Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

371–380 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#371

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

I might have the answer for you- the security question on some of my unimportant shared accounts where a question was required is "what color is my VGA cable?"

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#372
post #363

Earlier quoted context omitted.

Magic Online simulates paper Magic. You buy packs to get cards, each card is its own individual digital object which can be traded and sold, card sets go out of print or have limited runs, and rare promos are released. It even has its own digital currency, "tickets", which are reasonably easily converted to cash. Magic Online accounts can be worth tens of thousands of dollars. And at least back when I played, if your…

> Magic Online accounts can be worth tens of thousands of dollars. It might cost 10k+ dollars to make a behemoth account, but I don't think they are worth that much. It's basically fake internet points, I can gain these for free in this very comment.

No, you can get actual money for them.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#373

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…

I like original matthewdrussell's version more.

Overblown/fake apology is not very informative - it's hard to say what exactly can you trust in it.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#374
post #232

Earlier quoted context omitted.

> This isn't a problem for banks, why is it a problem for tech companies? Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies. Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech…

Banks don't try that hard. One of my bank is happy to resend me a password by snail mail with an account ID reset by phone. Also, rechecking the ID of a user can be as simple as asking for a new token payment by the same credit card as used by the account. It's not infailable, the CC can be compromised as well, but it should be way better than what we have now.

> One of my bank is happy to resend me a password by snail mail with an account ID reset by phone.

This is excellent security, as long as they're not sending it to an address you provided over the phone when you requested a reset.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#375

Earlier quoted context omitted.

Tell me one registrar where you can be sure that this will not happen and I will move my domains today. I wouldn't even care if I have to pay 100$ per year for a domain.

MarkMonitor perhaps? Google and Facebook both use MarkMonitor as the registrar for their primary domains. Might be more than $100 per domain though.

Try tens of thousands.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#376
post #15
post #14

What legal consequences could there be for Namecheap, if any at all?

Why would there be any? Would there be legal consequences to YC if I hacked your email and reset your HN account password?

The hacker wiped the VPSs, and there was no backup.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#377

Moved my domains off Namecheap because I could find a better deal elsewhere, but man I'm glad I don't have anything there now.

I use them for domains, but I wouldn't host there. (nor any other registrar, and if Starbucks started selling burgers, I doubt I'd buy one of those either)

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#378
post #347
post #305

Earlier quoted context omitted.

No, OP didn't have 2FA enabled on their namecheap account. It was namecheap's fault for improper handling of the social engineering attack but OP could have protected themselves by having 2FA

The article pretty clearly states 2FA was enabled for the Namecheap account in question. In fact, that is sort of the whole point of the article.

Oh this comment by CIO led me to think 2FA wasn't...

https://news.ycombinator.com/item?id=11480221

You should not be able to overcome 2FA with social engineering wtf!

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#379
post #147

Earlier quoted context omitted.

The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?

> This isn't a problem for banks, why is it a problem for tech companies? Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies. Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech…

Actually, this could be an interesting and lucrative side business for banks, identity verification. You could have varying levels of verification, requiring varying levels of authenticating documentation and numbers of employees to review and vouch that could then be used to provide a certificate of verification for a service.

E.g. namecheap.com generates verification ticket item requiring valid identification and SSN that Bank of America then uses to verify your identity for $30, and vouched for the identity. Meanwhile Goldman Sachs generates a verification ticket requiring much more strenuous authentication, and the bank charges $200 for (with increased insurance, etc), which satisfies the much higher validation standard the Goldman Sachs requires to authenticate you for your ritrement account with over $X in it, etc.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#380
post #125

Earlier quoted context omitted.

We do something similar at Silent Circle. In your recovery options, there's a page with a high-entropy secret key and a QR code that you can print out to use if you ever forget your password. There's also a checkbox that says "don't ever recover this account" (i.e. the "I have a password database on Dropbox") checkbox. Checking that box actually disables password resets on the admin interface, so your account is pret…

OT question about Silent Circle: I was just looking at your website, and I noticed that you cannot ship to PO Boxes. Is this a security feature (eg, no government knowledge of the recipient) or a logistics issue (eg, FedEx/UPS can't deliver to PO Boxes). I would imagine it is pretty hard to get service for your SIM card without revealing your identity to degree.

I'm not actually sure about that (I assume you're referring to shipping a Blackphone?). The Blackphones are a semi-separate division that I don't have much contact with, unfortunately.
Post reply on HN