There will always be rare occasions such as this, but considering how many customers Namecheap handle, I don't think we should be seriously concerned. I'm pretty confident lessons will be learned.
Namecheap live chat social engineering leads to loss of 2 VPS
51–60 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#52Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
> Established procedure was not followed Why have a procedure if your support doesn't follow it? Even if you have a procedure, everything falls apart when it isn't followed. This is the same as having no procedure at all.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#53Re: Namecheap live chat social engineering leads to loss of 2 VPS
#54What legal consequences could there be for Namecheap, if any at all?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#55Re: Namecheap live chat social engineering leads to loss of 2 VPS
#56Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
Wouldn't it make sense that support staff can only generate and send out password reset mails if the PIN/password has been entered into a form? I don't know the term for this - like "coded procedure".
In this case, the support staff wouldn't even needed to be trusted in the first case.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#57Re: Namecheap live chat social engineering leads to loss of 2 VPS
#58Re: Namecheap live chat social engineering leads to loss of 2 VPS
#59Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place.
What do you use to tell whether a chat session is a genuine user or someone successfully using a social engineering attack against your chat operatives? If the answer is "nothing" then you can't know if this is an isolated event or how many of your chat sessions go without a glitch.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#60Its been months since I wanted to write a detailed summary, but the notion that "namecheap is hackers best domain registrar" is not valid anymore!
About year ago I noticed DNS changes on many of my there-parked domains. Upon reaching via Chat (no phone support so that angry customers cannot vent off) I was told that they cannot help me cause Im not the owner of the account! Upon full verification even with CC on file and telling them purchase history going back to 2009, I was still denied the access. As it turned out, all hacker needed to know is my public WHOIS info to take over my account!! That was insane! Only continuance of threats from my side that I will plaster it all over the net made them change their mind, which again is a breach of trust - what if I was actually the hacker??
What really made me start moving domains to NameSilo (Im not affiliated) is that upon doing a thorough research, I found many cases where Namecheap gives up on fighting for peoples domain! I seen names like nanotmz where company was building some sort of magnetic devices and TMZ came in and threat to sue Namecheap if they dont shut the domain down. That's where I found similar cases for NameSilo and learnt that they stand their ground and would not give up on your domains, even if are threatened with legal action.
I'm out of Namecheap completely as of last month with last SSL expiring.