Live data from Hacker News

My website was stolen by a hacker and I got it back

ramshackleglam.com

101–110 of 159 posts

Re: My website was stolen by a hacker and I got it back

#101
post #65

Isn't escrow.com supposed to prevent payments from being stopped after the domain is released? Obviously, in this case it's justified, but for regular customers, you don't want escrow releasing a domain and then the buyer stops payment.

The buyer can't stop the payment as the wire is already complete and money in escrow.com's account. Escrow.com had to stop the payment and in this case they did so because there was a request from law enforcement.

Yes, I'm pretty sure this is where the FBI comes in. So the solution to this is: you agree to buy back your stolen property using an escrow service, then the FBI tells the escrow service not to release the money to a thief. Eventually you get your money back.

Re: My website was stolen by a hacker and I got it back

#102
It is not reassuring to see the level of compromise, the cost of disclosure, and the abuse of antiquated protocols rising faster than the institutions that depend on them can respond. In particular there was a lot of resistance early on to using credit cards on the Internet, now it is nearly compulsory, and yet many of the fears that banks and others raised in the early days of e-commerce are coming to pass.

I have to believe there are some seriously rich criminals out there. What do they expect to do with their ill gotten gains?

Re: My website was stolen by a hacker and I got it back

#103
post #75

Earlier quoted context omitted.

This was several years ago; what's done is done. I moved all my domains to another provider shortly afterwards. I'm not giving you another chance to screw me.

You publicly complained about their customer service. They have offered to right the wrong. You have a poor sense of fairness if you are willing to make a public claim and then aren't willing to address the issue when the company calls you out on it.

Oh, the stupidity, it burns. What sort of righting do you think they could do, several years past the fact? Gandi refused to respond to their web form for a period of about four weeks or more; they let my domain expire and be deleted (if I recall, the only problem was that my credit card expiration date needed to be updated in their system and the charge processed). Besides the immediate hassle and serious annoyance of having an uncontactable company ignore their support form, it ended up costing me a few hundred dollars to buy the domain back from a domain speculator who snatched it up.

What price should I put on that? What price is it worth to Gandi? Are they going to offer me a year's free domain registration with them? That offer has negative value to me; I wouldn't take it unless paid a lot of money to do so. Are they going to offer me a pile of money (no they aren't, it's not worth it to them). So what exactly are they going to offer here to right the wrong?

The point here - which the top of this thread made, but maybe it wasn't explicit enough for you - is that services such as domain registration can easily have effects disproportionate to the cost of providing them. If all of Google's domains were deleted tomorrow, the cost to Google would easily exceed ($10 x number_of_domains). So a poor service experience can easily do more damage than the sum total of all revenue ever received from a particular customer. Thus the commenter looking for companies which try hard to provide good service. Gandi.net is not such a company, in my experience. (Hint: companies which provide good service have email addresses and phone numbers to contact them.) That's my only comment.

Re: My website was stolen by a hacker and I got it back

#104
post #93
post #92

Earlier quoted context omitted.

Modern password crackers are pulling all of wikipedia and youtube for seed words. If your words are in either of those, don't expect the password to stand to a dedicated attacker

There are 1160290625000000000000000 combinations of 5 words with a dictionary of 65000 words. That's not brute-forceable. If you take existing phrases it's another story, but random words works well.

not sure what your calculation is, but permutations is what you should have calculated.

Re: My website was stolen by a hacker and I got it back

#105

> 1. Have a really, really good password, and change it often. Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. http://xkcd.com/936/ But really, I'm a bit puzzled by her 5 "recommendations". Turn off your devices…

The xkcd-style passwords may be less vulnerable to a brute-force attack, but they are more vulnerable to a dictionary attack.

There are (very) roughly 2^17 words in the dictionary, so if you pick 4 there are 2^68 possibilities, or 2.95e20.

There are 94 printable characters on a US keyboard. This means that an 11-character "hard to remember" password has over 16 times as many (~2^72, 5.06e21) combinations as a four-word xkcd style password.

But again, we are comparing two different types of attacks. I don't even know how feasible a 4-word dictionary attack is, or whether it's actually used "in the wild". Still interesting to think about.

Re: My website was stolen by a hacker and I got it back

#106
post #75

Earlier quoted context omitted.

You publicly complained about their customer service. They have offered to right the wrong. You have a poor sense of fairness if you are willing to make a public claim and then aren't willing to address the issue when the company calls you out on it.

Oh, the stupidity, it burns. What sort of righting do you think they could do, several years past the fact? Gandi refused to respond to their web form for a period of about four weeks or more; they let my domain expire and be deleted (if I recall, the only problem was that my credit card expiration date needed to be updated in their system and the charge processed). Besides the immediate hassle and serious annoyance…

just to drive a point home about "calling out stupidity". Your follow up statement is the equivalent of stating "I'll never ever ever use a Windows product because several years ago I use Windows M.E. and it was so bad and they wouldn't fix anything so they can't possibly have fixed any of the issues I may or may not have actually experienced".

It really irks me when people use this sort of logic. I can't say what their support was like several years ago, but I have heard nothing but fantastic things about their support and service offerings over the last 2-3 years, and not by the general web user, but by us "nerd elites". So dude, chill the Eff out and don't be such a hard ass against something that happened admittedly several years ago.

Oh, and you call out "what could they possibly provide me after so many years", well you have a direct response from a customer support person who has offered the ability to "make it right". You do not know what they would be willing/capable of doing until you ask. So get off your high horse and just ask. They might surprise you...

/rant

Re: My website was stolen by a hacker and I got it back

#108
post #80
post #62

Earlier quoted context omitted.

I (Anthony from the story) negotiated the price with the seller to $3,500. I had Jordan wire that to escrow.com while we waited for the domain, db and files to be transferred. We made this decision because nobody was helping (hosts/law enforcement) and with this action the worst case scenario became paying $3,500 for the site (assuming the seller didn't back out). After this the FBI took the case and they were involv…

I sent you an email to your inbox mentioned in your user profile. Someone tried to sell me that website as well and I did some research about him (got his skype, his email, and even his address ).

Thanks for reaching out - just sent you an email back.

Re: My website was stolen by a hacker and I got it back

#109

Earlier quoted context omitted.

No, GoDaddy was never in doubt: "No one at either company questioned my statement (supported by written proof) that the website belonged to me. No one doubted that it had been transferred without my authority". So GoDaddy's refusal to help was ridiculous. At the very least, they could have frozen control of the site for a day or two while investigating.

By ICANN policy domains can only be moved once every 60 days. How did you want them to go about freezing the site? ICANN has a dispute resolution policy in place.

They could have disabled access to it by the thief.

The 60 day policy does not apply to cases where it is "being transferred back to the original Registrar in cases where both Registrars so agree ..." http://www.icann.org/en/resources/registrars/transfers/polic...

And given that both registrars acknowledged that she was the real owner, I'd expect the transfer (to the thief) would not be counted as a legitimate one within that period.

Re: My website was stolen by a hacker and I got it back

#110

Earlier quoted context omitted.

Oh, the stupidity, it burns. What sort of righting do you think they could do, several years past the fact? Gandi refused to respond to their web form for a period of about four weeks or more; they let my domain expire and be deleted (if I recall, the only problem was that my credit card expiration date needed to be updated in their system and the charge processed). Besides the immediate hassle and serious annoyance…

just to drive a point home about "calling out stupidity". Your follow up statement is the equivalent of stating "I'll never ever ever use a Windows product because several years ago I use Windows M.E. and it was so bad and they wouldn't fix anything so they can't possibly have fixed any of the issues I may or may not have actually experienced". It really irks me when people use this sort of logic. I can't say what th…

Maybe I'm stupid, but I agree wit the parent - if a company fails me, I won't go back to them no matter how much they promise to have cleaned up their act.

It's not that I don't believe companies can fix their problems; it's that I believe in feedback and the one form of feedback companies cannot ignore is revenue. It's Darwinian - if a company screws too many customers, they die.

So I haven't used Windows since Microsoft's deeply unethical attacks on OpenDocument; I moved all my US domains from GoDaddy to NameCheap after the elephants broke that camel's back; and Domain Central have all my Aussie domains after NetRegistry de-registered a heavily used domain name in very dubious circumstances.

Post reply on HN