Live data from Hacker News

My website was stolen by a hacker and I got it back

ramshackleglam.com

41–50 of 159 posts

Re: My website was stolen by a hacker and I got it back

#41
I don't see how much she paid to get it back. A civil suit filing with a demand for a temporary restraining order and preliminary injunction could be filed in a few hours and since godaddy and hostmonster are US companies, they would have had to comply. She'd have her domain back in a matter of hours for maybe a couple grand.

Re: My website was stolen by a hacker and I got it back

#42

Earlier quoted context omitted.

GoDaddy could seize the domain until the dispute is settled. If everyone recognized she was the previous owner, that should be enough to cause an investigation into the transfer. Not saying a claim from anyone should cause a seizure, but the legitimate previous owner should be able to dispute it for a time period. Domains are stolen all the damn time.

I worked in webhosting for nearly a decade so I'm quite familiar with the volume of fraud and stolen domains. But to play the devils advocate how would you feel if somebody claimed a domain you own was stolen just to freeze your account and waste your time. You'd be furious at GoDaddy for freezing your account over a fictitious claim.

They only need to freeze the account if the domain was moved very recently.

Re: My website was stolen by a hacker and I got it back

#43

Is there any domain register that offers 2 factor authentication to make changes that are detrimental to a site? I have Network Solutions, KVC Hosting, and have tried 1and1, but all of them...from a security standpoint...are lackadaisical when it comes to security. Network solutions WANTS their clients to bundle userid's into 1 account...that makes it easy. KVC, I emailed them to update my domain contact info, then I…

Hover has 2fa as well.

Re: My website was stolen by a hacker and I got it back

#44
post #40

Earlier quoted context omitted.

I agree with you with the "bad advice," opinion. There's no glamour or valor with how she got her domain back. In reality...it appears from her article that she really just paid to get it back. So I guess her suggestion is to have $30k stashed to make up for lack of security. From what I read...she's still out money, even though she did get her domain back.

She retained the money. And then I called the wire transfer company and placed a stop on the payment. It's unclear to me how this works. At first, it seems as though she and Anthony pursued this action independently, which would seem quite risky: risk of the apparently-fraudulent stop payment not being processed in time, or at all, resulting in the loss of 30k; risk of legal action from the seller, however seemingly…

I don’t have my money back yet, but the man who stole my site from me doesn’t have it, either, and won’t be getting it, ever.

I don't think she got her money back, it may be held, but the method in which she got her domain back involved money transfer. The FBI, was really just sprinkled in the article. I understand the shock in how they handled the case immediately taking statements, but the resolution she had involved her money to get her domain back.

Re: My website was stolen by a hacker and I got it back

#45
post #35
post #2

I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…

http://gandi.net - I have never had my domain stolen but in general Gandi.net are good people and they care about their customers.

I lost a domain because Gandi refused to do anything about it; although I was well within the renewal period and tried to contact them many times Gandi refused to process any sort of renewal until it expired and was deleted by their system.

Gandi ONLY accepts support requests through their web form (no email, no phone), and generally ignores those or provides nonsense answers several days later.

As long as you never ever need any sort of support, Gandi is fine.

Re: My website was stolen by a hacker and I got it back

#46
post #24
post #21

Earlier quoted context omitted.

Curious why this is being down voted? Is it because namecheap does not offer 2FA? Seems to simply be answering the question above.

For me, their 2FA is essentially unusable. It uses a UK SMS gateway (no Authy / Google Authenticator support) and out of the 20 or so times I've tried to set it up, only once has the code actually come through to my phone. I've had an open support ticket for 6 months, 3 months since the last reply.

I just set it up (US cell phone) and it took less than 5 minutes end to end. Have you tried lately?

Re: My website was stolen by a hacker and I got it back

#47

Is there any domain register that offers 2 factor authentication to make changes that are detrimental to a site? I have Network Solutions, KVC Hosting, and have tried 1and1, but all of them...from a security standpoint...are lackadaisical when it comes to security. Network solutions WANTS their clients to bundle userid's into 1 account...that makes it easy. KVC, I emailed them to update my domain contact info, then I…

Gandi, mentioned several other times in this thread, also supports 2FA. https://wiki.gandi.net/en/contacts/login/2-factor-activation

You can also create a second account there and delegate limited rights to it for making changes. The odds of losing both accounts are remote.

Re: My website was stolen by a hacker and I got it back

#48
post #2

I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…

I use NameSilo

2 Factor Authentication and other security policies

Re: My website was stolen by a hacker and I got it back

#50

Isn't escrow.com supposed to prevent payments from being stopped after the domain is released? Obviously, in this case it's justified, but for regular customers, you don't want escrow releasing a domain and then the buyer stops payment.

I believe the thief demanded payment first, outside of escrow. Which seems odd considering they actually did return the name. Maybe they were afraid Escrow.com would determine the domain was stolen and simply return it to its owner?
Post reply on HN