Live data from Hacker News

My website was stolen by a hacker and I got it back

ramshackleglam.com

91–100 of 159 posts

Re: My website was stolen by a hacker and I got it back

#91

Earlier quoted context omitted.

Look at it from the GoDaddy's point of view: This woman is claiming she has rights to a domain in one of their customer's accounts. As far as they know it was legitimately transferred in by one of their paying customers. Her real issue rests with HostMonster and the ICANN dispute resolution system.

No, GoDaddy was never in doubt: "No one at either company questioned my statement (supported by written proof) that the website belonged to me. No one doubted that it had been transferred without my authority". So GoDaddy's refusal to help was ridiculous. At the very least, they could have frozen control of the site for a day or two while investigating.

By ICANN policy domains can only be moved once every 60 days. How did you want them to go about freezing the site? ICANN has a dispute resolution policy in place.

Re: My website was stolen by a hacker and I got it back

#92

> 1. Have a really, really good password, and change it often. Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. http://xkcd.com/936/ But really, I'm a bit puzzled by her 5 "recommendations". Turn off your devices…

To follow up, I will say that my favorite way to create a password is to use sayings from two or more of your favorite books or other sources. So, if you like Harry Potter and Enders Game, what are the phrases that come to mind? Harry Potter - expelliarmus Enders Game - win all the future fights Now you have a great password: "winallthefuturefightsexpelliarmus" Nice and long (33 chars), with some made up stuff. Maybe…

Modern password crackers are pulling all of wikipedia and youtube for seed words. If your words are in either of those, don't expect the password to stand to a dedicated attacker

Re: My website was stolen by a hacker and I got it back

#93
post #92

Earlier quoted context omitted.

To follow up, I will say that my favorite way to create a password is to use sayings from two or more of your favorite books or other sources. So, if you like Harry Potter and Enders Game, what are the phrases that come to mind? Harry Potter - expelliarmus Enders Game - win all the future fights Now you have a great password: "winallthefuturefightsexpelliarmus" Nice and long (33 chars), with some made up stuff. Maybe…

Modern password crackers are pulling all of wikipedia and youtube for seed words. If your words are in either of those, don't expect the password to stand to a dedicated attacker

There are 1160290625000000000000000 combinations of 5 words with a dictionary of 65000 words. That's not brute-forceable. If you take existing phrases it's another story, but random words works well.

Re: My website was stolen by a hacker and I got it back

#94

> 1. Have a really, really good password, and change it often. Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. http://xkcd.com/936/ But really, I'm a bit puzzled by her 5 "recommendations". Turn off your devices…

Two factor authentication should be one of the top recommendations. I'm not sure about the domain sites, but she mentioned a hacked Youtube account and it's possible to set up 2FA for that.

Re: My website was stolen by a hacker and I got it back

#95
Simple way to secure your passwords:

* 1) Use 1Password to generate and store them

* 2) Use DropBox or similar to share your encrypted vault between your devices

* 3) Secure your shard vault with a strong computer-generated password, and keep it written down somewhere

I wonder why strong password management isn't built into operating systems, thus educating everybody and making them ubiquitous. What am I missing? Where is MacPass? WinPass?

The advice on the blog and this comment thread isn't any good, but there's really no good advice besides use a password manager.

Re: My website was stolen by a hacker and I got it back

#96
> 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking.

Or don't let your kids use your work computer when you have very important privileges at stake? I would definitely keep all of this in a very encrypted environment that isn't accessible by my kids or anyone else.

Re: My website was stolen by a hacker and I got it back

#97
post #2

I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…

I use DNSimple.com. They've been great and are quick at support.

Re: My website was stolen by a hacker and I got it back

#98
-Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense

I think this is a bad advice. You only need long password that are not feasible for a brute force attack and not trivial (personal data). If you have a password you can't remember you are going to write it somewhere and that can be a security issue

Re: My website was stolen by a hacker and I got it back

#99
I wonder if her or her husband ever accessed any of their accounts using their cell phones. I've seen tons of stories lately about Samsung Galaxy phones being compromised so at this point I just assume that if top of the line phones are pwned, then all cell phones are.

I'm kind of shocked that there have been no class action lawsuits on phone manufacturers. Especially from banks.. just imagine the liability of millions of customers getting keylogged no matter what the bank uses to secure its site (even two factor authentication). It's almost unfathomable.

Someone really should make a one time pad login that doesn't work a second time even if you look over the user's shoulder. For example their password could be their favorite song and the site would ask them to enter the 2nd, 3rd and 4th letters of the 5th, 6th and 7th word respectively or something. Or how about a custom grid of letters printed on the back of the phone they’d look up positions on so it would have to at least be in someone's physical possession. Or how about a dongle in the headphone jack that's hardcoded and can't be hacked, that the user would type rolling codes through. There has to be a better way of doing this!

Re: My website was stolen by a hacker and I got it back

#100

> 1. Have a really, really good password, and change it often. Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. http://xkcd.com/936/ But really, I'm a bit puzzled by her 5 "recommendations". Turn off your devices…

To follow up, I will say that my favorite way to create a password is to use sayings from two or more of your favorite books or other sources. So, if you like Harry Potter and Enders Game, what are the phrases that come to mind? Harry Potter - expelliarmus Enders Game - win all the future fights Now you have a great password: "winallthefuturefightsexpelliarmus" Nice and long (33 chars), with some made up stuff. Maybe…

winallthefuturefightsexpelliarmus

Why not "Win all the future fights expelliarmus"? Passwords that don't accept spaces are pretty rare, and you end up with a longer password 'for free'.

Post reply on HN