As someone who runs an online game we find that a huge percentage of our users arrive pre-compromised. Vast quantities of people wander around from site to site using the same email/password combo that has been compromised a long time ago. We do a GeoIP check now and send an email with an unlock code any time someone logs in from a different city than last time. This reduced the account compromise problem significant…
As someone who plays online games, I get really, really annoyed when I'm forced to create a password to log in. ALL non-secure online sites that need to identify users should allow for Google or Facebook authentication, or I will never try to access the game from my phone or tablet. I refuse to use the same password everywhere, but that means I have a password vault on my computer . If I need to create a password and…
Urgent security warning that may affect all internet users
31–40 of 120 posts
Re: Urgent security warning that may affect all internet users
#32Earlier quoted context omitted.
Excellent, thanks! I have been using 2FA on NameCheap since you added the feature, but it's one of the more annoying implementations -- compare to Google's 2FA setup, for example. There I have to jump through the hoop of getting an SMS once a month (and verify my password a bit more frequently). For NameCheap, it's every single time I log in, which translates to every single time I need to do or check something in my…
We're rolling out Google Authenticator support sometime in the fall. I know SMS can be a pain sometime but we definitely recommend having it enabled, regardless.
Re: Urgent security warning that may affect all internet users
#33As someone who runs an online game we find that a huge percentage of our users arrive pre-compromised. Vast quantities of people wander around from site to site using the same email/password combo that has been compromised a long time ago. We do a GeoIP check now and send an email with an unlock code any time someone logs in from a different city than last time. This reduced the account compromise problem significant…
As someone who plays online games, I get really, really annoyed when I'm forced to create a password to log in. ALL non-secure online sites that need to identify users should allow for Google or Facebook authentication, or I will never try to access the game from my phone or tablet. I refuse to use the same password everywhere, but that means I have a password vault on my computer . If I need to create a password and…
There are two sides to this - some prefer convenience and are happy to give up some control. Others do not want to depend on a third party and want to have control themselves.
Re: Urgent security warning that may affect all internet users
#34Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.
Teddy, I'm a Namecheap user (over 30 domains and a bunch of SSLs) and what really concerns me is that I find out about this security issue via hacker news, instead of being sent an email. This is not how you communicate with customers when these types of security issues arise.
Re: Urgent security warning that may affect all internet users
#35Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.
If I set up 2FA, only my device can log in. If I become unavailable for some reason, none of my team members can access the account. The only way to do this is for all team members to do the 2FA setup at the same time, which I believe will seed the generator so that they will all produce the same sequence of tokens. But that's just unacceptable. It's like renting an office and only getting a single key.
I find it amazing that in this day and age, most providers still conflate the concepts of "login" and "account". I log into an account; that login is a set of credentials giving me access, but one account obviously must support multiple logins.
Without a clean separation, you turn employees into single points of failure. Shared account credentials is a potential security risk. And it makes it harder to lock out employees who leave the company once given access. And of course, it makes auditing harder because you just have the IP.
Most providers make this mistake: Among DNS providers, I use Gandi, EasyDNS and iWantMyName, all set up like this. Cloud-oriented providers like Digital Ocean and Mailgun, same problem. AWS does the right thing.
Re: Urgent security warning that may affect all internet users
#36"We'd love to tell you more, but that would compromise our position of compromising positions, so stay compromised but if ur compromised don't do anything important unless you know, you have to or be safe while you do it by not being too secure but being unsecure enough, you know?"
Re: Urgent security warning that may affect all internet users
#37Earlier quoted context omitted.
We're rolling out Google Authenticator support sometime in the fall. I know SMS can be a pain sometime but we definitely recommend having it enabled, regardless.
If you simply sent the SMS as soon as someone enters their login credentials instead of requiring another button to be pressed, it would make your system a bit less annoying.
Re: Urgent security warning that may affect all internet users
#38Earlier quoted context omitted.
The original should be available without issue. Can you please let me know what happens when you try to access it? What ISP are you using? Thanks, Tamar from Namecheap
Your server is not handling the load.
Re: Urgent security warning that may affect all internet users
#39Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.
OT, but why is that providers like Namecheap implement 2FA but not organizational team support? If I set up 2FA, only my device can log in. If I become unavailable for some reason, none of my team members can access the account. The only way to do this is for all team members to do the 2FA setup at the same time, which I believe will seed the generator so that they will all produce the same sequence of tokens. But th…
It's certainly something we are aware of and multiple logins are planned.
We are using Authy as two-factor authentication service provider and they allow you to use multiple devices: http://blog.authy.com/multi-device
Re: Urgent security warning that may affect all internet users
#40Earlier quoted context omitted.
What you're saying is factually incorrect. A hacker group has accumulated thousands (millions?) of email+password pairs. Anyone who uses the same password on all sites could be compromised, even if their password is 16 characters and random (i.e., immune to dictionary attacks).
Tim is right. The group has actually acquired ~1.2 billion passwords, which is a obviously a widespread beach.