who you are. This happens with DANG and SAMA comments as well. Back when PG used to comment also happened. Look at their profiles, really no explanation of who they are here: https://news.ycombinator.com/user?id=pg https://news.ycombinator.com/user?id=dang https://news.ycombinator.com/user?id=sama Why is it so hard to put info in your profile or to put a f…

He posted this down the thread which starts with: > Disclaimer: I'm CIO @ Namecheap https://news.ycombinator.com/item?id=11479810

Still not outrageous to think that people might be able to give rookies some context rather than check the full thread for other comments doing so.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#343
post #319
post #300

Earlier quoted context omitted.

I can't reply to the sister comment for some reason, so I'll piggyback on the parent. I always fill these with awkward or absurd questions/anwers that would be amusing if a human operator ever needs to verify them. E.g. Would you like to go on a date with me? What color pants am I wearing? What is the square root of insanity? Obviously you need to store these in a password database in order to remember them, which ki…

I've just started filling them with randomly generated strings that my password manager helpfully creates for me. Though, apparently my bank uses those answers for phone verification also, which makes answering questions like "What's your Significant Other's nickname?" awkward when the answer is "F9-#g7a2<qj"

Use a random but user friendly value

#$%&+@ is going to be hard to type or speak, just say their nickname is "the frozen one", same entropy, easier to handle

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#344
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

To be fair, that's a game account. I realize some MMOs can have really real-money valuable characters/items, so this argument can break down, but the security should be different from an MMO and a VPS solution or a bank.

All of my security questions are passwords. I once had someone at a bank ask "Wait, your mother's maiden's name has a number in it?"

"Wait, you actually answer security questions that any of your friends can guess honestly?"

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#345

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

Matthew, It sounds like you are confirming that this incident did happen and it was your fault for not following your procedures. I am not a lawyer, but since there was signification loss, it would probably be in your best interest to offer better reparations. OpenDomain has several domains that are on NameCheap - I will transfer them immediately since it appears you do not care about customers.

[deleted]

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#346
post #242

Earlier quoted context omitted.

See my other comments in this thread

I've reviewed all 16 of your comments on the page and beyond sawing a single person at Namecheap didn't follow policy and blaming the user in question, I don't see anywhere that you've stated there's an issue with controls. Am I missing something, or is Namecheap saying they didn't do anything wrong?

You can't expect them to admit liability now can you? They offered the customer a year free of their shitty hosting without admitting fault after all.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#347
post #305

Earlier quoted context omitted.

The email being compromised opened the door to his email being compromised. The door to his Namecheap account being compromised was apparently already wide open.

No, OP didn't have 2FA enabled on their namecheap account. It was namecheap's fault for improper handling of the social engineering attack but OP could have protected themselves by having 2FA

The article pretty clearly states 2FA was enabled for the Namecheap account in question. In fact, that is sort of the whole point of the article.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#348

Earlier quoted context omitted.

"Better be safe than sorry" - namecheap for when you lose your stuff on their services. I don't think the best way to respond to a public vent is "Here's what you should have done instead". Responses might be technically correct but they lack empathy for the customer.

"Hard drives never fail" - kelukelugames

We've banned this account for repeatedly violating the HN guidelines. If you don't want it to be banned, you're welcome to email hn@ycombinator.com.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#349

Earlier quoted context omitted.

The issue is that Namecheap was the one that fucked up here, and now is not the time to emphasize "you should really be prepared for us fucking up in this manner". It's victim blaming. It looks shitty. The argument I refer to isn't "you should have offsite backups". The argument is that Namecheap is implicitly victim blaming, and they're not going to convince many people that they aren't.

Eh.. I don't really agree that this is victim blaming. But then again, I find that I disagree with most uses of the phrase "victim blaming". Pointing out that somebody did something sub-optimal, while still acknowledging the mis-deeds, mistakes, etc. of other parties, is not "victim blaming" in my book. It's just pointing out the truth. I mean, if you go for a stroll through the roughest neighborhood in town, unarmed…

I don't know where any of you live, but saying recklessness is "victim blaming" sounds like a first world privilege. Yes, in generally in the first world, screaming for your rights can actually work.

In other worlds however, the problem is usually too widespread. You might get a lot of attention, comiseration, etc. but in the end, being reckless goes against survival. People who point this out should not be shushed for pointing out what you need to do to survive.

Its amazing to see that this "victim blaming" mentality is growing in Brazil. Violence here is out of control. You might get mugged/shot/kidnapped for no reason, or not displaying any wealth. Having been kidnapped myself, and chatted with the kidnappers, they do look for signs of wealth before pouncing. Therefore, yes, the victim does has an ounce of control over their risk and it's not wrong to point that out.

It does not solve violence, and attackers will just look for other victims regardless of their reward estimate. However, would you tell your children not to not show affluence/vulnerability in shady places just because you don't want to "victim blame"?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#350

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

To be fair, that's a game account. I realize some MMOs can have really real-money valuable characters/items, so this argument can break down, but the security should be different from an MMO and a VPS solution or a bank. All of my security questions are passwords. I once had someone at a bank ask "Wait, your mother's maiden's name has a number in it?" "Wait, you actually answer security questions that any of your fri…

> To be fair, that's a game account. I realize some MMOs can have really real-money valuable characters/items, so this argument can break down

You want to know how bad it can break down? I imagine the worst case scenario, for so many reasons, actually happened and was mtgox.com. It started out as a Magic: The Gathering Online Exchange (from what I understand) before it became the now infamous Bitcoin exchange that was hacked[1] and massive amounts of money was stolen. I don't know for a fact that old accounts before the pivot to Bitcoin still existed and worked, but it's not inconceivable that they would. One hopes they adopted much better security compared to when they were a trading card exchange (if it wasn't already exceptional at that time), but there could very well have been a time when it was gaining traction for financial type services but didn't have good account safeguards.

1: Or whatever. From what I remember that's a story convoluted and with enough conspiracy theories it's worth a movie.

Post reply on HN