Live data from Hacker News

Urgent security warning that may affect all internet users

community.namecheap.com

31–40 of 120 posts

Re: Urgent security warning that may affect all internet users

#31

As someone who runs an online game we find that a huge percentage of our users arrive pre-compromised. Vast quantities of people wander around from site to site using the same email/password combo that has been compromised a long time ago. We do a GeoIP check now and send an email with an unlock code any time someone logs in from a different city than last time. This reduced the account compromise problem significant…

As someone who plays online games, I get really, really annoyed when I'm forced to create a password to log in. ALL non-secure online sites that need to identify users should allow for Google or Facebook authentication, or I will never try to access the game from my phone or tablet. I refuse to use the same password everywhere, but that means I have a password vault on my computer . If I need to create a password and…

I (and probably the vast majority of the world) have a single separate password for sites I couldn't care less about being compromised or really serve no purpose for anyone to compromise.

Re: Urgent security warning that may affect all internet users

#32
post #28
post #26

Earlier quoted context omitted.

Excellent, thanks! I have been using 2FA on NameCheap since you added the feature, but it's one of the more annoying implementations -- compare to Google's 2FA setup, for example. There I have to jump through the hoop of getting an SMS once a month (and verify my password a bit more frequently). For NameCheap, it's every single time I log in, which translates to every single time I need to do or check something in my…

We're rolling out Google Authenticator support sometime in the fall. I know SMS can be a pain sometime but we definitely recommend having it enabled, regardless.

If you simply sent the SMS as soon as someone enters their login credentials instead of requiring another button to be pressed, it would make your system a bit less annoying.

Re: Urgent security warning that may affect all internet users

#33

As someone who runs an online game we find that a huge percentage of our users arrive pre-compromised. Vast quantities of people wander around from site to site using the same email/password combo that has been compromised a long time ago. We do a GeoIP check now and send an email with an unlock code any time someone logs in from a different city than last time. This reduced the account compromise problem significant…

As someone who plays online games, I get really, really annoyed when I'm forced to create a password to log in. ALL non-secure online sites that need to identify users should allow for Google or Facebook authentication, or I will never try to access the game from my phone or tablet. I refuse to use the same password everywhere, but that means I have a password vault on my computer . If I need to create a password and…

Some of us use password managers like 1Password and get really, really annoyed when we're forced to use Google or Facebook to log in.

There are two sides to this - some prefer convenience and are happy to give up some control. Others do not want to depend on a third party and want to have control themselves.

Re: Urgent security warning that may affect all internet users

#34
post #21
post #12

Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.

Teddy, I'm a Namecheap user (over 30 domains and a bunch of SSLs) and what really concerns me is that I find out about this security issue via hacker news, instead of being sent an email. This is not how you communicate with customers when these types of security issues arise.

You should have no such expectation. This isn't a namecheap-specific security issue - they are reporting their perspective of a global security issue.

Re: Urgent security warning that may affect all internet users

#35
post #12

Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.

OT, but why is that providers like Namecheap implement 2FA but not organizational team support?

If I set up 2FA, only my device can log in. If I become unavailable for some reason, none of my team members can access the account. The only way to do this is for all team members to do the 2FA setup at the same time, which I believe will seed the generator so that they will all produce the same sequence of tokens. But that's just unacceptable. It's like renting an office and only getting a single key.

I find it amazing that in this day and age, most providers still conflate the concepts of "login" and "account". I log into an account; that login is a set of credentials giving me access, but one account obviously must support multiple logins.

Without a clean separation, you turn employees into single points of failure. Shared account credentials is a potential security risk. And it makes it harder to lock out employees who leave the company once given access. And of course, it makes auditing harder because you just have the IP.

Most providers make this mistake: Among DNS providers, I use Gandi, EasyDNS and iWantMyName, all set up like this. Cloud-oriented providers like Digital Ocean and Mailgun, same problem. AWS does the right thing.

Re: Urgent security warning that may affect all internet users

#36
Wow, what a completely vague and useless warning. It should just say "be secure, but not too secure, you know just don't buy Russian stuff, would probably be a good start. Change your password, but make sure you use no special characters and keep it under 16 symbols in length, use only approved SSL cert authorities and don't look behind that curtain!!!"

"We'd love to tell you more, but that would compromise our position of compromising positions, so stay compromised but if ur compromised don't do anything important unless you know, you have to or be safe while you do it by not being too secure but being unsecure enough, you know?"

Re: Urgent security warning that may affect all internet users

#37
post #32
post #28

Earlier quoted context omitted.

We're rolling out Google Authenticator support sometime in the fall. I know SMS can be a pain sometime but we definitely recommend having it enabled, regardless.

If you simply sent the SMS as soon as someone enters their login credentials instead of requiring another button to be pressed, it would make your system a bit less annoying.

That's good feedback. We have the extra step there now because some people actually prefer getting a call rather than SMS to retrieve their code.

Re: Urgent security warning that may affect all internet users

#38
post #20
post #8

Earlier quoted context omitted.

The original should be available without issue. Can you please let me know what happens when you try to access it? What ISP are you using? Thanks, Tamar from Namecheap

Your server is not handling the load.

Thanks. Getting a mix of results here - server issues (should be fine), and 404s - but the page wasn't deleted. Not sure what it is but we'll keep an eye on it. Thanks!

Re: Urgent security warning that may affect all internet users

#39
post #12

Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.

OT, but why is that providers like Namecheap implement 2FA but not organizational team support? If I set up 2FA, only my device can log in. If I become unavailable for some reason, none of my team members can access the account. The only way to do this is for all team members to do the 2FA setup at the same time, which I believe will seed the generator so that they will all produce the same sequence of tokens. But th…

Timo from iwantmyname here.

It's certainly something we are aware of and multiple logins are planned.

We are using Authy as two-factor authentication service provider and they allow you to use multiple devices: http://blog.authy.com/multi-device

Re: Urgent security warning that may affect all internet users

#40
post #29

Earlier quoted context omitted.

What you're saying is factually incorrect. A hacker group has accumulated thousands (millions?) of email+password pairs. Anyone who uses the same password on all sites could be compromised, even if their password is 16 characters and random (i.e., immune to dictionary attacks).

Tim is right. The group has actually acquired ~1.2 billion passwords, which is a obviously a widespread beach.

Does anyone know a list of the sites they got this data from?
Post reply on HN