Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

361–370 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#361

Earlier quoted context omitted.

AT&T has a security code which is "What is your favorite restaurant?" that we set a decade ago when signing up for internet service. My wife and I have made, I don't know, 10 guesses over the years and have never been able to figure out what our response was back then. Questions with fact-based answers are much better. But...I once had a site ask me for my best man's first name (Good! This probably won't change over…

I'm always amazed at how little thought seems to go into these questions. My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus. One of the questions was "What's your favorite summer activity?" Her answer was, "Swimming." Yeah, that's going to add about one bit of entropy to most people's accounts, you idiots. Another favorite is "middle name of your youngest child…

> My wife filled one out a few weeks ago where both the questions and answers were selected from popup menus

United Airlines does this.

Their reason is incredibly depressing.

https://mobile.twitter.com/evacide/status/711853927134842880

Infosec is an unsolved problem in so many ways, especially for the majority of people that are nontechnical.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#362
post #329

Earlier quoted context omitted.

It seems like a general principle that the less important something is, the better the security probably is. Steam, for example, is really paranoid, constantly asking for verification whenever it thinks I'm logging in from a new computer, bugging me nonstop to set up 2FA, e-mailing me with alerts, etc. Meanwhile my bank does straightforward username/password authentication, with the bonus that the password is case in…

It's not that Steam is paranoid for no reason. People keep virtual items on their accounts which attackers can sell for real money, potentially yielding hundreds to thousands of dollars from one account, and so attempted Steam account hacking is rampant. Of course, that's nothing compared to the amounts stored in bank accounts...

Not to mention an account with saved billing info could be used to sell "extra copies of games I can gift you for a few bucks" since Steam allows gifting. What, you mean you didn't mean to buy 10 copies of "DARK SOULS III Deluxe Edition + Steam Controller Bundle" for $115 each to gift to all your friends and family?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#363

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

To be fair, that's a game account. I realize some MMOs can have really real-money valuable characters/items, so this argument can break down, but the security should be different from an MMO and a VPS solution or a bank. All of my security questions are passwords. I once had someone at a bank ask "Wait, your mother's maiden's name has a number in it?" "Wait, you actually answer security questions that any of your fri…

Magic Online simulates paper Magic. You buy packs to get cards, each card is its own individual digital object which can be traded and sold, card sets go out of print or have limited runs, and rare promos are released. It even has its own digital currency, "tickets", which are reasonably easily converted to cash.

Magic Online accounts can be worth tens of thousands of dollars.

And at least back when I played, if your account got compromised and all your cards were liquidated, the response from customer support was pretty much "that's too bad, shouldn't have let your account get compromised". I seriously doubt they ever added 2FA or anything either.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#364

Earlier quoted context omitted.

My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…

That's impressive, can you teach me to write like you?

[deleted]

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#365

Earlier quoted context omitted.

To be fair, that's a game account. I realize some MMOs can have really real-money valuable characters/items, so this argument can break down, but the security should be different from an MMO and a VPS solution or a bank. All of my security questions are passwords. I once had someone at a bank ask "Wait, your mother's maiden's name has a number in it?" "Wait, you actually answer security questions that any of your fri…

> To be fair, that's a game account. I realize some MMOs can have really real-money valuable characters/items, so this argument can break down You want to know how bad it can break down? I imagine the worst case scenario, for so many reasons , actually happened and was mtgox.com. It started out as a Magic: The Gathering Online Exchange (from what I understand) before it became the now infamous Bitcoin exchange that w…

MTGOX was purchased as a domain name for a possible MTG exchange, but it never went further than a domain name. There was never even a site.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#366
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

So could I have social engineered a 10 year old MTGO account? Yes. But without it, I would have been locked out. I was NOT going to remember some stupid passcode kid me set on a game account.

And apparently I am the nacho King.

What are the chances that you'll remember it in the future? You're already two years into remembering it for the next decade after you found it out again.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#367

Earlier quoted context omitted.

Until someone says "I know my dad was born in Minneapolis, what does it say??" and the customer service representative replies "Huh, it looks like the answer is just gibberish...", "Ah! I must have just mashed on my keyboard when I made the account, sorry about that!!", "No problem, your password is now reset to foobar".

While avoidable with training, that brings up its own issue: What if what's being asked of the people taking these calls is outside their pay range?

I think all account credentials related things should be handled by special support people, who were trained to understand the situation. Shouldn't be that big percentage of all requests when people need to change/remember password and can't use regular ways.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#368
post #365

Earlier quoted context omitted.

> To be fair, that's a game account. I realize some MMOs can have really real-money valuable characters/items, so this argument can break down You want to know how bad it can break down? I imagine the worst case scenario, for so many reasons , actually happened and was mtgox.com. It started out as a Magic: The Gathering Online Exchange (from what I understand) before it became the now infamous Bitcoin exchange that w…

MTGOX was purchased as a domain name for a possible MTG exchange, but it never went further than a domain name. There was never even a site.

Are you sure? Wikipedia[1] seems to indicate it at least got into a beta, but it also implies that the domain was what was reused for the bitcoin exchange, not the code base. That said, the references on wikipedia point to the Internet Archive, which shows a placeholder page that says it's in beta, but there's little there to indicate there was ever anything working. It also says it was used to advertise another card game later, but that was just a link to another domain.

I guess that's a long-winded way of saying you are probably right.

Then again, bitcoins were worth so little in 2010 that I could imagine the account security on exchanges back then being comparable to hobbiest exchange sites, so the spirit of the comment may be valid even if the specific example falls down. :/

1: https://en.wikipedia.org/wiki/Mt._Gox#Founding

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#369

Earlier quoted context omitted.

Matthew, It sounds like you are confirming that this incident did happen and it was your fault for not following your procedures. I am not a lawyer, but since there was signification loss, it would probably be in your best interest to offer better reparations. OpenDomain has several domains that are on NameCheap - I will transfer them immediately since it appears you do not care about customers.

Tell me one registrar where you can be sure that this will not happen and I will move my domains today. I wouldn't even care if I have to pay 100$ per year for a domain.

MarkMonitor perhaps? Google and Facebook both use MarkMonitor as the registrar for their primary domains. Might be more than $100 per domain though.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#370
post #363

Earlier quoted context omitted.

To be fair, that's a game account. I realize some MMOs can have really real-money valuable characters/items, so this argument can break down, but the security should be different from an MMO and a VPS solution or a bank. All of my security questions are passwords. I once had someone at a bank ask "Wait, your mother's maiden's name has a number in it?" "Wait, you actually answer security questions that any of your fri…

Magic Online simulates paper Magic. You buy packs to get cards, each card is its own individual digital object which can be traded and sold, card sets go out of print or have limited runs, and rare promos are released. It even has its own digital currency, "tickets", which are reasonably easily converted to cash. Magic Online accounts can be worth tens of thousands of dollars. And at least back when I played, if your…

> Magic Online accounts can be worth tens of thousands of dollars.

It might cost 10k+ dollars to make a behemoth account, but I don't think they are worth that much. It's basically fake internet points, I can gain these for free in this very comment.

Post reply on HN