Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

391–400 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#391

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I had a similar thing happen with my Battle.net account. I forgot to transfer over my authenticator backup code when I switched password managers last time. I had to send them a photo of my driver's license next to my face and another one of it next to a physical newspaper with the date on it. This seems like a much better process for recovering accounts that matter.

The way I fix this is to save the images that you get for 2FA and store them offline in a password manager like KeyPass.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#392
post #300

Earlier quoted context omitted.

I'm always amazed at how little thought seems to go into these questions. My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus. One of the questions was "What's your favorite summer activity?" Her answer was, "Swimming." Yeah, that's going to add about one bit of entropy to most people's accounts, you idiots. Another favorite is "middle name of your youngest child…

I can't reply to the sister comment for some reason, so I'll piggyback on the parent. I always fill these with awkward or absurd questions/anwers that would be amusing if a human operator ever needs to verify them. E.g. Would you like to go on a date with me? What color pants am I wearing? What is the square root of insanity? Obviously you need to store these in a password database in order to remember them, which ki…

Error: Security question answer cannot contain special characters: !@#$%^&*()';

Error: Security question answer cannot be more than 10 characters long.

Error: Security question answer must be one word.

Error: Security question answer must be unique.

Error: Security question error. Please try again.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#393
post #297

Since the CIO (and another employee) are here. Why are you not offering support for Google Authenticator? Last time someone asked for it was 2 years ago[1] and still no sign of the feature. Cheap prices are good to have but combining that with more security can only add value. [1]: https://www.namecheap.com/support/knowledgebase/article.aspx...

It's in the works. We're aware of the request.

You should integrate Authy instead.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#394

The comments remind me of the time I tried to get a copy of my credit report from one of the big 3 agencies back in '09. One of the authentication questions was, "What is the name of your mortgage company?" My house had been foreclosed during a divorce 5 years earlier, and of course the mortgage had been sliced and diced about 15 times by different companies during the heyday of mortgage-based derivatives before the…

I finally gave up trying to get a copy from those guys

I had a similar experience. IIRC TransUnion was the problem one. They wanted something like 3 credit card numbers as part of the identification. But I only had two active credit cards. Fortunately I was able to find an old cancelled one in a drawer and they accepted the number!???

The problem is that you're not their customer, you're just an irritant that the federal govt demands that they give "free" information to.

They treat their real customers much better. E.g., go to a used car dealer. Give them your SSN and they'll have your life story in front of them in about 10 seconds. They get good service because they're paying for it.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#395

As someone in the domain registrar industry, are there any features beyond 2FA that you would like to see implemented by registrars? More bluntly, what is it that you think your current registrar is lacking? I read a few comments on Gandi and support of GPG keys. I'm guessing this is what you're referring to: https://wiki.gandi.net/en/gandi/documents

I would like to see something where a postcard is mailed and a phone call, each with half of the code needed for a reset. Postcard should not be sent using a method that supports forwarding so an attacker cannot setup a mail forward. Customer support should not be able to see anything about these accounts except for a reset button. I do expect to be charge a fee for a reset if I need to use it. This would need to be…

a postcard is mailed

If you want them to go thru the trouble of mailing something, at least require it to be a letter. Inside an opaque envelope.

A postcard is the exact opposite of something you want to use to send sensitive information.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#397

I'd give money to a VPS, or what have you, that had a stated policy along the lines of, "here is a recovery key, here is the 2FA setup, here's how you recover your password with those items if you forget. If you call about account recovery and you do not have $REQUIRED_ITEMS, our service reps have been instructed to hang up on you. If you lose access to your account without $REQUIRED_ITEMS, you have lost access to yo…

we have set procedures from which we do not, under any circumstances, deviate

Fair enough. There's a subset of people who want that and would agree to that beforehand.

But, and here's an important "but", do not just display a checkbox and an Agree button. Instead display a sentence something like this:

   I UNDERSTAND THAT I WILL PERMANENTLY LOSE
   ALL ACCESS IF I FORGET MY PASSWORD AND
   MY RECOVERY KEY
In order to agree to the terms, make the customer type out:

   I UNDERSTAND THAT I WILL PERMANENTLY LOSE
   ALL ACCESS IF I FORGET MY PASSWORD AND
   MY RECOVERY KEY
BTW, don't allow "paste" into the reply field, try to enforce actual typing of characters.

After you've done that, if a customer is later locked out, that customer will STILL be mad at you. It will be the providers fault that the customer can't get access. No matter how explicitly the customer agreed to the terms.

That's human nature. I don't care how explicit you make it, you simply can't win this one.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#398
I've been battling with Namecheap for over a month now just to try and get the registrant details updated on a handful of .com.au domains I own. Their "support" is hands down the worst I've ever experienced, and the moment I'm able to move every domain I have away from Namecheap to a registrar that actually gives a shit, I'm going to do just that.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#399
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I would prefer being stuck without being able to login to my server, compared to potentially having customer support allow someone else to access my server.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#400

Earlier quoted context omitted.

Until someone says "I know my dad was born in Minneapolis, what does it say??" and the customer service representative replies "Huh, it looks like the answer is just gibberish...", "Ah! I must have just mashed on my keyboard when I made the account, sorry about that!!", "No problem, your password is now reset to foobar".

While avoidable with training, that brings up its own issue: What if what's being asked of the people taking these calls is outside their pay range?

Then the company's decisions on how much to pay their call centre staff has just opened up a possible vector for attack. Simple as that.
Post reply on HN