Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

351–360 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#351

Earlier quoted context omitted.

Low end hosting doesn't generally have backups, because it's well, cheap. Extra overheads make the price increase, then you're not cheap and can't compete at that end. Usually there are backup options included in the plan for upsell possibilities with these kinds of providers. Really, you should not expect a service that has 'cheap' in the name to offer any kind of backup.

Furthermore, is Namecheap authorized to copy their clients' data by their terms of service? If not, automatic backups may bypass totally-reasonable expectations that other users have. Backups can potentially be a threat vector, for example. There might be many reasons why one of Namecheap's clients might say "you copied this data?! and now I have no control of the environment the backup lives in?!"... An example woul…

That's true, although we should be fairly concerned about a company using very cheap hosting on VPS with no form of encryption storing anything sensitive. You may also be breaching PCI DSS (fwiw) doing that.

In reality though, more companies do this than should be allowed. I worked for an ISP in a previous life and even on the super cheap shared hosting there were companies that were making a decent turnover and then using the cheapest possible hosting for their email/site. The quantity of these companies was a significant number too.

Especially when they were kicking off on the phone due to inevitable maintenance/downtime. Trying to appease customers that turn over 10 million a year and pay £5 a month for hosting is a bit wtf. You pay for what you get... that's no different in hosting.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#352

Earlier quoted context omitted.

Low end hosting doesn't generally have backups, because it's well, cheap. Extra overheads make the price increase, then you're not cheap and can't compete at that end. Usually there are backup options included in the plan for upsell possibilities with these kinds of providers. Really, you should not expect a service that has 'cheap' in the name to offer any kind of backup.

> Really, you should not expect a service that has 'cheap' in the name to offer any kind of backup. They never spell this out for you though, usually they imply that their service is just as good as their pricier rivals. As a result, many people get burnt before they get savvy. Some never get savvy, they just get turned off to the industry. Not sure what the alternative is. I suspect a company that did clearly spell…

There are a couple of adages that may be valid.

"If it's too good to be true, it probably is"

and

"Cheap, Good, Fast - pick two"

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#353
post #319

Earlier quoted context omitted.

I've just started filling them with randomly generated strings that my password manager helpfully creates for me. Though, apparently my bank uses those answers for phone verification also, which makes answering questions like "What's your Significant Other's nickname?" awkward when the answer is "F9-#g7a2<qj"

Use a random but user friendly value #$%&+@ is going to be hard to type or speak, just say their nickname is "the frozen one", same entropy, easier to handle

>> What's your Significant Other's nickname?

> Use a random but user friendly value

> "the frozen one"

I imagine that may make make your significant other who was previously friendly, markedly less so, if they see your "friendly value". But that may have been your point, as it may be quite a bit easier to remember. :)

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#354

Earlier quoted context omitted.

AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…

I once tried to perform an internet banking task only to find out I had to call in by phone and enable it first. So I did, and I was asked a few security questions about my data, one of them was: what's the name of your spouse? I gave the name, was asked to repeat it, so I did, they informed me I was wrong. I still don't know if they had a name with a typo in the records, a maidem name, or maybe they didn't even have…

Did you by-chance try substituting all "n's" with "m's" in your spouse's name?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#355
post #338

Earlier quoted context omitted.

It's a common practice. I don't see how it is personally offensive to you. My description was for the CIO and execs in general, yet you insisted they were for you. So maybe you should stop making tongue-in-cheek comments. In fact, I am moving my domains off of Namecheap because I don't think Namecheap is very good at handling customer relations, particularly on social media.

(the reply link didn't show up before, so I don't know if you saw my response posted right after this) To be fair, your third edit was only for me. And that was the only comment I was replying to. As I said, we are working to respond to hundreds of comments across dozens of platforms. I certainly respect your distaste in the more rushed responses in order to address all of the deluge, and that is why we were also sim…

[deleted]

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#356

Earlier quoted context omitted.

That's impressive, can you teach me to write like you?

Formula: * Actually apologize in a human way * Show empathy by identifying the impact of what happened to customers (not your impact internally) * State action items that you've created, even if they are just in 'evaluation' state * Indicate that the specific incident in question is being handled outside of this forum * Take responsibility for things even if you shouldn't "have to"

[deleted]

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#357

Earlier quoted context omitted.

Until someone says "I know my dad was born in Minneapolis, what does it say??" and the customer service representative replies "Huh, it looks like the answer is just gibberish...", "Ah! I must have just mashed on my keyboard when I made the account, sorry about that!!", "No problem, your password is now reset to foobar".

While avoidable with training, that brings up its own issue: What if what's being asked of the people taking these calls is outside their pay range?

[deleted]

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#358

Earlier quoted context omitted.

Ah, but the anti-pattern folks have a way around that. Drop-downs for answers . Just got this on United.com: http://imgur.com/84l0CdU

How about 5 random questions, 5 random answers and record all of these in your password manager?

If you have a password manager that successfully tracks the questions, then there's no reason to need to recover the password, as you'll just track the password in the same system.

The catch-22 of these systems is that recovery questions need to be obvious, memorable and unchanging enough to the user that they are useful for recovery, while also being hard for a third party to guess/research. I feel like for the most part those are more often than not mutually exclusive.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#359
post #319
post #300

Earlier quoted context omitted.

I can't reply to the sister comment for some reason, so I'll piggyback on the parent. I always fill these with awkward or absurd questions/anwers that would be amusing if a human operator ever needs to verify them. E.g. Would you like to go on a date with me? What color pants am I wearing? What is the square root of insanity? Obviously you need to store these in a password database in order to remember them, which ki…

I've just started filling them with randomly generated strings that my password manager helpfully creates for me. Though, apparently my bank uses those answers for phone verification also, which makes answering questions like "What's your Significant Other's nickname?" awkward when the answer is "F9-#g7a2<qj"

I do the same, but Correct Horse Battery Staple them.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#360
post #78
post #59

Earlier quoted context omitted.

Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. What do you use to tell whether a chat session is a genuine user or someone successfully using a social engineering attack against your chat operatives? If the answer is "nothing" then you can't know if this is an isolated event or how many of your chat sessions go without a glitch.

There are identification methods requested via chat. Matt invited you to try it. Go for it.

We don't need to try. A hacker already did and was successful.
Post reply on HN