> 1. Have a really, really good password, and change it often. Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. http://xkcd.com/936/ But really, I'm a bit puzzled by her 5 "recommendations". Turn off your devices…
The xkcd-style passwords may be less vulnerable to a brute-force attack, but they are more vulnerable to a dictionary attack. There are (very) roughly 2^17 words in the dictionary, so if you pick 4 there are 2^68 possibilities, or 2.95e20. There are 94 printable characters on a US keyboard. This means that an 11-character "hard to remember" password has over 16 times as many (~2^72, 5.06e21) combinations as a four-wo…
My website was stolen by a hacker and I got it back
111–120 of 159 posts
Re: My website was stolen by a hacker and I got it back
#112I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…
Namecheap offers two-factor-authentication.
Re: My website was stolen by a hacker and I got it back
#113I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…
Re: My website was stolen by a hacker and I got it back
#114I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…
The company can only do so much, so make sure you do everything you can do as well to make your domains as secure as possible.
Re: My website was stolen by a hacker and I got it back
#115I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…
I use gandi.net never had any serious issues with them and since their located in France (yes i intentionally avoided American companies) all this suing problem may not apply to them or at least it would be a lot more difficult. One thing is certain though most people i know have had issues with GoDaddy and avoid it like the plague.
Re: My website was stolen by a hacker and I got it back
#116Re: My website was stolen by a hacker and I got it back
#117Re: My website was stolen by a hacker and I got it back
#118I can't understand why people still use GoDaddy. They lose domains to hackers every week, you can just call them and they are more than happy to change contact information or email address for you. Freakin' amazing.
Re: My website was stolen by a hacker and I got it back
#119Here is what I recommend for website security (this is a lot of advice and is not perfect - if you want me to write this up in a detailed blog post and cover more things let me know)... I also provided my contact information at the bottom if you have any questions or need any help settings this up.
Domain Registrar:
1. Melbourne IT - https://www.melbourneit.com.au/ 2. Namecheap - https://www.namecheap.com/ 3. Gandi - https://www.gandi.net/
- Enable WHOIS protection - Enable domain locking - if you want more details on how to set this up let me know - Enable email notifications and make sure you keep your account information up to date - Log in from a computer using a VPN (I use and recommend proXPN - https://proxpn.com/) which encrypts your connection
DNS
1. Any of the domain registrars mentioned above 2. CloudFlare - https://www.cloudflare.com/ (offers performance benefits as well) Their DDOS protection, DNS, and performance benefits are why I use and recommend them. They are not very good in terms of their WAF or website security and that is why I use and recommend Sucuri as well. 3. DNS Made Easy - http://www.dnsmadeeasy.com/
- Follow advice from passwords section - Delete unnecessary DNS records - Enable DNSSEC if possible
Email Hosting
1. I recommend that you use Google Apps for Business - https://www.google.com/enterprise/apps/business/.
- Follow advice from passwords section - Take advantage of the security Google offers
Passwords
1. Create strong passwords using a password generator. I use GRC's Password Generator by Steve Gibson. - https://www.grc.com/passwords.htm 2. Store your passwords in a password manager such as LastPass. - https://lastpass.com/ 3. With LastPass use a strong master password, limit login attempts to your country and the ones you travel to frequently, use two factor authentication, don't use a password reminder, don't write down your master password - only memorize it and don't ever share it, change your master password at least slightly every 3 months, and disable logins from the TOR network. 4. Use the same password only once (Don't use the same password on multiple sites). 5. Don't store your passwords in the browser or save them, so you are automatically logged in. 6. Make sure your password is at least 15+ characters (I use 50+ characters) and it contains lowercase letters, uppercase letters, numbers, and special characters. 7. If a site requires a secret question, make sure the answer to that question no one else would know or make it a password or phrase that you would remember. 8. Use the browser add-on HTTPS Everywhere and use Mozilla Firefox or Google Chrome as your browser. 9. Try to not share your passwords - I would like to say never share your passwords, but I know that is not possible :). If you have to share your passwords, do so using LastPass, change the password after they are done, make sure they haven't done anything that looks malicious, have a clear plan of what they need to do, and ask them how long it will take them.
Website Security
1. Backup your site - I recommend and use Sucuri Backups - http://sucuri.net/services/website-backups (it is $5 a month per website) 2. Use monitoring, alerting, and a removal service - I recommend and use Sucuri - http://sucuri.net/signup
It is $89.99 per year for one website. The service includes 3 main areas which are monitoring (http://sucuri.net/services/website-scan-malware-detection), alerting (http://sucuri.net/services/alerting), and removal (http://sucuri.net/services/malware-removal). You can use any of those links for further details.
3. Use a WAF - I recommend and use Sucuri CloudProxy - http://cloudproxy.sucuri.net/signup ($9.99 a month for the most basic plan - the two other plans are $19.98 and $69.93 per month)
4. There could be a lot more in this area, but that should do a pretty good job for you. If you are using a CMS such as WordPress, Joomla, or Drupal you have quite a bit more you can do in this area.
Hosting
1. It honestly depends on your needs, so I am not going to recommend anyone specifically. If you want help with this or anything you can find my contact information at the bottom.
Network Security
1. Use WPA2 for the encryption protocol 2. Make your network name random 3. Make your password to connect to your network very strong 4. Change the default login credentials to login to your network to a secure username and password. 5. Disable Wi-Fi Protected Setup (WPS) 6. Configure OpenDNS at the router level - http://www.opendns.com/ 7. Follow the passwords section for your passwords
Computer Security
1. Use a antivirus program (Antivirus for Mac by Sophos for MAC computers and Microsoft Security Essentials or Avast for Windows) 2. Use an anti-malware program (Malwarebytes Antimalware and Malwarebytes Anti-Exploit for Windows) 3. Use a firewall (Windows Firewall or TinyWall for Windows) 4. Keep your operating system updated 5. Keep your programs updated (Secunia PSI or FileHippo Update Checker for Windows and AppFresh for MAC) 6. Remove Java and Quicktime if you don't need them 7. Replace Adobe Reader with Foxit Reader or Sumatra PDF 8. Make sure you keep Adobe Flash Player up to date 9. Uninstall programs that you don't need or don't use 10. Only download things from trusted sources (the browser extension Web of Trust would help with this) 11. For your browser make sure you are using Google Chrome or Mozilla Firefox. For Google Chrome and Mozilla Firefox, I recommend that you use Adblock Plus, Disconnect, and HTTPS Everywhere). If you want to be very secure and are somewhat technical, I recommend that you also use NoScript for Mozilla Firefox and NotScripts for Google Chrome.
If you have any questions you can email me at [redacted].