Live data from Hacker News

When two-factor authentication is not enough

blog.fastmail.fm

21–30 of 57 posts

Re: When two-factor authentication is not enough

#21
I wish there were a "pro registrar" who handled domains, ssl certs, etc for people who actually value their business. Right now, the best you can do is probably become an ICANN registrar yourself (since all the registrars seem to be assclowns from a security or support perspective, or both), and get an intermediate ca (if needed) or manage your certs through something like venafi. That is maybe a $100k setup, $50k/yr cost.

Someone less than that, or for that price but without having to devote staff, would make sense for some customers.

Sort of like MarkMonitor, I guess.

Re: When two-factor authentication is not enough

#22

Earlier quoted context omitted.

You actually want both - you want all of the automatic safety checks to be first completed, and then, after all of them have been passed, you want an account manager to personally pick up the phone, and call their contact at the company making the change, and have a discussion as to what is trying to be done, and whether everything is kosher.

Sure, for a company, yeah. For my personal domains, I'd rather have cheap and human-free ;)

Actually gandi's fortune was created on human-free. But they had a founder clash on what do with the money, and wether to seek more, one left, and now it's a normal corporate company.

Re: When two-factor authentication is not enough

#24
post #18

Although Gandi.net is a fantastic company, their security practices are nothing to write home about. A few years ago, one of my clients lost access to her Gandi.net account. Unfortunately, she had the "disable password resets via email" option set in her account. That should have given her quite a headache, right? Nope. I, an independent contractor who didn't even own the account, was able to convince Gandi support t…

> And this is not a problem that is specific to Gandi. Even with other online services, it's often quite easy to bypass automated security measures if you go through a human being, whether through the support system or through good ol' snail mail.

I wonder if this is actually a counter-intuitive advantage of AWS, which, as far as I can tell, offers absolutely zero, zip, nada human support.

Re: When two-factor authentication is not enough

#25
post #18

Although Gandi.net is a fantastic company, their security practices are nothing to write home about. A few years ago, one of my clients lost access to her Gandi.net account. Unfortunately, she had the "disable password resets via email" option set in her account. That should have given her quite a headache, right? Nope. I, an independent contractor who didn't even own the account, was able to convince Gandi support t…

> And this is not a problem that is specific to Gandi. Even with other online services, it's often quite easy to bypass automated security measures if you go through a human being, whether through the support system or through good ol' snail mail. I wonder if this is actually a counter-intuitive advantage of AWS, which, as far as I can tell, offers absolutely zero, zip, nada human support.

Actually they do for MFA problems, even if you don't have paid support on your account. A few years ago I wiped my phone without first disabling MFA on my account (I use Google Authenticator). After business hours on a holiday, I submitted the support form [0] and got a call from a human five minutes later. He asked me several questions and deactivated MFA so I could log in.

[0] https://portal.aws.amazon.com/gp/aws/html-forms-controller/c...

Re: When two-factor authentication is not enough

#27
post #26

Can anyone recommend a registrar who takes domain security seriously? (think, £ six digit value domain names)

When you're at that level of risk you probably need to worry as much about the registry as the registrar. If a corrupt registrar can simply bypass your registrar and claim the domain for example.

Re: When two-factor authentication is not enough

#28

It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain. It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything…

Well, we are paying for Gandi's corporate level of support. Funnily enough, we feel the same way about people who don't want to pay $20/year for their email address, given that it's the primary method of identifying yourself online. As with any business expense though, you only want to pay for value - if you spend $1000/year for exactly what you could have got for $100 year, that's wasting money. And we're satisfied…

With all due respect. I looked at the pricing of fastmail. So is it security the customer is paying for? Because for $10 and $20, you get a rather small max storage (250MB or 1GB). The only way to get a useful amount of data is to pay at least $40 a year. So basically most of the money goes to small data storage. What part of it goes to security and human time to handle security breaches?

Re: When two-factor authentication is not enough

#29

Earlier quoted context omitted.

Well, we are paying for Gandi's corporate level of support. Funnily enough, we feel the same way about people who don't want to pay $20/year for their email address, given that it's the primary method of identifying yourself online. As with any business expense though, you only want to pay for value - if you spend $1000/year for exactly what you could have got for $100 year, that's wasting money. And we're satisfied…

With all due respect. I looked at the pricing of fastmail. So is it security the customer is paying for? Because for $10 and $20, you get a rather small max storage (250MB or 1GB). The only way to get a useful amount of data is to pay at least $40 a year. So basically most of the money goes to small data storage. What part of it goes to security and human time to handle security breaches?

The $10 level is very much "entry level". The $20 level is enough for a lot of people. It's surprising how many people still delete most of their email from the server.

You're also paying for multiple replica copies and backups and all that good stuff. By the time you add RAID, search, metadata, etc - there's pretty much a 10:1 ratio between quota usage figures and raw disk used.

Then there's development effort - we're not just installing a couple of packages and then sitting back and letting them run.

Re: When two-factor authentication is not enough

#30
post #3

This article really should have been called "Security hole in Gandi's processes". Why would they change the account email address if you didn't reply to a single email within 24 hours? Who thought that was a good solution?

A possible reason was called out in the article: "Gandi’s paper 'email reset' form makes a lot of sense in the world where most of their customers are individuals or small businesses with one or two domains, and using addresses that they may lose access to. With no other factors, if they lose access to the email address and forget their password, there needs to be a process to regain access." If a customer loses acce…

Why not send a reset code to the registered address or phone number? Or they could pay some money into the registered bank account with a special code that would only be visible on a bank statement (like Paypal).
Post reply on HN