Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
Matthew, It sounds like you are confirming that this incident did happen and it was your fault for not following your procedures. I am not a lawyer, but since there was signification loss, it would probably be in your best interest to offer better reparations. OpenDomain has several domains that are on NameCheap - I will transfer them immediately since it appears you do not care about customers.
Namecheap live chat social engineering leads to loss of 2 VPS
341–350 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#342Earlier quoted context omitted.
Example of on HN expecting everyone (newbies and all) to know who you are. This happens with DANG and SAMA comments as well. Back when PG used to comment also happened. Look at their profiles, really no explanation of who they are here: https://news.ycombinator.com/user?id=pg https://news.ycombinator.com/user?id=dang https://news.ycombinator.com/user?id=sama Why is it so hard to put info in your profile or to put a f…
He posted this down the thread which starts with: > Disclaimer: I'm CIO @ Namecheap https://news.ycombinator.com/item?id=11479810
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#343Earlier quoted context omitted.
I can't reply to the sister comment for some reason, so I'll piggyback on the parent. I always fill these with awkward or absurd questions/anwers that would be amusing if a human operator ever needs to verify them. E.g. Would you like to go on a date with me? What color pants am I wearing? What is the square root of insanity? Obviously you need to store these in a password database in order to remember them, which ki…
I've just started filling them with randomly generated strings that my password manager helpfully creates for me. Though, apparently my bank uses those answers for phone verification also, which makes answering questions like "What's your Significant Other's nickname?" awkward when the answer is "F9-#g7a2<qj"
#$%&+@ is going to be hard to type or speak, just say their nickname is "the frozen one", same entropy, easier to handle
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#344I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…
All of my security questions are passwords. I once had someone at a bank ask "Wait, your mother's maiden's name has a number in it?"
"Wait, you actually answer security questions that any of your friends can guess honestly?"
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#345Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
Matthew, It sounds like you are confirming that this incident did happen and it was your fault for not following your procedures. I am not a lawyer, but since there was signification loss, it would probably be in your best interest to offer better reparations. OpenDomain has several domains that are on NameCheap - I will transfer them immediately since it appears you do not care about customers.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#346Earlier quoted context omitted.
See my other comments in this thread
I've reviewed all 16 of your comments on the page and beyond sawing a single person at Namecheap didn't follow policy and blaming the user in question, I don't see anywhere that you've stated there's an issue with controls. Am I missing something, or is Namecheap saying they didn't do anything wrong?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#347Earlier quoted context omitted.
The email being compromised opened the door to his email being compromised. The door to his Namecheap account being compromised was apparently already wide open.
No, OP didn't have 2FA enabled on their namecheap account. It was namecheap's fault for improper handling of the social engineering attack but OP could have protected themselves by having 2FA
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#348Earlier quoted context omitted.
"Better be safe than sorry" - namecheap for when you lose your stuff on their services. I don't think the best way to respond to a public vent is "Here's what you should have done instead". Responses might be technically correct but they lack empathy for the customer.
"Hard drives never fail" - kelukelugames
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#349Earlier quoted context omitted.
The issue is that Namecheap was the one that fucked up here, and now is not the time to emphasize "you should really be prepared for us fucking up in this manner". It's victim blaming. It looks shitty. The argument I refer to isn't "you should have offsite backups". The argument is that Namecheap is implicitly victim blaming, and they're not going to convince many people that they aren't.
Eh.. I don't really agree that this is victim blaming. But then again, I find that I disagree with most uses of the phrase "victim blaming". Pointing out that somebody did something sub-optimal, while still acknowledging the mis-deeds, mistakes, etc. of other parties, is not "victim blaming" in my book. It's just pointing out the truth. I mean, if you go for a stroll through the roughest neighborhood in town, unarmed…
In other worlds however, the problem is usually too widespread. You might get a lot of attention, comiseration, etc. but in the end, being reckless goes against survival. People who point this out should not be shushed for pointing out what you need to do to survive.
Its amazing to see that this "victim blaming" mentality is growing in Brazil. Violence here is out of control. You might get mugged/shot/kidnapped for no reason, or not displaying any wealth. Having been kidnapped myself, and chatted with the kidnappers, they do look for signs of wealth before pouncing. Therefore, yes, the victim does has an ounce of control over their risk and it's not wrong to point that out.
It does not solve violence, and attackers will just look for other victims regardless of their reward estimate. However, would you tell your children not to not show affluence/vulnerability in shady places just because you don't want to "victim blame"?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#350Earlier quoted context omitted.
It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…
To be fair, that's a game account. I realize some MMOs can have really real-money valuable characters/items, so this argument can break down, but the security should be different from an MMO and a VPS solution or a bank. All of my security questions are passwords. I once had someone at a bank ask "Wait, your mother's maiden's name has a number in it?" "Wait, you actually answer security questions that any of your fri…
You want to know how bad it can break down? I imagine the worst case scenario, for so many reasons, actually happened and was mtgox.com. It started out as a Magic: The Gathering Online Exchange (from what I understand) before it became the now infamous Bitcoin exchange that was hacked[1] and massive amounts of money was stolen. I don't know for a fact that old accounts before the pivot to Bitcoin still existed and worked, but it's not inconceivable that they would. One hopes they adopted much better security compared to when they were a trading card exchange (if it wasn't already exceptional at that time), but there could very well have been a time when it was gaining traction for financial type services but didn't have good account safeguards.
1: Or whatever. From what I remember that's a story convoluted and with enough conspiracy theories it's worth a movie.