Live data from Hacker News

Hackers Stole My Website

medium.com

11–20 of 144 posts

Re: Hackers Stole My Website

#11

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

[deleted]

Re: Hackers Stole My Website

#12

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

SMS is far better than nothing. Your average script kiddie is not going to be able to intercept your SMS messages. If you are specifically targeted by sophisticated attackers, maybe.

Re: Hackers Stole My Website

#13

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

https://www.name.com lets you use Google Authenticator for 2FA.

Re: Hackers Stole My Website

#14
post #9
post #4

>3. Turn off your computer and personal devices when they’re not in use. This article reads like an AOL scare from 1995 directed at my grandma.

And yet many people who were born in 1995 are still using crappy passwords, downloading crappy files from crappy sites with no protection. This stuff may be obvious to us, but it seems we're in a minority.

EDIT: If you're going to downvote me, did you even read the article?

Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash

- - -

But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience?

The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking to stop a wire transfer, hardly a sting) was successful. It's a long-winded rant about HostMonster and GoDaddy being shitty. We already knew these things. If the article was just focused criticism on GoDaddy or clear advice on web security, I wouldn't be so hash. Whatever educational benefits there were in article are lost with the writing.

This has got to be on the front page because of some shilling.

Re: Hackers Stole My Website

#15
And then I called the wire transfer company and placed a stop on the payment.

How do you place a stop on a wire transfer? I thought irreversibility was the whole point of wire transfers.

Re: Hackers Stole My Website

#16
post #13

Earlier quoted context omitted.

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

https://www.name.com lets you use Google Authenticator for 2FA.

https://www.gandi.net/ does as well and has been pretty great in my (somewhat limited) experience.

Re: Hackers Stole My Website

#17
post #12

Earlier quoted context omitted.

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

SMS is far better than nothing. Your average script kiddie is not going to be able to intercept your SMS messages. If you are specifically targeted by sophisticated attackers, maybe.

My biggest gripe with SMS 2FA is that it is prone to locking me out of my accounts on travel, if I suddenly need to log in to something and my phone number isn't the same abroad.

Re: Hackers Stole My Website

#18
post #16
post #13

Earlier quoted context omitted.

https://www.name.com lets you use Google Authenticator for 2FA.

https://www.gandi.net/ does as well and has been pretty great in my (somewhat limited) experience.

http://www.namecheap.com offers their own 2fa service, as well.

Re: Hackers Stole My Website

#19
post #16
post #13

Earlier quoted context omitted.

https://www.name.com lets you use Google Authenticator for 2FA.

https://www.gandi.net/ does as well and has been pretty great in my (somewhat limited) experience.

https://www.dynadot.com offers both Google 2fA and SMS, with a big push toward the Google solution. Dynadot has been a great all-around solution in my experience. Gandi is also excellent.

Re: Hackers Stole My Website

#20
post #15

And then I called the wire transfer company and placed a stop on the payment. How do you place a stop on a wire transfer? I thought irreversibility was the whole point of wire transfers.

I was thrown by this too. If the destination account had the funds deposited, which set the domain transfer process in motion, I don't think a stop payment works.

What I do think works is reporting that the money was involved in fraud and freezing the money in the destination account, subject to the destination banks cooperation with the source bank and FBI.

https://www.quora.com/Can-wire-transfers-be-reversed-in-case...

Post reply on HN