Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

311–320 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#312
post #149

Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…

I hate to break it to you, but "uniform" security standards that are out there in the open would be like a whole can of worms. That is like showing someone "here's a lock and what's inside of it." In time, someone will pick that lock. Uniformity is what you don't need, nor would you want to know the nuances of how security and privacy are handled at a company so that you know exactly what holes need to be exposed. Yo…

Of course you can standardize security. This means that the same authentication methods would be used across the industry, and the agents would be trained to not leak those details through social engineering, etc. It would mean that there would be standards with respect to what information tier 1 agents have vs tier 2 agents, etc, with proper separation of duties, so that poorly trained tier 1 agents wouldn't have the ability to be socially engineered.

Your method of security through obscurity simply doesn't work because hackers will figure it out and exploit impedance mismatches between vendors.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#313

Social engineering in tech has been around since before Kevin Mitnick publicized it and went to jail (unjustly). Why do we keep making the same mistakes over and over again as an industry? We NEED UNIFORM security standards with ALL trusted companies with customer support, where we have tiers of support, and 1st tier doesn't have any access that could compromised security. Similar to ISO standards. This means there c…

As a business, it costs more to piss off your customers regularly because they can't get into their accounts than it does to refund the rare victim of social engineering.

Sounds exactly like what I would expect from a lazy, shortsighted business who believed that a successful social engineering attempt wouldn't cost them more money.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#314
post #25

Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…

I think another lesson in security is that 2FA are sometimes completely broken because of real use-case where the user lose his second authenticator device. This is one of the reason I'm really iffy about setting up 2FA on my own accounts.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#315

Earlier quoted context omitted.

Amazon Web Services is great, and as far as I experienced, their support knows more than average.

You can get AWS customer support to reset your password if you know the last 4 digits of the credit card used to pay for the account. This is the same info that's printed on any credit card receipt.

If they have your bank account number for whatever reason you can also use last 4 of the bank account number. Your bank account number is not secret by design and most people only have one.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#318
post #210

Earlier quoted context omitted.

I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…

Thanks for edit2 :) I see us having used the word "mistake" many times here! But yes, we apologize that this happened as well.

The namecheap CIO never uses the word mistake. The execs rarely show any remorse. Best case they delegate to underlings like the social media guru.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#319
post #300

Earlier quoted context omitted.

I'm always amazed at how little thought seems to go into these questions. My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus. One of the questions was "What's your favorite summer activity?" Her answer was, "Swimming." Yeah, that's going to add about one bit of entropy to most people's accounts, you idiots. Another favorite is "middle name of your youngest child…

I can't reply to the sister comment for some reason, so I'll piggyback on the parent. I always fill these with awkward or absurd questions/anwers that would be amusing if a human operator ever needs to verify them. E.g. Would you like to go on a date with me? What color pants am I wearing? What is the square root of insanity? Obviously you need to store these in a password database in order to remember them, which ki…

I've just started filling them with randomly generated strings that my password manager helpfully creates for me. Though, apparently my bank uses those answers for phone verification also, which makes answering questions like "What's your Significant Other's nickname?" awkward when the answer is "F9-#g7a2<qj"

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#320
post #210

Earlier quoted context omitted.

Thanks for edit2 :) I see us having used the word "mistake" many times here! But yes, we apologize that this happened as well.

The namecheap CIO never uses the word mistake. The execs rarely show any remorse. Best case they delegate to underlings like the social media guru.

Let's not throw personal attacks at me (and the tongue-in-cheek "congrats for being promoted to executive!" comment). There's plenty of remorse and there's plenty of acknowledgment of mistakes here. That said, as we acknowledged elsewhere, we're responding to the matter across several different platforms and specifically say we're rushed in trying to get out some basic insights behind what happened and transpired. A more well crafted blog response for all to see (this time from the CEO) has been published to https://blog.namecheap.com/social-engineering-issue/
Post reply on HN