Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

421–426 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#421
Whoa. I turned on my 2FA at Linode. Their policy to disable is to require a copy of credit card + government ID so hopefully that's followed... https://www.linode.com/docs/security/linode-manager-security...

Also checked: if you pay for their backup service, nobody can delete the backups, so those backups are even safe if compromised.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#422

Earlier quoted context omitted.

Story time: I have been trying for 3 years to figure out what I wanted to hint at with "If it's not this one then it's the other one" as a secret question. I thought I was a clever boy not choosing the usual predetermined "what's your mother's name ?".

perhaps it's one of the two "throwaway" passwords you were using at the time?

It most certainly is but... it doesn't work. At that time I had some kind of semantic combinations for passwords but it doesn't compute for that website.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#423

Earlier quoted context omitted.

Maybe it's time for Amazon to decouple AWS accounts from Amazon shopping accounts.

I think you can do that yourself, although it probably means that you need two credit cards.

I mean from a system level perspective. The trouble is that they have policies that are optimized for people shopping on a site with a money back guarantee not for hosting critical infrastructure.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#424

Earlier quoted context omitted.

Did you read the article? I ask because one of the problems was a compromised email account.

I did. It doesn't change anything, email is still a way better verification method than ID scans that the company will be unable to authenticate.

unless your email account has been compromised.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#425

Earlier quoted context omitted.

I did. It doesn't change anything, email is still a way better verification method than ID scans that the company will be unable to authenticate.

unless your email account has been compromised.

Even if the email account is compromised it's still stronger proof of identity than ID scans.

An attacker can't just pretend to be able to read your email, such ability is too easy to conclusively prove. To be able to read your email they need to hack you somehow.

But for a fake ID the attacker only needs to throw your name in a PSD and they're good to go.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#426

Earlier quoted context omitted.

My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…

That's impressive, can you teach me to write like you?

Go out right now and get the book "Crucial Conversations". It is BY FAR the best book I've ever read on this kind of thing. It is simultaneously the best relationship book I've ever read and the best business book I've ever read. It goes through the basic principles for handling these situations in an easy to understand way.
Post reply on HN