Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

411–420 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#411
I agree with most people that calling to reset password should be a service that can be entirely disabled, or at least require 2FA. But think about this. All of this could have been avoided if they had the simple policy of calling you back. The only thing you would have to do as a user, would be to keep your number up-to-date.

Of course this also requires that you should never be able to add a number using the phone though, but this makes sense, since they can just say: "To do that you just have to sign in and click on..."

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#412

Earlier quoted context omitted.

Use a random but user friendly value #$%&+@ is going to be hard to type or speak, just say their nickname is "the frozen one", same entropy, easier to handle

>> What's your Significant Other's nickname? > Use a random but user friendly value > "the frozen one" I imagine that may make make your significant other who was previously friendly, markedly less so, if they see your "friendly value". But that may have been your point, as it may be quite a bit easier to remember. :)

My point is to use a term that is easier to type and speak rather than just a sequence of symbols. Or just modify the "right" answer in a quirky way.

But yeah, what you said might happen.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#413

Earlier quoted context omitted.

Formula: * Actually apologize in a human way * Show empathy by identifying the impact of what happened to customers (not your impact internally) * State action items that you've created, even if they are just in 'evaluation' state * Indicate that the specific incident in question is being handled outside of this forum * Take responsibility for things even if you shouldn't "have to"

For a "what not to do", have a look how (the CEO of?) FTDI responded after they were caught intentionally "bricking" chips that were detected as counterfeit by the Windows drivers.

Last I heard, these tainted drivers from FTDI weasled their way through WHQL and into Windows Update...

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#414

Earlier quoted context omitted.

Eh.. I don't really agree that this is victim blaming. But then again, I find that I disagree with most uses of the phrase "victim blaming". Pointing out that somebody did something sub-optimal, while still acknowledging the mis-deeds, mistakes, etc. of other parties, is not "victim blaming" in my book. It's just pointing out the truth. I mean, if you go for a stroll through the roughest neighborhood in town, unarmed…

>I mean, if you go for a stroll through the roughest neighborhood in town, unarmed, by yourself, at night, and you get mugged, is it wrong to point out that going for that walk was stupid? Yes, this is the textbook example of victim blaming. Placing any amount of blame on the person who is the victim in this situation is saying that they don't have the right to walk down a street and not be mugged. I am admittedly no…

Victim blaming is used to vindicate a perpetrator of a wrong doing. That isn't being done here, nor in the mugging example.

You can say a victim is stupid without giving any vindication to the person in the wrong.

Namecheap are saying "be responsible for your backups, but yeah we screwed up on our security policy" - They are seperate things, that the victim here has conflated, but are seperate problems (in regards to namecheaps offering).

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#415
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

This is something we struggled with at Exoscale, I took the time to do a small write-up of how we approach reset requests here: https://www.exoscale.ch/syslog/2016/04/13/i-lost-my-2-factor...

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#416

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…

This should become a thing. I want to make a Tumblr now.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#417

Earlier quoted context omitted.

This seems very easy to bypass.

Very easy? I'd say "possible" at best . And now you've got access to a battle.net account. Took a heck of a lot more work than asking someone for username/pass in a live chat, and what you gained access to is worth a heck of a lot less. Plus Blizzard actually does keep backups and records and will be able to fix the situation for the account owner. I'd be surprised if ever a Blizzard account was compromised by someon…

>Very easy? I'd say "possible" at best.

I think you are a little confused here. There's no way for Blizzard to authenticate those pictures, you can take literally anyones passport and just swap the name on it.

> Took a heck of a lot more work than asking someone for username/pass in a live chat

This might be true in a world without photoshop, but that's not the world we live in.

>I'd be surprised if ever a Blizzard account was compromised by someone sending in a false picture.

In my personal experience, they'll very rarely insist upon receiving those photos. My battle.net account isn't even under a real name and despite that I've had the authenticator added and removed several times.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#418

Earlier quoted context omitted.

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

Story time: I have been trying for 3 years to figure out what I wanted to hint at with "If it's not this one then it's the other one" as a secret question. I thought I was a clever boy not choosing the usual predetermined "what's your mother's name ?".

perhaps it's one of the two "throwaway" passwords you were using at the time?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#419

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

Maybe ... Eiffel65? :-)

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#420
post #214

Earlier quoted context omitted.

Huh. I'm going to say thanks to HN, and this comment chain, for bringing this to light. That seems kind of insane.

Maybe it's time for Amazon to decouple AWS accounts from Amazon shopping accounts.

I think you can do that yourself, although it probably means that you need two credit cards.
Post reply on HN