Live data from Hacker News

My website was stolen by a hacker and I got it back

ramshackleglam.com

131–140 of 159 posts

Re: My website was stolen by a hacker and I got it back

#131

> 1. Have a really, really good password, and change it often. Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. http://xkcd.com/936/ But really, I'm a bit puzzled by her 5 "recommendations". Turn off your devices…

If you read the comments she is no computer security expert. And she accepted the comments of others that passwords that "look like nonsense" are not necessarily best.

My guess is "turning off" relates to not leaving a device that is logged in and open available for someone at school/work/... to stop by and mess with.

She ends up advising 2 factor authentication for email (an old email that was compromised is he guess on the cause of the problem). It is a good article. For advice it might be nice to put a TLDR of: "use 2 factor authentication."

Re: My website was stolen by a hacker and I got it back

#132

This has a lot of good information in it and I put a lot of time into it, but I do realize it is hard to read since Hacker News doesn't start things on new lines. If someone can tell me how to do that if it is possible that would be great. If not here it is on Pastebin - http://pastebin.com/MspKq8sz . Here is what I recommend for website security (this is a lot of advice and is not perfect - if you want me to write t…

I would definitely make this a blog post, or even an infographic. What I would really like to see/ is all this as a step by step FAQ/how to.

If you tell me how to attribute you properly, I will do this. I'm about to embark on a year long experiment in a lifestyle app development business. The first step I will be taking is to buy a new PC, laptop, smart phones (android & iOS) tablets (again, android and iOS), set-up a blog and marketing website and get some form of cloud provider (I currently have AWS, but I'm looking at different options.

So I will be setting everything up from factory new hardware and brand new accounts (new email, hosting providers etc) putting all the info you've listed into a repeatable process would be beneficial to anyone else who wants to try the same experiment I'm heading out on.

Re: My website was stolen by a hacker and I got it back

#133
post #104
post #93

Earlier quoted context omitted.

There are 1160290625000000000000000 combinations of 5 words with a dictionary of 65000 words. That's not brute-forceable. If you take existing phrases it's another story, but random words works well.

not sure what your calculation is, but permutations is what you should have calculated.

His calculation was (65000 Choose 5) * 5!. His premise required a combination then a permutation.

Re: My website was stolen by a hacker and I got it back

#134
post #18

Earlier quoted context omitted.

I use gandi.net never had any serious issues with them and since their located in France (yes i intentionally avoided American companies) all this suing problem may not apply to them or at least it would be a lot more difficult. One thing is certain though most people i know have had issues with GoDaddy and avoid it like the plague.

Gandi now has offices in the USA, so they are effectively an American company as far as being subject to the US legal system and extraconstitutional orders from agencies and such. You won't get any privacy protection or immunity from illegal orders from Gandi.

Oh well off to find another good company for may gray area domains then.

Too bad I liked them why are all of them going to America.

I don't want my stuff subject to American laws.

Re: My website was stolen by a hacker and I got it back

#135

Earlier quoted context omitted.

@jellicle, that doesn't sound like us. Can I look into your case further? If we messed up, we'll make it right.

@soulshake - check out legal #4827870. We were, as we would say in Australia, bloody lucky.

This is me nodding in greeting and letting the legal team do their thing.

Re: My website was stolen by a hacker and I got it back

#136

This has a lot of good information in it and I put a lot of time into it, but I do realize it is hard to read since Hacker News doesn't start things on new lines. If someone can tell me how to do that if it is possible that would be great. If not here it is on Pastebin - http://pastebin.com/MspKq8sz . Here is what I recommend for website security (this is a lot of advice and is not perfect - if you want me to write t…

This is really good advice. Some additional things that come to mind regarding domains: - enable 2-factor authentication/IP-based login restriction, - disable password reset via email, - provide valid registrant data, in case you ever have to prove your identity - for the extra cautious, contact the provider and ask them to add a note to your file to be extra wary of any requests.

Hey, I'm with Gandi and only after this thread did I realise you offered 2FA. I would have enabled much sooner had a i known it was available.

I know you guys don't often send out emails (and I really appreciate that), but perhaps a mail shot letting people know it's an option would be worthwhile. For security stuff I'm happy to receive unsolicited emails

Re: My website was stolen by a hacker and I got it back

#137
post #59
post #41

I don't see how much she paid to get it back. A civil suit filing with a demand for a temporary restraining order and preliminary injunction could be filed in a few hours and since godaddy and hostmonster are US companies, they would have had to comply. She'd have her domain back in a matter of hours for maybe a couple grand.

She didn't pay anything. She stopped/cancelled the wire transfer

This was the most interesting (unique) thing about the whole ordeal.

I did not realize that wire transfers can be cancelled after the receiver has already had the funds placed in the account(else the thief would not have released the domain).

Re: My website was stolen by a hacker and I got it back

#138

Earlier quoted context omitted.

just to drive a point home about "calling out stupidity". Your follow up statement is the equivalent of stating "I'll never ever ever use a Windows product because several years ago I use Windows M.E. and it was so bad and they wouldn't fix anything so they can't possibly have fixed any of the issues I may or may not have actually experienced". It really irks me when people use this sort of logic. I can't say what th…

Maybe I'm stupid, but I agree wit the parent - if a company fails me, I won't go back to them no matter how much they promise to have cleaned up their act. It's not that I don't believe companies can fix their problems; it's that I believe in feedback and the one form of feedback companies cannot ignore is revenue. It's Darwinian - if a company screws too many customers, they die. So I haven't used Windows since Micr…

I do worse (I'm bad, I know). A large Telco in Australia once charged me $800 in phone calls several years ago before the TIO and ACCC mandated SMS notifications when accounts go over a certain amount.

I explained the situation to them, that I was a good customer, I'd just had my first child, could they shave off some of the bill as a goodwill gesture. Even $40. They didn't budge an inch.

Over the next 6 years I've made a complaint about every single fault, bill error, outage and mistake they have made. Each time I've demanded compensation. I have a number of accounts with this Telco.

I estimate that I've recovered $700 worth of compensation. I'll keep going till I get the entire amount back, then probably go on for another $100. Then I'll stop. And probably find alternative services and dump them completely.

Don't piss off your customers.

Re: My website was stolen by a hacker and I got it back

#139
post #18

Earlier quoted context omitted.

I use gandi.net never had any serious issues with them and since their located in France (yes i intentionally avoided American companies) all this suing problem may not apply to them or at least it would be a lot more difficult. One thing is certain though most people i know have had issues with GoDaddy and avoid it like the plague.

Gandi now has offices in the USA, so they are effectively an American company as far as being subject to the US legal system and extraconstitutional orders from agencies and such. You won't get any privacy protection or immunity from illegal orders from Gandi.

I think you mean extraterritorial jurisdiction. Extraconsitutional orders would be... against the U.S. Consitution and illegal :-)

Re: My website was stolen by a hacker and I got it back

#140
post #137
post #59

Earlier quoted context omitted.

She didn't pay anything. She stopped/cancelled the wire transfer

This was the most interesting (unique) thing about the whole ordeal. I did not realize that wire transfers can be cancelled after the receiver has already had the funds placed in the account(else the thief would not have released the domain).

It's an escrow service, not a wiretransfer company.

The bit that I don't get is that escrow.com (the one party that didn't actually do anything wrong here) now has acted in a way which they probably should not have done, from their point of view the transaction actually is legit (buyer has control of the domain name, so funds should be released).

If Escrow.com can't be trusted to release the funds when the recipient has the goods then what point is there to use them in the first place?

Post reply on HN