Live data from Hacker News

Urgent security warning that may affect all internet users

community.namecheap.com

61–70 of 120 posts

Re: Urgent security warning that may affect all internet users

#61
post #44

Earlier quoted context omitted.

OT, but why is that providers like Namecheap implement 2FA but not organizational team support? If I set up 2FA, only my device can log in. If I become unavailable for some reason, none of my team members can access the account. The only way to do this is for all team members to do the 2FA setup at the same time, which I believe will seed the generator so that they will all produce the same sequence of tokens. But th…

We actually have a little-known feature, which allows you to grant domain modification rights to other Namecheap users. https://www.namecheap.com/support/knowledgebase/article.aspx... You can also add other phone numbers to your 2FA preferences, although I can understand if that's annoying for your colleagues if everyone is getting an SMS on every login.

(Namecheap user here. Just set up 2FA.)

Could you have people adding multiple phone numbers to the 2FA process and then allow someone to set their preferred, whitelisted number for the SMS?

I need to grant access to a second account to purchase services on my behalf. Does your solution of granting domain modification access work in that case or are we going to have to deal with the SMSes?

Also, is there a plan to upgrade the internal tools that don't much the newer public design? It's pretty jarring.

Re: Urgent security warning that may affect all internet users

#62
post #40
post #29

Earlier quoted context omitted.

Tim is right. The group has actually acquired ~1.2 billion passwords, which is a obviously a widespread beach.

Does anyone know a list of the sites they got this data from?

There's been stories for a while of massive malware infections sniffing usernames and passwords of infected users. Simply because there's little to give away that such an activity is going on (ie, if you were spamming or mining bitcoin there would be a real-world impact shown immediately) it's extremely hard to confirm or deny if this is happening and at what scale. In my mind it doesn't seem unlikely that would be happening though. Combined with large websites like LinkedIn being compromised, you're looking at a very, very big problem.

Re: Urgent security warning that may affect all internet users

#63

As someone who runs an online game we find that a huge percentage of our users arrive pre-compromised. Vast quantities of people wander around from site to site using the same email/password combo that has been compromised a long time ago. We do a GeoIP check now and send an email with an unlock code any time someone logs in from a different city than last time. This reduced the account compromise problem significant…

As someone who plays online games, I get really, really annoyed when I'm forced to create a password to log in. ALL non-secure online sites that need to identify users should allow for Google or Facebook authentication, or I will never try to access the game from my phone or tablet. I refuse to use the same password everywhere, but that means I have a password vault on my computer . If I need to create a password and…

Find a better vault solution. Keepassx is available for every platform out there, and when combined with a file sync solution like dropbox, box, etc can be trivially used on iOS or android.

Re: Urgent security warning that may affect all internet users

#64
post #61
post #44

Earlier quoted context omitted.

We actually have a little-known feature, which allows you to grant domain modification rights to other Namecheap users. https://www.namecheap.com/support/knowledgebase/article.aspx... You can also add other phone numbers to your 2FA preferences, although I can understand if that's annoying for your colleagues if everyone is getting an SMS on every login.

(Namecheap user here. Just set up 2FA.) Could you have people adding multiple phone numbers to the 2FA process and then allow someone to set their preferred, whitelisted number for the SMS? I need to grant access to a second account to purchase services on my behalf. Does your solution of granting domain modification access work in that case or are we going to have to deal with the SMSes? Also, is there a plan to upg…

The new account panel / internal tools are in development and will roll out soon.

With the existing 2FA, you can set a primary or disable a number without deleting it. This could work for what you're describing.

Re: Urgent security warning that may affect all internet users

#65
post #12

Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.

two factor authentication via SMS is the biggest waste of time. It's not true two factor authentication as you need to depend on the network and protocol between namecheap and my phone. Not to mention the code is probably not originating from a namecheap server but from a third party service.

TOTP is a standard, it's great, there are open source implementations, and it's easy to integrate. Google even has that pam module. Use it.

Re: Urgent security warning that may affect all internet users

#66
post #51

The question for us, as technologists, is what are we doing about this? 2FA is nice, but not the end all, be all. OAuth has largely failed to gain any reasonable traction. Using Facebook login means Facebook gets to track me as I move around the web. Our users reuse passwords, primarily due to the proliferation of dozens or often hundreds of online accounts that a single individual has. We can't expect people to use…

All the security measures usually presented (including here) are completely unrealistic - no one can use different, complex passwords on every site we log into, and then change them every month!

The only way to do this would be to use a password manager in an Saas mode... and if it gets cracked then you're completely doomed and lose all access to all services.

People probably assume that the time saved by not caring about security is greater than the time they will lose if (when) they're attacked, and they may be right.

Re: Urgent security warning that may affect all internet users

#67
The way I have organised is to have 5 varying levels. This limits the volume of passwords I have to recall whilst maintaining variety. While there is still opportunity for cross-use if one is hacked it does create breakage points from areas more likely to be hacked and avoids a single point of failure. It's structured something like this;

1) Random sign-ups.

2) Slightly personal information e.g. Hackernews

3) Personal or slightly financial: e.g. mail accounts

4) Financial: e.g. Banking/Share trading

5) Work accounts

I've been wondering if I should expand this to have the same as above but bring in a component of the URL into the password to create variance for all but keeping it easy to remember. Does that seem a good method or do people have better systems?

Re: Urgent security warning that may affect all internet users

#68

The way I have organised is to have 5 varying levels. This limits the volume of passwords I have to recall whilst maintaining variety. While there is still opportunity for cross-use if one is hacked it does create breakage points from areas more likely to be hacked and avoids a single point of failure. It's structured something like this; 1) Random sign-ups. 2) Slightly personal information e.g. Hackernews 3) Persona…

Why not just use:

https://lastpass.com/

https://agilebits.com/onepassword

http://keepass.info/

Re: Urgent security warning that may affect all internet users

#69
I've seen a huge uptick in spam email the last few days, and although I have no indication that I've been hacked, I feel as though I should probably fear for the worst and aggressively change all my passwords from their current kindergarten security levels. Is there a widely accessible, secure, multi platform, free/libre password manager that is recommendable as easy to use? I reuse passwords because its easy to remember, and I'm hoping there is something out there that is light years better than those I found the last time I tried (2007).

Re: Urgent security warning that may affect all internet users

#70
This is a good reminder that we all need to encourage our friends, family, and colleagues to not use the same password everywhere. Almost all of them currently do.

The best solution I've found thus far is getting them to use 1Password or the like. They still only have to remember 1 password, and the browser extensions make it trivial to log in different places. If necessary, buy them the software.

Post reply on HN