Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.
Urgent security warning that may affect all internet users
21–30 of 120 posts
Re: Urgent security warning that may affect all internet users
#22"504 Gateway Time-out" Seems we were all too late....
Re: Urgent security warning that may affect all internet users
#23As someone who runs an online game we find that a huge percentage of our users arrive pre-compromised. Vast quantities of people wander around from site to site using the same email/password combo that has been compromised a long time ago. We do a GeoIP check now and send an email with an unlock code any time someone logs in from a different city than last time. This reduced the account compromise problem significant…
ALL non-secure online sites that need to identify users should allow for Google or Facebook authentication, or I will never try to access the game from my phone or tablet.
I refuse to use the same password everywhere, but that means I have a password vault on my computer. If I need to create a password and I'm on my phone, I simply click "close" (and uninstall if necessary). I sympathize with those "precompromised accounts," given that it's such a user interface failure (not to mention arrogant) to require a new password for every single little service/game/whatever.
OTOH, if I can "login with Google" and/or Facebook, both of those are already authenticated on my phone, and through the magic of OAUTH I can securely connect to your game without needing to generate a password. Certainly having the OPTION to create a password is fine; there will be people who hate Google/Facebook/whatever and who won't use them. But not having the option is an instant fail for me.
Not saying you're doing it wrong, since I don't know what game you're talking about, but I've certainly encountered many games that have no OAUTH options.
Re: Urgent security warning that may affect all internet users
#24Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.
Teddy, I'm a Namecheap user (over 30 domains and a bunch of SSLs) and what really concerns me is that I find out about this security issue via hacker news, instead of being sent an email. This is not how you communicate with customers when these types of security issues arise.
Re: Urgent security warning that may affect all internet users
#25Earlier quoted context omitted.
Thanks for pointing to a cached version. ...strange that the original is unavailable.
The original should be available without issue. Can you please let me know what happens when you try to access it? What ISP are you using? Thanks, Tamar from Namecheap
Edit: worked now.
Re: Urgent security warning that may affect all internet users
#26Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.
I have been using 2FA on NameCheap since you added the feature, but it's one of the more annoying implementations -- compare to Google's 2FA setup, for example. There I have to jump through the hoop of getting an SMS once a month (and verify my password a bit more frequently).
For NameCheap, it's every single time I log in, which translates to every single time I need to do or check something in my account.
This is probably only a minor annoyance for most of your customers; for me it sometimes means I can't sign in. I live in an area with fairly poor mobile coverage, so internet access & ability to receive an SMS do not always coincide. I'm also not tied to my mobile, so I may need to go find it where it's charging downstairs (or plug it in if it's dead) before I can continue.
I'd really appreciate either the option of a code generator (Google Authenticator, Authy, etc.), or a longer "remember-me" time -- it's rather more likely that my phone would be stolen than my laptop... so letting the laptop I've just double-authenticated be a "thing I have" is perfectly valid.
Re: Urgent security warning that may affect all internet users
#27> The group behind this is using the stored usernames and passwords to simulate a web browser login through fake browser software. This software simulates the actual login process a user would use if they are using Firefox/Safari/Chrome to access their Namecheap account. So basically PhantomJS? Or is it more sophisticated than that? Also, this might actually let me see if I'm in the list, since I will get an unsolici…
My guess would be Selenium.
Re: Urgent security warning that may affect all internet users
#28Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.
Excellent, thanks! I have been using 2FA on NameCheap since you added the feature, but it's one of the more annoying implementations -- compare to Google's 2FA setup, for example. There I have to jump through the hoop of getting an SMS once a month (and verify my password a bit more frequently). For NameCheap, it's every single time I log in, which translates to every single time I need to do or check something in my…
Re: Urgent security warning that may affect all internet users
#29Hyperbole much? WTF is this "urgent"? How might this affect "all internet users"? A hacker group is trying dictionary attacks. Wow. Flagged.
What you're saying is factually incorrect. A hacker group has accumulated thousands (millions?) of email+password pairs. Anyone who uses the same password on all sites could be compromised, even if their password is 16 characters and random (i.e., immune to dictionary attacks).
Re: Urgent security warning that may affect all internet users
#30Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.
Teddy, I'm a Namecheap user (over 30 domains and a bunch of SSLs) and what really concerns me is that I find out about this security issue via hacker news, instead of being sent an email. This is not how you communicate with customers when these types of security issues arise.
I know you wouldn't want to provoke panicked overreactions, or risk customers thinking that this indicates a flaw in NameCheap's security, but direct contact is essential for this kind of ongoing attack.
> continue to update our customers through our blog and social media
I'm not sure what percentage of your customers this will actually reach, but surely not a majority (certainly not me, anyway).