Live data from Hacker News

My website was stolen by a hacker and I got it back

ramshackleglam.com

121–130 of 159 posts

Re: My website was stolen by a hacker and I got it back

#121
post #34

The most unfortunate part of this story is that the site owner had to use underhanded tactics of her own to regain control of her site. She didn't get her site back by going through formal legal channels, she got it back by using tactics similar to those used by the criminal she was dealing with. Different intent and legal standing, but same methods. It would be interesting to know what would have happened if she had…

That's a more unfortunate part of the story than the registrars' inaction? Or the theft itself? I don't think so.

Re: My website was stolen by a hacker and I got it back

#122
post #74

Earlier quoted context omitted.

This. I want to upvote this comment a hundred times. If there's a dispute with probable cause , temporarily freezing the domain while launching an immediate investigation seems by far the best balance of thwarting domain theft and minimizing fraudulent claims.

By ICANN policy domains can only be moved once every 60 days. Did you want the domain name taken offline?

I'm not very familiar with their policies. Does that apply even in the case of theft? Didn't the article's author recover her domain within a few days?

Re: My website was stolen by a hacker and I got it back

#123
post #75

Earlier quoted context omitted.

You publicly complained about their customer service. They have offered to right the wrong. You have a poor sense of fairness if you are willing to make a public claim and then aren't willing to address the issue when the company calls you out on it.

Oh, the stupidity, it burns. What sort of righting do you think they could do, several years past the fact? Gandi refused to respond to their web form for a period of about four weeks or more; they let my domain expire and be deleted (if I recall, the only problem was that my credit card expiration date needed to be updated in their system and the charge processed). Besides the immediate hassle and serious annoyance…

Besides the immediate hassle and serious annoyance of having an uncontactable company ignore their support form, it ended up costing me a few hundred dollars to buy the domain back from a domain speculator who snatched it up.

I once let a domain expire by accident, but since it was obscure the squatter who snatched it let it lapse after the ~45 day ICANN "trial" period that used to be a boon to evil squatters (AIUI, IIRC). So I just registered it again myself.

Re: My website was stolen by a hacker and I got it back

#124

Simple way to secure your passwords: * 1) Use 1Password to generate and store them * 2) Use DropBox or similar to share your encrypted vault between your devices * 3) Secure your shard vault with a strong computer-generated password, and keep it written down somewhere I wonder why strong password management isn't built into operating systems, thus educating everybody and making them ubiquitous. What am I missing? Whe…

OS X/iOS have cross device password syncing using keychain these days.

Re: My website was stolen by a hacker and I got it back

#125

> 1. Have a really, really good password, and change it often. Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. http://xkcd.com/936/ But really, I'm a bit puzzled by her 5 "recommendations". Turn off your devices…

The xkcd-style passwords may be less vulnerable to a brute-force attack, but they are more vulnerable to a dictionary attack. There are (very) roughly 2^17 words in the dictionary, so if you pick 4 there are 2^68 possibilities, or 2.95e20. There are 94 printable characters on a US keyboard. This means that an 11-character "hard to remember" password has over 16 times as many (~2^72, 5.06e21) combinations as a four-wo…

The issue with the numbers you give is that nobody really has an 11 character password compatible with it.

The reality is that people have trouble remembering 11 truly random and unrelated things, so they try to simplify and group things - e.g. by taking a base word and changing the spelling, or adding numbers on. This is what leads to the easy to brute force passwords; the cracking techniques now cater for the most popular variations.

So again, while you may be right on paper, you can't compare a 4 word passphrase with a true 11 character random password; they are on completely different scales of difficulty to remember. If you're interested, take a look at how the xkcd comic constructs the difficulty of the two passwords, it is fairly realistic. For what it's worth, it considers only "common" words (top 1000 to 2000 most popular) from the dictionary, and the passphrase wins out even so. Throw in a word from another language, would be my suggestion.

Re: My website was stolen by a hacker and I got it back

#126

Earlier quoted context omitted.

I lost a domain because Gandi refused to do anything about it; although I was well within the renewal period and tried to contact them many times Gandi refused to process any sort of renewal until it expired and was deleted by their system. Gandi ONLY accepts support requests through their web form (no email, no phone), and generally ignores those or provides nonsense answers several days later. As long as you never…

@jellicle, that doesn't sound like us. Can I look into your case further? If we messed up, we'll make it right.

@soulshake - check out legal #4827870. We were, as we would say in Australia, bloody lucky.

Re: My website was stolen by a hacker and I got it back

#127

This has a lot of good information in it and I put a lot of time into it, but I do realize it is hard to read since Hacker News doesn't start things on new lines. If someone can tell me how to do that if it is possible that would be great. If not here it is on Pastebin - http://pastebin.com/MspKq8sz . Here is what I recommend for website security (this is a lot of advice and is not perfect - if you want me to write t…

This is really good advice. Some additional things that come to mind regarding domains: - enable 2-factor authentication/IP-based login restriction, - disable password reset via email, - provide valid registrant data, in case you ever have to prove your identity - for the extra cautious, contact the provider and ask them to add a note to your file to be extra wary of any requests.

Re: My website was stolen by a hacker and I got it back

#128
post #56

Earlier quoted context omitted.

Yeah, they are in charge of Hostgator India. They have no reach into the US based brands. Source: I work at one of the aforementioned brands.

Unless you're in Burlington you probably aren't familiar with the brands you don't work at. Most of them have support provided through GlowTouch. Even HostGator USA has GlowTouch Indians doing transfers and helping in ticket queues.

Source? You just replied to someone who works there and who specifically said "They have no reach into the US based brands.".

Re: My website was stolen by a hacker and I got it back

#129

Earlier quoted context omitted.

Oh, the stupidity, it burns. What sort of righting do you think they could do, several years past the fact? Gandi refused to respond to their web form for a period of about four weeks or more; they let my domain expire and be deleted (if I recall, the only problem was that my credit card expiration date needed to be updated in their system and the charge processed). Besides the immediate hassle and serious annoyance…

just to drive a point home about "calling out stupidity". Your follow up statement is the equivalent of stating "I'll never ever ever use a Windows product because several years ago I use Windows M.E. and it was so bad and they wouldn't fix anything so they can't possibly have fixed any of the issues I may or may not have actually experienced". It really irks me when people use this sort of logic. I can't say what th…

From experience it's generally not worth the risk. Perhaps they got it right but 90% don't. It's like playing the lottery.

Re: My website was stolen by a hacker and I got it back

#130

Is there any domain register that offers 2 factor authentication to make changes that are detrimental to a site? I have Network Solutions, KVC Hosting, and have tried 1and1, but all of them...from a security standpoint...are lackadaisical when it comes to security. Network solutions WANTS their clients to bundle userid's into 1 account...that makes it easy. KVC, I emailed them to update my domain contact info, then I…

Even Dreamhost has two factor authentication.
Post reply on HN