Live data from Hacker News

When two-factor authentication is not enough

blog.fastmail.fm

41–50 of 57 posts

Re: When two-factor authentication is not enough

#41

It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain. It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything…

I've heard this claim made repeatedly on this site, but I've not heard any details as to what specifically MarkMonitor does to protect domains above and beyond other registrars. Anyone care to chime in?

I have previously worked with MarkMonitor. One big factor is that at the time I had a single dedicated person who oversaw our domains. I knew him and his manager, and they knew me. Everything related to our domains went through them. It's not impossible to fool someone in that situation, of course, but it's a lot harder than fooling some random support person who knows nothing about the business or people involved. We talked on the phone regularly, and I have absolute certainty that if anything unusual came through, they wouldn't hesitate to call me and figure out if it was legitimate.

Re: When two-factor authentication is not enough

#42
post #26

Can anyone recommend a registrar who takes domain security seriously? (think, £ six digit value domain names)

I would suggest either MarkMonitor or Corporation Service Company. They're trusted by all the biggest corporations, and handle all their domain registrations themselves.

Re: When two-factor authentication is not enough

#43
post #26

Can anyone recommend a registrar who takes domain security seriously? (think, £ six digit value domain names)

When you're at that level of risk you probably need to worry as much about the registry as the registrar. If a corrupt registrar can simply bypass your registrar and claim the domain for example.

That's why several TLDs have a "registry lock" as well as a "registrar lock". Basically you can't transfer your domain between registrars without first going above their head to the registry.

Re: When two-factor authentication is not enough

#44

Earlier quoted context omitted.

A possible reason was called out in the article: "Gandi’s paper 'email reset' form makes a lot of sense in the world where most of their customers are individuals or small businesses with one or two domains, and using addresses that they may lose access to. With no other factors, if they lose access to the email address and forget their password, there needs to be a process to regain access." If a customer loses acce…

Shouldn't they send out a paper letter to the owner of the domain then? That might be a better way to verify identity. Or use an actual "real world" identity check? In Germany you can do that with the German mail system - the postman will then check your id and confirm you are who you claim to be. Certainly not foolproof, but just accepting incoming letters at face value seems crazy.

In Finland all changes to your .fi domain (renews, nameserver changes, etc.) are snail mailed to you. It was a confusing experience for me when I registered a .fi domain on Gandi, but still got all the mails sent to me. Also, I can't control my domain on Gandi, as the credentials were snail mailed to me by my country's authorities. The only place I can make changes to my domain is on Finnish authority's website - with the credentials which were snail mailed to me.

In here postmen only check your ID when receiving or retrieving packages, but I've understood that you can buy the same service for letters as well. Most online identity checks are made by logging in trough banks, which can verify your SSN and alike.

Re: When two-factor authentication is not enough

#45

Earlier quoted context omitted.

I think Google actually stand to lose less than a smaller corporation. The registry will not assign Google to another company in any way that passes any eyeballs without seriously questioning it; if it did get re-assigned then they wouldn't have a problem recovering it. It's not likely to be gone for more than a few seconds before it's noticed and customers who were phished, or whatever, wouldn't be that likely to le…

I would agree that any attempt to reassign google.com ought to raise someone's eyebrows. But I would have said the same about mit.edu and they got reassigned about a year ago. Obviously not for long, but the damage someone well-prepared could do by owning google.com for just 30 minutes is scary.

The "well prepared" part makes me wonder. What kind of infrastructure would you need to handle google.com's traffic? I don't think any of the cloud providers can scale up to that kind of traffic out of the box, and it's not like someone can just build and staff a dozen data centers in preparation of this hijack attempt.

Re: When two-factor authentication is not enough

#46
post #44

Earlier quoted context omitted.

Shouldn't they send out a paper letter to the owner of the domain then? That might be a better way to verify identity. Or use an actual "real world" identity check? In Germany you can do that with the German mail system - the postman will then check your id and confirm you are who you claim to be. Certainly not foolproof, but just accepting incoming letters at face value seems crazy.

In Finland all changes to your .fi domain (renews, nameserver changes, etc.) are snail mailed to you. It was a confusing experience for me when I registered a .fi domain on Gandi, but still got all the mails sent to me. Also, I can't control my domain on Gandi, as the credentials were snail mailed to me by my country's authorities. The only place I can make changes to my domain is on Finnish authority's website - wit…

It's probably too expensive to use as a standard method, but I would be willing to deposit some money with Gandi just in case they need to ID check me.

Re: When two-factor authentication is not enough

#47

Earlier quoted context omitted.

Well, we are paying for Gandi's corporate level of support. Funnily enough, we feel the same way about people who don't want to pay $20/year for their email address, given that it's the primary method of identifying yourself online. As with any business expense though, you only want to pay for value - if you spend $1000/year for exactly what you could have got for $100 year, that's wasting money. And we're satisfied…

With all due respect. I looked at the pricing of fastmail. So is it security the customer is paying for? Because for $10 and $20, you get a rather small max storage (250MB or 1GB). The only way to get a useful amount of data is to pay at least $40 a year. So basically most of the money goes to small data storage. What part of it goes to security and human time to handle security breaches?

> So is it security the customer is paying for? [...] The only way to get a useful amount of data is to pay at least $40 a year.

Security is one of my top concerns, which is why I don't need much storage at FastMail. My email is deleted from FastMail's servers in less than 180 days after receipt because the USG considers email over 180 days old to be abandoned and will access such email without a warrant.

http://en.wikipedia.org/wiki/Electronic_Communications_Priva...

Re: When two-factor authentication is not enough

#48

Earlier quoted context omitted.

A possible reason was called out in the article: "Gandi’s paper 'email reset' form makes a lot of sense in the world where most of their customers are individuals or small businesses with one or two domains, and using addresses that they may lose access to. With no other factors, if they lose access to the email address and forget their password, there needs to be a process to regain access." If a customer loses acce…

Shouldn't they send out a paper letter to the owner of the domain then? That might be a better way to verify identity. Or use an actual "real world" identity check? In Germany you can do that with the German mail system - the postman will then check your id and confirm you are who you claim to be. Certainly not foolproof, but just accepting incoming letters at face value seems crazy.

The US has this as well -- registered mail, which provides a full chain of custody for the letter. It's also a serious crime to provide fraudulent identification.

Re: When two-factor authentication is not enough

#49

It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain. It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything…

I've heard this claim made repeatedly on this site, but I've not heard any details as to what specifically MarkMonitor does to protect domains above and beyond other registrars. Anyone care to chime in?

Part of what they do is set up registry locks.

This is different than a registrar lock in that a registrar lock is managed by the registrar (GoDaddy, Tucows, etc) but a registry lock is managed by the registry themselves. It requires personal contact with specific individuals to enable and disable the lock, making attempts to steal domains more difficult (but not impossible since social engineering is still feasible).

I've never used MarkMonitor before, but I did handle the registration for a hugely popular domain at one time. They decided to move to MarkMonitor but in the meantime they requested a registry lock set up on their main domain. This turned out to be very good idea since the registrar at the time was social engineered into changing the credentials for the account (with forged letter head similar to the fastmail.fm attack). The attackers were able to change the nameservers for little used domains but their main domain could not be modified.

Re: When two-factor authentication is not enough

#50

It's interesting how there are people who think spending $100/year/domain is a lot of money - but when your entire company's business/value is on the line, I would think that spending $1,000/year/domain, to make absolutely sure nothing goes wrong, would be a bargain. It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything…

Wasn't Facebook's domain, or at least their whois record, hacked via MarkMonitor in February? At least that was the initial report; I'm not sure what happened and it's hard to find a credible source about it. Here's the best I found in a short search:

http://thenextweb.com/facebook/2014/02/06/uh-oh-syrian-elect....

Of course if it was hacked it wasn't necessarily MarkMonitor's fault; it could be Facebook's (though good security would anticipate that some customers will have poor security).

(If that post looks familiar, yes I'm reposting from a few days ago when someone made a similar comment. I'm hoping someone knows more about it.)

Post reply on HN