Live data from Hacker News

My website was stolen by a hacker and I got it back

ramshackleglam.com

21–30 of 159 posts

Re: My website was stolen by a hacker and I got it back

#21
post #16

Earlier quoted context omitted.

Got a list? It seems like every day GoDaddy is leaking domains. I've been using Hover a lot, but I'm not sure what their exposure is like.

Namecheap does 2FA.

Curious why this is being down voted? Is it because namecheap does not offer 2FA? Seems to simply be answering the question above.

Re: My website was stolen by a hacker and I got it back

#22
post #6

Earlier quoted context omitted.

My guess is that the author's home computer was compromised or their gmail password was guessed. They mentioned that they ignored a warning that someone logged into their account remotely.

And the how to avoid it section mentions using a different computer for banking than your kids use to click around the web...

At home I have a Chromebox machine that I only use for online banking and no other purpose.

My other machines are used for the usual consumer Web activities, including Web site administration. I'm wondering if perhaps I should modify my approach to do the admin only from the Chromebox... which brings up the classic tradeoff of security vs convenience.

Re: My website was stolen by a hacker and I got it back

#23
post #11
post #2

I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…

Moniker claims that they have never lost a domain. I've got several domains (over 50) registered with them and never had a problem in almost 8 years. Many of them belonged to high traffic sites that might be desirable to thieves. I also have many with Name cheap right now and haven't had a problem them either.

I use them as well and have had no issues; however just because two of us have had no issues, it's not much of a data point.

Re: My website was stolen by a hacker and I got it back

#24
post #21
post #16

Earlier quoted context omitted.

Namecheap does 2FA.

Curious why this is being down voted? Is it because namecheap does not offer 2FA? Seems to simply be answering the question above.

For me, their 2FA is essentially unusable. It uses a UK SMS gateway (no Authy / Google Authenticator support) and out of the 20 or so times I've tried to set it up, only once has the code actually come through to my phone. I've had an open support ticket for 6 months, 3 months since the last reply.

Re: My website was stolen by a hacker and I got it back

#26
I never trust shared hosts provided by a registrar. I have my own blog software running on AWS and I am the programmer and only user. The fewer people involved is better security but that's not generally possible for the average person. At least I can't lose both the domain and the content.

Re: My website was stolen by a hacker and I got it back

#28
post #10

So apart from the 4 pretty much "how not to happen", try using a host that supports 2FA.

Got a list? It seems like every day GoDaddy is leaking domains. I've been using Hover a lot, but I'm not sure what their exposure is like.

GoDaddy supports 2FA. http://support.godaddy.com/help/article/7502/enabling-twoste...

edit Can only receive the text code on US-based numbers, but you can get one of those from something like Google Voice for free.

Re: My website was stolen by a hacker and I got it back

#29

I feel for her but I do need to point out that some of the suggestions she makes for making it easier to get her stolen domain back would also make it easier for bad actors to cause mischief in the first place. But GoDaddy sucks. True dat.

GoDaddy has two-step authentication. If you make any type of money off of a website or other account, you should use two-factor authentication. Facebook, email, and godaddy would be a decent start. A similar incident occurred when the man lost his $50k? twitter account because he didn't use two-factor anywhere.

Re: My website was stolen by a hacker and I got it back

#30
Is there any domain register that offers 2 factor authentication to make changes that are detrimental to a site?

I have Network Solutions, KVC Hosting, and have tried 1and1, but all of them...from a security standpoint...are lackadaisical when it comes to security.

Network solutions WANTS their clients to bundle userid's into 1 account...that makes it easy.

KVC, I emailed them to update my domain contact info, then I transferred one of my domains out with that new email.

I never did any test with 1and1...but then again the 2 above (with kvc and netsol) weren't even tests.

Another security breach involving GoDaddy(1)?

(1): Naoki lost his twitter (https://medium.com/cyber-security/24eb09e026dd)

Post reply on HN