Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

261–270 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#261
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

Very much this. As a long-time Namecheap customer, this thread caught my attention, but my layman's conclusion is that it doesn't really sound like they did anything worse than any other host would have done.

As someone who forgets his passwords on a regular basis, I'm kind of glad that there's no such thing as perfect security...

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#262

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

Story time: I have been trying for 3 years to figure out what I wanted to hint at with "If it's not this one then it's the other one" as a secret question. I thought I was a clever boy not choosing the usual predetermined "what's your mother's name ?".

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#263
post #42

Earlier quoted context omitted.

Second biggest lesson here: do not use weak passwords for emails.

Was interesting that the victim said they used 2FA for everything they considered important, but not email. I guess their email provider doesn't provide it?

I was thinking the same. But in that case, maybe move to a provider that does support it?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#264

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…

If I ever run a company that screws up I'm calling you.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#265

Earlier quoted context omitted.

This seems very easy to bypass.

Very easy? I'd say "possible" at best . And now you've got access to a battle.net account. Took a heck of a lot more work than asking someone for username/pass in a live chat, and what you gained access to is worth a heck of a lot less. Plus Blizzard actually does keep backups and records and will be able to fix the situation for the account owner. I'd be surprised if ever a Blizzard account was compromised by someon…

It seems like a general principle that the less important something is, the better the security probably is. Steam, for example, is really paranoid, constantly asking for verification whenever it thinks I'm logging in from a new computer, bugging me nonstop to set up 2FA, e-mailing me with alerts, etc. Meanwhile my bank does straightforward username/password authentication, with the bonus that the password is case insensitive and silently truncated to eight characters.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#266

Earlier quoted context omitted.

For every site that does this, I have a blob of text in my password manager where I write down Q: what was your childhood best friend's last name? A: pathway-titian-slowly-quiver-kodiak-hue etc., even for fact-based things like "what city were you born in?" or "what street did you live on in 1995?".

Ah, but the anti-pattern folks have a way around that. Drop-downs for answers . Just got this on United.com: http://imgur.com/84l0CdU

How about 5 random questions, 5 random answers and record all of these in your password manager?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#267
post #196

Earlier quoted context omitted.

This is an excellent point. > "You forgot the password that you've logged in with multiple times... including 20 minutes ago." That should raise a flag.

Namecheap has security notifications that inform you of login attempts. https://www.namecheap.com/support/knowledgebase/article.aspx...

This is more about preventing the social engineering attacks. The example you're replying to is where the actual user logged in 20 minutes ago, while the attacker is trying to claim to customer service that they forgot the password. If customer service were looking at login attempts, they would see that it doesn't make sense for the user to not know their password, when clearly they provided it to the site just 20 minutes ago.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#269
post #6
post #2

The most significant security problem with Namecheap is really this: It only takes a 4 digit PIN to perform any action on an account through live chat (which seems to be outsorced to Eastern Europe), even if the account is protected with a 2FA... All you need is the PIN, and an attacker can do anything to the account. Sometimes you get what you pay for.

If I wanted more security on my account, is there a different service I should be using?

NearlyFreeSpeech seems pretty serious about this sort of thing: https://www.nearlyfreespeech.net/about/faq#LostEverything

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#270

Earlier quoted context omitted.

For every site that does this, I have a blob of text in my password manager where I write down Q: what was your childhood best friend's last name? A: pathway-titian-slowly-quiver-kodiak-hue etc., even for fact-based things like "what city were you born in?" or "what street did you live on in 1995?".

Ah, but the anti-pattern folks have a way around that. Drop-downs for answers . Just got this on United.com: http://imgur.com/84l0CdU

I think that the drop-downs are trying to prevent people from mistyping things and locking themselves out because "Accordien" doesn't match "accordion".
Post reply on HN