Live data from Hacker News

Namecheap live chat social engineering leads to loss of 2 VPS

postphp.com

401–410 of 426 posts

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#401

Earlier quoted context omitted.

That's impressive, can you teach me to write like you?

Formula: * Actually apologize in a human way * Show empathy by identifying the impact of what happened to customers (not your impact internally) * State action items that you've created, even if they are just in 'evaluation' state * Indicate that the specific incident in question is being handled outside of this forum * Take responsibility for things even if you shouldn't "have to"

For a "what not to do", have a look how (the CEO of?) FTDI responded after they were caught intentionally "bricking" chips that were detected as counterfeit by the Windows drivers.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#402
post #50

I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I recently changed my phone support password at work to "aaah, f*, I'm not sure is it.." after listening to all my previous support calls and realising that was what I answered with 9/10 times. I suspect its only a matter of time before someone else accidentally guesses it. Its only for my regular user account, for my admin accounts I need to get another domain admin to reset the password, there is no process for anyone to exploit, just an audit every month.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#403

That's bad, really bad. No 2auth can save you from humans who do support. I also had one of my VPS attacked recently, and I feel for you. But the name namecheap says "cheap". Maybe they are indeed cheap? I'm not sure the same would have happened with say HE. You pay, but you know what you pay for and get in return. Personally, I am thinking about moving from a "manually setup" distribution to a "no ssh but deploy", s…

> Any suggestion for tools to do that with Debian distort? If you write apps, package them as Debs. If you need to configure other Debs, make config packages with config-package-dev [1] from the DebAthena project. Create a metapackage that depends on your software + config packages, and your setup process just needs to be "add private apt repo, apt update, apt install ". [1] https://packages.debian.org/jessie/config-…

This is fantastic, I wish I'd known about this earlier. Now I just need a way of testing Debian preseed faster than spinning up VMs, and I'll be set.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#405
post #155

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

One option is to look at when the user last logged in. I would be a lot less pissed if an account that I've never touched in 10 years got compromised... I'm probably going to remember my info for recent accounts and want it to be difficult to social engineering those

> I would be a lot less pissed if an account that I've never touched in 10 years got compromised...

You don't need to log into your VPS provider's account or domain name provider's account very often, compared to how often you use the machine or domain. But you don't want those getting reset more easily just because you haven't logged into them in a while.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#406

Earlier quoted context omitted.

My hobby: role-playing how I would respond as the CEO if my company was getting skewered on HN. Here is my version! --- Disclaimer: I'm [not] CIO @ Namecheap We messed up, big time. While we handle 1000s of live chat sessions everyday without issue, I realize that even one breakdown in security protocol can cause huge problems and a loss of trust for our customers. In response to this isolated case (in which our esta…

That's impressive, can you teach me to write like you?

If you're actually interested in the topic, here's an absolutely fantastic blog post on the subject:

http://blog.statuspage.io/why-public-apologies-suck

Some important bits:

>4 PARTS OF A BAD APOLOGY

- Justifying the offending actions or words.

- Blaming the victim.

- Making excuses.

- Minimizing the consequences.

>8 PARTS OF AN EFFECTIVE APOLOGY

- You actually have to use the words I’m sorry.

- Acknowledge that you messed up. (As in, “I take full responsibility for my words.”)

- Tell the person how you’ll fix the situation.

- Describe what happened, but without foisting the blame off on someone else.

- Promise to behave better next time.

- Make sure the person knows you know exactly how you hurt or inconvenienced them.

- Much like the first rule, it’s important to use some version of the phrase “I was wrong.”

- Ask for forgiveness.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#407
"On April 9, 2016 I had an email address compromised, with the attacker brute-forcing a weak password."

Namecheap is obviously to blame for the compromise of the VPS, but failing to secure an email account which can be used for password resets is even a bigger fail, IMO.

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#408

Earlier quoted context omitted.

It's tricky because a lot of customers really DO lock themselves out of a service, and forget their password reset code. Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support. The support guy was like chortle what was your security passcode…

I once tried to log into a site only to discover that the security question I left for myself was "What is blue?". I never figured it out.

And it wasn't 'the sky'?

Re: Namecheap live chat social engineering leads to loss of 2 VPS

#410
post #386

Earlier quoted context omitted.

This is an excellent point. > "You forgot the password that you've logged in with multiple times... including 20 minutes ago." That should raise a flag.

It actually should not. People using a password manager might not ever know their password. Funny things happen with password managers where history is missing, changes don't save, keystrokes break things. We can't penalize users who use them. It's unfortunately a really messy area. Source: was a password manager in a past life

That's why it should only raise a flag rather than totally stop. Perhaps the customer service rep can ask a few more questions.

It's a similar situation to someone who only ever uses their credit card to buy small amounts from their local supermarket. Then suddenly they use it to buy a flight in another country. It might be legit, but it's often not, and should suggest that customer service need to do more investigation before approving.

Post reply on HN