Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

381–390 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#381

Earlier quoted context omitted.

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

Comcast's password recovery is pretty weak. I just did it last night. They ask for your zip code and your favorite sports team. If I have a Boston zip code there are likely only 4 options for favorite sports team.

Poor Revs

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#382
The comments remind me of the time I tried to get a copy of my credit report from one of the big 3 agencies back in '09. One of the authentication questions was, "What is the name of your mortgage company?" My house had been foreclosed during a divorce 5 years earlier, and of course the mortgage had been sliced and diced about 15 times by different companies during the heyday of mortgage-based derivatives before the '08 crash. I finally gave up trying to get a copy from those guys.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#383
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

Another vote for gandi.net here. I transferred all my domains to them during the past years and have never been happier.

Security is almost bomb proof with IP restrictions, GPG keys, 2FA and one little checkbox in their settings I like a lot: "This setting allows you to authorize or disable password resets from the login screen."

I think a good practice is to try to social engineer your own account and see if you end up getting it.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#384

Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups

Welcome to the jungle. Kumbaya.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#385

Earlier quoted context omitted.

> Magic Online accounts can be worth tens of thousands of dollars. It might cost 10k+ dollars to make a behemoth account, but I don't think they are worth that much. It's basically fake internet points, I can gain these for free in this very comment.

No, you can get actual money for them.

Used to be easier when you could directly trade digital cards for paper cards..

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#386
post #155

Earlier quoted context omitted.

One option is to look at when the user last logged in. I would be a lot less pissed if an account that I've never touched in 10 years got compromised... I'm probably going to remember my info for recent accounts and want it to be difficult to social engineering those

This is an excellent point. > "You forgot the password that you've logged in with multiple times... including 20 minutes ago." That should raise a flag.

It actually should not.

People using a password manager might not ever know their password. Funny things happen with password managers where history is missing, changes don't save, keystrokes break things. We can't penalize users who use them.

It's unfortunately a really messy area.

Source: was a password manager in a past life

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#387

Earlier quoted context omitted.

My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…

You are really good at it

Previously, IFTTT: https://news.ycombinator.com/item?id=11379475

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#388
I transferred all my domains away from namecheap several months ago when the Ukrainian based live chat support was adamant they couldn't send an "ACK" message and have my domain transfer out automatically, and instead had to wait nearly a week for the "AUTO-ACK" to process. They lied to me and insisted ICANN require a five day wait even when I linked the ICANN documentation stating otherwise.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#389
post #319
post #300

Earlier quoted context omitted.

I can't reply to the sister comment for some reason, so I'll piggyback on the parent. I always fill these with awkward or absurd questions/anwers that would be amusing if a human operator ever needs to verify them. E.g. Would you like to go on a date with me? What color pants am I wearing? What is the square root of insanity? Obviously you need to store these in a password database in order to remember them, which ki…

I've just started filling them with randomly generated strings that my password manager helpfully creates for me. Though, apparently my bank uses those answers for phone verification also, which makes answering questions like "What's your Significant Other's nickname?" awkward when the answer is "F9-#g7a2<qj"

Yep, that's the way to do it - just ignore the questions competely and let your password manager handle it.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#390

Earlier quoted context omitted.

No, you can get actual money for them.

Used to be easier when you could directly trade digital cards for paper cards..

You can depending on how recent they are.
Post reply on HN