Earlier quoted context omitted.
I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.
Comcast's password recovery is pretty weak. I just did it last night. They ask for your zip code and your favorite sports team. If I have a Boston zip code there are likely only 4 options for favorite sports team.
Namecheap live chat social engineering leads to loss of 2 VPS
381–390 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#382Re: Namecheap live chat social engineering leads to loss of 2 VPS
#383I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
Security is almost bomb proof with IP restrictions, GPG keys, 2FA and one little checkbox in their settings I like a lot: "This setting allows you to authorize or disable password resets from the login screen."
I think a good practice is to try to social engineer your own account and see if you end up getting it.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#384Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#385Earlier quoted context omitted.
> Magic Online accounts can be worth tens of thousands of dollars. It might cost 10k+ dollars to make a behemoth account, but I don't think they are worth that much. It's basically fake internet points, I can gain these for free in this very comment.
No, you can get actual money for them.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#386Earlier quoted context omitted.
One option is to look at when the user last logged in. I would be a lot less pissed if an account that I've never touched in 10 years got compromised... I'm probably going to remember my info for recent accounts and want it to be difficult to social engineering those
This is an excellent point. > "You forgot the password that you've logged in with multiple times... including 20 minutes ago." That should raise a flag.
People using a password manager might not ever know their password. Funny things happen with password managers where history is missing, changes don't save, keystrokes break things. We can't penalize users who use them.
It's unfortunately a really messy area.
Source: was a password manager in a past life
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#387Earlier quoted context omitted.
My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…
You are really good at it
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#388Re: Namecheap live chat social engineering leads to loss of 2 VPS
#389Earlier quoted context omitted.
I can't reply to the sister comment for some reason, so I'll piggyback on the parent. I always fill these with awkward or absurd questions/anwers that would be amusing if a human operator ever needs to verify them. E.g. Would you like to go on a date with me? What color pants am I wearing? What is the square root of insanity? Obviously you need to store these in a password database in order to remember them, which ki…
I've just started filling them with randomly generated strings that my password manager helpfully creates for me. Though, apparently my bank uses those answers for phone verification also, which makes answering questions like "What's your Significant Other's nickname?" awkward when the answer is "F9-#g7a2<qj"