Live data from Hacker News

My website was stolen by a hacker and I got it back

ramshackleglam.com

141–150 of 159 posts

Re: My website was stolen by a hacker and I got it back

#141
post #74

Earlier quoted context omitted.

This. I want to upvote this comment a hundred times. If there's a dispute with probable cause , temporarily freezing the domain while launching an immediate investigation seems by far the best balance of thwarting domain theft and minimizing fraudulent claims.

By ICANN policy domains can only be moved once every 60 days. Did you want the domain name taken offline?

No, not offline. Just have the administration of it frozen.

And it's only for recently transferred domains where it's the previous owner disputing the legitimacy of the transfer.

Domains are entries in a table. A "60 day freeze", if it exists, is just a policy.

Re: My website was stolen by a hacker and I got it back

#142

Earlier quoted context omitted.

By ICANN policy domains can only be moved once every 60 days. Did you want the domain name taken offline?

I'm not very familiar with their policies. Does that apply even in the case of theft? Didn't the article's author recover her domain within a few days?

It's no matter what you are only allowed to move domains once every 60 days. It is to prevent somebody from stealing a domain and moving it through 10 different registrars to wash the history of ownership.

Re: My website was stolen by a hacker and I got it back

#143
>cyber hacking

For when just 'cyber' and just misuse of the word hacking aren't enough.

Edit: >assuming that... my husband had accidentally logged into my account instead of his own

I think this shows her attitude to security could at best be described as lax.

>3. Turn off your computer and personal devices when they’re not in use.

I... this is... wow, what.

Re: My website was stolen by a hacker and I got it back

#144
post #100

Earlier quoted context omitted.

To follow up, I will say that my favorite way to create a password is to use sayings from two or more of your favorite books or other sources. So, if you like Harry Potter and Enders Game, what are the phrases that come to mind? Harry Potter - expelliarmus Enders Game - win all the future fights Now you have a great password: "winallthefuturefightsexpelliarmus" Nice and long (33 chars), with some made up stuff. Maybe…

winallthefuturefightsexpelliarmus Why not "Win all the future fights expelliarmus"? Passwords that don't accept spaces are pretty rare, and you end up with a longer password 'for free'.

> Passwords that don't accept spaces are pretty rare

Oh how I wish that was the case. Twitter is one such example which don't allow spaces (Last time I checked anyway)

Re: My website was stolen by a hacker and I got it back

#145
post #137

Earlier quoted context omitted.

This was the most interesting (unique) thing about the whole ordeal. I did not realize that wire transfers can be cancelled after the receiver has already had the funds placed in the account(else the thief would not have released the domain).

It's an escrow service, not a wiretransfer company. The bit that I don't get is that escrow.com (the one party that didn't actually do anything wrong here) now has acted in a way which they probably should not have done, from their point of view the transaction actually is legit (buyer has control of the domain name, so funds should be released). If Escrow.com can't be trusted to release the funds when the recipient…

That's what surprised me as well, but maybe the FBI intervening in the case was what pushed them to not honor the wire transfer.

Re: My website was stolen by a hacker and I got it back

#146
post #93
post #92

Earlier quoted context omitted.

Modern password crackers are pulling all of wikipedia and youtube for seed words. If your words are in either of those, don't expect the password to stand to a dedicated attacker

There are 1160290625000000000000000 combinations of 5 words with a dictionary of 65000 words. That's not brute-forceable. If you take existing phrases it's another story, but random words works well.

Being a little loose with my estimates and a bit of Fermi Math, thats only about 300 years of computing time on a small home built GPU cluster.

Basically tells me that 4 random words are definitely crackable and 5 are theoretically possible (and definitely doable with 5-10 years of Moore's law)

Re: My website was stolen by a hacker and I got it back

#147
post #146
post #93

Earlier quoted context omitted.

There are 1160290625000000000000000 combinations of 5 words with a dictionary of 65000 words. That's not brute-forceable. If you take existing phrases it's another story, but random words works well.

Being a little loose with my estimates and a bit of Fermi Math, thats only about 300 years of computing time on a small home built GPU cluster. Basically tells me that 4 random words are definitely crackable and 5 are theoretically possible (and definitely doable with 5-10 years of Moore's law)

lg(65k^4) is very nearly 64. If you worry about 4 random words being brute forced, you should worry about 64 bit symmetric keys being brute forced. I don't know where the current recommendations come down on that.

Re: My website was stolen by a hacker and I got it back

#148
post #92

Earlier quoted context omitted.

To follow up, I will say that my favorite way to create a password is to use sayings from two or more of your favorite books or other sources. So, if you like Harry Potter and Enders Game, what are the phrases that come to mind? Harry Potter - expelliarmus Enders Game - win all the future fights Now you have a great password: "winallthefuturefightsexpelliarmus" Nice and long (33 chars), with some made up stuff. Maybe…

Modern password crackers are pulling all of wikipedia and youtube for seed words. If your words are in either of those, don't expect the password to stand to a dedicated attacker

If you're picking with structure (including "phrases that spring to mind"), agreed. If you genuinely include enough entropy, then it doesn't much matter what mnemonics you layer on top.

Re: My website was stolen by a hacker and I got it back

#149

> 1. Have a really, really good password, and change it often. Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. http://xkcd.com/936/ But really, I'm a bit puzzled by her 5 "recommendations". Turn off your devices…

The xkcd-style passwords may be less vulnerable to a brute-force attack, but they are more vulnerable to a dictionary attack. There are (very) roughly 2^17 words in the dictionary, so if you pick 4 there are 2^68 possibilities, or 2.95e20. There are 94 printable characters on a US keyboard. This means that an 11-character "hard to remember" password has over 16 times as many (~2^72, 5.06e21) combinations as a four-wo…

They are more vulnerable to a dictionary attack for a given password length. The theory is that memorability (and ease of typing) decays more slowly with respect to the entropy contained in an xkcd style password than in a jumble of random characters.

Re: My website was stolen by a hacker and I got it back

#150
post #18

Earlier quoted context omitted.

I use gandi.net never had any serious issues with them and since their located in France (yes i intentionally avoided American companies) all this suing problem may not apply to them or at least it would be a lot more difficult. One thing is certain though most people i know have had issues with GoDaddy and avoid it like the plague.

Gandi now has offices in the USA, so they are effectively an American company as far as being subject to the US legal system and extraconstitutional orders from agencies and such. You won't get any privacy protection or immunity from illegal orders from Gandi.

Gandi does have an office in San Francisco, but our registrar service is accredited and located in France. It is under EU law.

Those who have been following the industry's responses to the massively reprehensible, illegal dragnet surveillance will know better than to take any company at their word as they swear up and down that they care about their users' right to privacy. So I know this will be taken with a grain of salt (hell, I take it with a grain of salt and I work here)...

But as far as I know, and I've asked around, we _actually_ do protect our customers' privacy to the maximum possible legal extent.

The day I find out otherwise is the day I no longer work here.

Post reply on HN