Live data from Hacker News

My website was stolen by a hacker and I got it back

ramshackleglam.com

111–120 of 159 posts

Re: My website was stolen by a hacker and I got it back

#111

> 1. Have a really, really good password, and change it often. Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. http://xkcd.com/936/ But really, I'm a bit puzzled by her 5 "recommendations". Turn off your devices…

The xkcd-style passwords may be less vulnerable to a brute-force attack, but they are more vulnerable to a dictionary attack. There are (very) roughly 2^17 words in the dictionary, so if you pick 4 there are 2^68 possibilities, or 2.95e20. There are 94 printable characters on a US keyboard. This means that an 11-character "hard to remember" password has over 16 times as many (~2^72, 5.06e21) combinations as a four-wo…

The issue with "random" passwords is trying to remember them. XKCD-style isn't perfect, but it is loads better than "Password91" and "Dragon" style passwords which are what most people actually use.

Re: My website was stolen by a hacker and I got it back

#112
post #9
post #2

I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…

Namecheap offers two-factor-authentication.

Thanks, good to know.

Re: My website was stolen by a hacker and I got it back

#113
post #2

I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…

I use EasyDNS. Here's why: http://blog.easydns.org/2014/01/29/welcome-to-easydns-press-...

Re: My website was stolen by a hacker and I got it back

#114
post #2

I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…

I would recommend Melbourne IT or Namecheap for what you are looking for. I would recommend you take advantage of WHOIS protection, two factor authentication, locking your domain at the registrar level (not just with Namecheap for example, but with the actual registrar), using strong passwords, etc.

The company can only do so much, so make sure you do everything you can do as well to make your domains as secure as possible.

Re: My website was stolen by a hacker and I got it back

#115
post #18
post #2

I am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as…

I use gandi.net never had any serious issues with them and since their located in France (yes i intentionally avoided American companies) all this suing problem may not apply to them or at least it would be a lot more difficult. One thing is certain though most people i know have had issues with GoDaddy and avoid it like the plague.

Gandi now has offices in the USA, so they are effectively an American company as far as being subject to the US legal system and extraconstitutional orders from agencies and such. You won't get any privacy protection or immunity from illegal orders from Gandi.

Re: My website was stolen by a hacker and I got it back

#118

I can't understand why people still use GoDaddy. They lose domains to hackers every week, you can just call them and they are more than happy to change contact information or email address for you. Freakin' amazing.

I once called a registrar (that I've never heard of before or since) to inform them that a domain they registered was missing WHOIS data, they asked me what I wanted to put in for the WHOIS data. I facepalmed. While I wanted the domain, I wasn't going to steal it.

Re: My website was stolen by a hacker and I got it back

#119
This has a lot of good information in it and I put a lot of time into it, but I do realize it is hard to read since Hacker News doesn't start things on new lines. If someone can tell me how to do that if it is possible that would be great. If not here it is on Pastebin - http://pastebin.com/MspKq8sz.

Here is what I recommend for website security (this is a lot of advice and is not perfect - if you want me to write this up in a detailed blog post and cover more things let me know)... I also provided my contact information at the bottom if you have any questions or need any help settings this up.

Domain Registrar:

1. Melbourne IT - https://www.melbourneit.com.au/ 2. Namecheap - https://www.namecheap.com/ 3. Gandi - https://www.gandi.net/

- Enable WHOIS protection - Enable domain locking - if you want more details on how to set this up let me know - Enable email notifications and make sure you keep your account information up to date - Log in from a computer using a VPN (I use and recommend proXPN - https://proxpn.com/) which encrypts your connection

DNS

1. Any of the domain registrars mentioned above 2. CloudFlare - https://www.cloudflare.com/ (offers performance benefits as well) Their DDOS protection, DNS, and performance benefits are why I use and recommend them. They are not very good in terms of their WAF or website security and that is why I use and recommend Sucuri as well. 3. DNS Made Easy - http://www.dnsmadeeasy.com/

- Follow advice from passwords section - Delete unnecessary DNS records - Enable DNSSEC if possible

Email Hosting

1. I recommend that you use Google Apps for Business - https://www.google.com/enterprise/apps/business/.

- Follow advice from passwords section - Take advantage of the security Google offers

Passwords

1. Create strong passwords using a password generator. I use GRC's Password Generator by Steve Gibson. - https://www.grc.com/passwords.htm 2. Store your passwords in a password manager such as LastPass. - https://lastpass.com/ 3. With LastPass use a strong master password, limit login attempts to your country and the ones you travel to frequently, use two factor authentication, don't use a password reminder, don't write down your master password - only memorize it and don't ever share it, change your master password at least slightly every 3 months, and disable logins from the TOR network. 4. Use the same password only once (Don't use the same password on multiple sites). 5. Don't store your passwords in the browser or save them, so you are automatically logged in. 6. Make sure your password is at least 15+ characters (I use 50+ characters) and it contains lowercase letters, uppercase letters, numbers, and special characters. 7. If a site requires a secret question, make sure the answer to that question no one else would know or make it a password or phrase that you would remember. 8. Use the browser add-on HTTPS Everywhere and use Mozilla Firefox or Google Chrome as your browser. 9. Try to not share your passwords - I would like to say never share your passwords, but I know that is not possible :). If you have to share your passwords, do so using LastPass, change the password after they are done, make sure they haven't done anything that looks malicious, have a clear plan of what they need to do, and ask them how long it will take them.

Website Security

1. Backup your site - I recommend and use Sucuri Backups - http://sucuri.net/services/website-backups (it is $5 a month per website) 2. Use monitoring, alerting, and a removal service - I recommend and use Sucuri - http://sucuri.net/signup

It is $89.99 per year for one website. The service includes 3 main areas which are monitoring (http://sucuri.net/services/website-scan-malware-detection), alerting (http://sucuri.net/services/alerting), and removal (http://sucuri.net/services/malware-removal). You can use any of those links for further details.

3. Use a WAF - I recommend and use Sucuri CloudProxy - http://cloudproxy.sucuri.net/signup ($9.99 a month for the most basic plan - the two other plans are $19.98 and $69.93 per month)

4. There could be a lot more in this area, but that should do a pretty good job for you. If you are using a CMS such as WordPress, Joomla, or Drupal you have quite a bit more you can do in this area.

Hosting

1. It honestly depends on your needs, so I am not going to recommend anyone specifically. If you want help with this or anything you can find my contact information at the bottom.

Network Security

1. Use WPA2 for the encryption protocol 2. Make your network name random 3. Make your password to connect to your network very strong 4. Change the default login credentials to login to your network to a secure username and password. 5. Disable Wi-Fi Protected Setup (WPS) 6. Configure OpenDNS at the router level - http://www.opendns.com/ 7. Follow the passwords section for your passwords

Computer Security

1. Use a antivirus program (Antivirus for Mac by Sophos for MAC computers and Microsoft Security Essentials or Avast for Windows) 2. Use an anti-malware program (Malwarebytes Antimalware and Malwarebytes Anti-Exploit for Windows) 3. Use a firewall (Windows Firewall or TinyWall for Windows) 4. Keep your operating system updated 5. Keep your programs updated (Secunia PSI or FileHippo Update Checker for Windows and AppFresh for MAC) 6. Remove Java and Quicktime if you don't need them 7. Replace Adobe Reader with Foxit Reader or Sumatra PDF 8. Make sure you keep Adobe Flash Player up to date 9. Uninstall programs that you don't need or don't use 10. Only download things from trusted sources (the browser extension Web of Trust would help with this) 11. For your browser make sure you are using Google Chrome or Mozilla Firefox. For Google Chrome and Mozilla Firefox, I recommend that you use Adblock Plus, Disconnect, and HTTPS Everywhere). If you want to be very secure and are somewhat technical, I recommend that you also use NoScript for Mozilla Firefox and NotScripts for Google Chrome.

If you have any questions you can email me at [redacted].

Post reply on HN