Earlier quoted context omitted.
It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…
I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.
Namecheap live chat social engineering leads to loss of 2 VPS
371–380 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#372Earlier quoted context omitted.
Magic Online simulates paper Magic. You buy packs to get cards, each card is its own individual digital object which can be traded and sold, card sets go out of print or have limited runs, and rare promos are released. It even has its own digital currency, "tickets", which are reasonably easily converted to cash. Magic Online accounts can be worth tens of thousands of dollars. And at least back when I played, if your…
> Magic Online accounts can be worth tens of thousands of dollars. It might cost 10k+ dollars to make a behemoth account, but I don't think they are worth that much. It's basically fake internet points, I can gain these for free in this very comment.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#373Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…
Overblown/fake apology is not very informative - it's hard to say what exactly can you trust in it.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#374Earlier quoted context omitted.
> This isn't a problem for banks, why is it a problem for tech companies? Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies. Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech…
Banks don't try that hard. One of my bank is happy to resend me a password by snail mail with an account ID reset by phone. Also, rechecking the ID of a user can be as simple as asking for a new token payment by the same credit card as used by the account. It's not infailable, the CC can be compromised as well, but it should be way better than what we have now.
This is excellent security, as long as they're not sending it to an address you provided over the phone when you requested a reset.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#375Earlier quoted context omitted.
Tell me one registrar where you can be sure that this will not happen and I will move my domains today. I wouldn't even care if I have to pay 100$ per year for a domain.
MarkMonitor perhaps? Google and Facebook both use MarkMonitor as the registrar for their primary domains. Might be more than $100 per domain though.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#376Re: Namecheap live chat social engineering leads to loss of 2 VPS
#377Moved my domains off Namecheap because I could find a better deal elsewhere, but man I'm glad I don't have anything there now.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#378Earlier quoted context omitted.
No, OP didn't have 2FA enabled on their namecheap account. It was namecheap's fault for improper handling of the social engineering attack but OP could have protected themselves by having 2FA
The article pretty clearly states 2FA was enabled for the Namecheap account in question. In fact, that is sort of the whole point of the article.
https://news.ycombinator.com/item?id=11480221
You should not be able to overcome 2FA with social engineering wtf!
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#379Earlier quoted context omitted.
The answer to "I don't know my password and I don't know my security question/answer" is, "Sorry, for security reasons we can't help you access this account, you'll need to create a new account." This isn't a problem for banks, why is it a problem for tech companies?
> This isn't a problem for banks, why is it a problem for tech companies? Banks have the option of you physically going into the branch and identifying yourself with relevant legally backed forms of ID. That would not really work for most online companies. Other methods which involve sending in copies of ID and/or letters signed by appropriate notaries would fail due to human engineering too because your average tech…
E.g. namecheap.com generates verification ticket item requiring valid identification and SSN that Bank of America then uses to verify your identity for $30, and vouched for the identity. Meanwhile Goldman Sachs generates a verification ticket requiring much more strenuous authentication, and the bank charges $200 for (with increased insurance, etc), which satisfies the much higher validation standard the Goldman Sachs requires to authenticate you for your ritrement account with over $X in it, etc.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#380Earlier quoted context omitted.
We do something similar at Silent Circle. In your recovery options, there's a page with a high-entropy secret key and a QR code that you can print out to use if you ever forget your password. There's also a checkbox that says "don't ever recover this account" (i.e. the "I have a password database on Dropbox") checkbox. Checking that box actually disables password resets on the admin interface, so your account is pret…
OT question about Silent Circle: I was just looking at your website, and I noticed that you cannot ship to PO Boxes. Is this a security feature (eg, no government knowledge of the recipient) or a logistics issue (eg, FedEx/UPS can't deliver to PO Boxes). I would imagine it is pretty hard to get service for your SIM card without revealing your identity to degree.