Earlier quoted context omitted.
https://www.gandi.net/ does as well and has been pretty great in my (somewhat limited) experience.
http://www.namecheap.com offers their own 2fa service, as well.
Hackers Stole My Website
81–90 of 144 posts
Re: Hackers Stole My Website
#82> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…
You're a complete idiot
Re: Hackers Stole My Website
#83Earlier quoted context omitted.
Depends on your underlying email service provider. If it is gmail, for example, then they provide one-time use passwords for exactly his purpose. What this means is if you enable 2FA for your gmail account, you can generate a one-time password to authorize any client which does not support a 2FA auth flow. This password is then destroyed by both parties. If you run your own email server, I think you are at low risk o…
> This password is then destroyed by both parties. I don't quite understand this. Won't the email client need the need the password every time to auth with IMAP?
Re: Hackers Stole My Website
#84Her password advice is literally the opposite of the classic https://xkcd.com/936/ .
Here is some info from a quick search: https://security.stackexchange.com/questions/6095/xkcd-936-s...
Re: Hackers Stole My Website
#85It sounds like the core of this hack was an attack on her email (followed by password resets for registrar, etc.). So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own. Stealing email passwords is easy. So easy. No matter ho…
It also happened to me to loose a smartphone without PIN, and I never thought it would happen and I kept postponing that simple step.
Maybe this time I should listen.
Re: Hackers Stole My Website
#86Re: Hackers Stole My Website
#87Earlier quoted context omitted.
> 3. Turn off your computer and personal devices when they’re not in use. Even Bruce Schneier recommends you do that[1]. The idea is that if your machine is a spambot and you don't know it, there are fewer windows of time where your machine can be blasting the Internet with spam. Or if there's some network-based exploit, you're not vulnerable while your device is off. 1. https://www.schneier.com/blog/archives/2004/12…
> Turn off the computer when you're not using it, especially if you have an "always on" Internet connection. How old is that article? Sounds like this is from the days back when dial-up was still popular. I guess there may be some marginal increase in security by turning off your computer like this, but I don't think it's the kind of thing most users should be worried about. > if your machine is a spambot and you don…
Re: Hackers Stole My Website
#88> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…
See I was all for 2FA, but there were a number of high profile heists that actually used 2FA to gain control first of your mobile number, then email, then anything else they valued. Since mobile operators care even less then hosting companies, I am not sure having 2FA with sms code to be a good security practice. I do have yubikey keyfob but sites that are supporting it are very few unfortunately. Gmail being one, wh…
Real 2FA uses a token generator device or an app like google authenticator which does the same thing. This is a real "something you possess" as it can't be compromized without getting access to the device.
Re: Hackers Stole My Website
#89Looks like it got a good number of shares and good velocity so makes sense to keep milking it for what it's worth i suppose.
Btw, GoDaddy's response: http://news.softpedia.com/news/GoDaddy-Defends-Itself-in-Ram...
Re: Hackers Stole My Website
#90Earlier quoted context omitted.
Yeah so about that 2FA. I have a local email client, which uses IMAP and hence cannot do 2FA. What now? I've always thought this is rather a gaping hole. Of course i use app-specific passwords which presumably won't allow access to webmail or changing the account password, but still, if someone got my app password for IMAP, they could still siphon out password reset emails for all my other services. What do the rest…
If you simply don't use webmail, you're about 99% less likely to accidentally type your password into a website that happens to look like your webmail login page (which doesn't exist).