Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
> Established procedure was not followed Why have a procedure if your support doesn't follow it? Even if you have a procedure, everything falls apart when it isn't followed. This is the same as having no procedure at all.
Namecheap live chat social engineering leads to loss of 2 VPS
141–150 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#142Earlier quoted context omitted.
A few ideas: * If they happen to be using authy for 2FA and you have the Authy app on your phone, it will use that instead of sending an SMS. You could also just have it send to Authy's Chrome extension. * Consider setting up a Google Voice number to receive the SMS.
no, no authy option Google voice ok, but given google hasn't updated google voice in like 3 years I expect they'll announce it being discontinued soon. Any other options?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#143Earlier quoted context omitted.
I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…
I don't think it was personal, simply a reminder that it always helps to have good backup procedures in place. Even my managed services have offsite backups. Better be safe than sorry, I always say.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#144I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#145Earlier quoted context omitted.
I am not sure why you would respond to an accusation about victim blaming by reiterating the exact thing that caused the accusation. You might want to reconsider continuing this particular aspect of discussion for PR reasons. It's not an argument you're going to win.
It's not an argument you're going to win. Unless you sign up for a managed service that claims to include backups or whatever, you are responsible for your own backups. What's controversial about that?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#146Re: Namecheap live chat social engineering leads to loss of 2 VPS
#147I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#148Earlier quoted context omitted.
I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…
I don't think it was personal, simply a reminder that it always helps to have good backup procedures in place. Even my managed services have offsite backups. Better be safe than sorry, I always say.
I don't think the best way to respond to a public vent is "Here's what you should have done instead". Responses might be technically correct but they lack empathy for the customer.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#149Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…
That is like showing someone "here's a lock and what's inside of it."
In time, someone will pick that lock.
Uniformity is what you don't need, nor would you want to know the nuances of how security and privacy are handled at a company so that you know exactly what holes need to be exposed.
You can't standardize security. It's way too risky.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#150Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…
> Kevin Mitnick publicized it and went to jail (unjustly) You're joking right? He even fully admits that he did what they accused him of doing.