Live data from Hacker News

Urgent security warning that may affect all internet users

community.namecheap.com

41–50 of 120 posts

Re: Urgent security warning that may affect all internet users

#41

As someone who runs an online game we find that a huge percentage of our users arrive pre-compromised. Vast quantities of people wander around from site to site using the same email/password combo that has been compromised a long time ago. We do a GeoIP check now and send an email with an unlock code any time someone logs in from a different city than last time. This reduced the account compromise problem significant…

As someone who plays online games, I get really, really annoyed when I'm forced to create a password to log in. ALL non-secure online sites that need to identify users should allow for Google or Facebook authentication, or I will never try to access the game from my phone or tablet. I refuse to use the same password everywhere, but that means I have a password vault on my computer . If I need to create a password and…

It's a real shame that the only widely deployed OpenID support is tied heavily to Google or Facebook.

Actually, is that still even OpenID? Or is it something more proprietary?

Re: Urgent security warning that may affect all internet users

#42
post #12

Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.

Hi, did you turn on (or can you) selective forensic logging from the ip-adresses you believe are attacking, logging username/password pairs? AFAIK the list in question isn't public, it would be nice to see if there was a pattern (to uids and/or uid:password pairs) -- that might be turned into an IDS rule? (failed login for user: alfa, followed by user beta, followed by... -> block/flag originating ip etc)

Re: Urgent security warning that may affect all internet users

#43
post #21

Earlier quoted context omitted.

Teddy, I'm a Namecheap user (over 30 domains and a bunch of SSLs) and what really concerns me is that I find out about this security issue via hacker news, instead of being sent an email. This is not how you communicate with customers when these types of security issues arise.

You should have no such expectation. This isn't a namecheap-specific security issue - they are reporting their perspective of a global security issue.

They are reporting a specific attack on Namecheap accounts based upon a previous attack.

Re: Urgent security warning that may affect all internet users

#44
post #12

Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.

OT, but why is that providers like Namecheap implement 2FA but not organizational team support? If I set up 2FA, only my device can log in. If I become unavailable for some reason, none of my team members can access the account. The only way to do this is for all team members to do the 2FA setup at the same time, which I believe will seed the generator so that they will all produce the same sequence of tokens. But th…

We actually have a little-known feature, which allows you to grant domain modification rights to other Namecheap users. https://www.namecheap.com/support/knowledgebase/article.aspx...

You can also add other phone numbers to your 2FA preferences, although I can understand if that's annoying for your colleagues if everyone is getting an SMS on every login.

Re: Urgent security warning that may affect all internet users

#45
post #41

Earlier quoted context omitted.

As someone who plays online games, I get really, really annoyed when I'm forced to create a password to log in. ALL non-secure online sites that need to identify users should allow for Google or Facebook authentication, or I will never try to access the game from my phone or tablet. I refuse to use the same password everywhere, but that means I have a password vault on my computer . If I need to create a password and…

It's a real shame that the only widely deployed OpenID support is tied heavily to Google or Facebook. Actually, is that still even OpenID? Or is it something more proprietary?

OAuth2

Re: Urgent security warning that may affect all internet users

#46

As someone who runs an online game we find that a huge percentage of our users arrive pre-compromised. Vast quantities of people wander around from site to site using the same email/password combo that has been compromised a long time ago. We do a GeoIP check now and send an email with an unlock code any time someone logs in from a different city than last time. This reduced the account compromise problem significant…

As someone who plays online games, I get really, really annoyed when I'm forced to create a password to log in. ALL non-secure online sites that need to identify users should allow for Google or Facebook authentication, or I will never try to access the game from my phone or tablet. I refuse to use the same password everywhere, but that means I have a password vault on my computer . If I need to create a password and…

So, having large corporations (google, facebook, etc) know everything you're doing all the time at every site and in every app is better than...having to keep track of various passwords? I don't get it.

I find 3rd party authentication without the slightest appeal. Maybe it's a teensy bit easier.

Re: Urgent security warning that may affect all internet users

#48
post #28
post #26

Earlier quoted context omitted.

Excellent, thanks! I have been using 2FA on NameCheap since you added the feature, but it's one of the more annoying implementations -- compare to Google's 2FA setup, for example. There I have to jump through the hoop of getting an SMS once a month (and verify my password a bit more frequently). For NameCheap, it's every single time I log in, which translates to every single time I need to do or check something in my…

We're rolling out Google Authenticator support sometime in the fall. I know SMS can be a pain sometime but we definitely recommend having it enabled, regardless.

This is fantastic news. It's a feature I've been missing since you introduced 2FA (which was also a great move)

Re: Urgent security warning that may affect all internet users

#49
post #47

For sensitive sites like this, users should not be given the option to use the same username/password as other websites: The username should be issued by the site in the form Sally379687 or Fred965912

What Namecheap do is better - two-factor authentication. usernames are not meant to be secret, and forcing users to look up a username as well as a password is going to be annoying.

Off-topic, I switched to Namecheap (from GoDaddy) a couple of years ago, and have been impressed. Things like two-factor auth and being aware of and publicising this attack are all signs of a good corporate citizen doing things right.

Re: Urgent security warning that may affect all internet users

#50
post #47

For sensitive sites like this, users should not be given the option to use the same username/password as other websites: The username should be issued by the site in the form Sally379687 or Fred965912

Then people are just likely to write it down, or forget it, etc. Need to provide for humans too :)
Post reply on HN