5 ms·
Name.com Tells Customers To Change Password Due To Breach
- ceejayoz 13y agoWell, that confirms at least part of the Linode story.
- dkuntz2 13y agoWhat exactly wasn't believable about it before? Linode confirmed that someone cracked into their system on their blog, which I consider as being confirmation enough for everything.
- ceejayoz 13y agoLinode confirmed they were cracked, but the HTP write-up in https://news.ycombinator.com/item?id=5667027 https://news.ycombinator.com/item?id=5667027 included a lot of additional details, much of it hard to confirm. FBI moles, compromise of a fairly large registrar, etc.
- dkuntz2 13y agoI guess I just didn't see a reason for HTP to lie about it, especially with several smaller pieces out there confirming large portions of it. I suppose I don't understand why it's necessary to know if HTP was being 100% honest when the big details have been confirmed.
- ceejayoz 13y agoThis is the first confirmation I've seen of Name.com being hacked. That's a fairly significant sticking point, particularly as the known attack vector on Linode was a ColdFusion exploit, not a complete takeover of their registrar...
- kouiskas 13y agoThe name.com sample data HTP showed in their log by querying the database was real. Source: I work for one of the companies they used as sample rows when querying the name.com DB. Our head of ops confirmed that the hash in the HTP log was indeed the MySQL 4.1 PASSWORD() unsalted hash of our password at the time. name.com is kind of generous with the term "encrypted" in their email.
- mcintyre1994 13y agoThe article implies this is the first time they've notified customers, so they've either been unaware (seems unlikely since the FBI had a mole in HTP, who have claimed responsibility) or just not disclosing it? Is that true? I can understand why people are annoyed at Linode and everything, but this seems ridiculous if it's the first time.
- carlsednaoui 13y agoName.com user here. This is the first time one of my registrars gets compromised and I'm not sure I understand the (potential) severity of what has happened. What would HN suggest doing in a case like this (aside from changing passwords)? Just let it be? Monitor credit card? Change registrar? Looking forward to your feedback.
- blacktulip 13y agoI try not use credit card online while other choices are given. Name.com only has my paypal account name (if they save this kind of information). However I still changed my credit card since it was in the Linode database. I considered changing registrar. But I really can't know to which one I can go. How do you know they won't be (or already are) compromised?
- carlsednaoui 13y agoVery true. Perhaps I should try getting into the habit of using PayPal instead of credit cards.
- eli 13y agoAt least in the US, having your card number stolen is such a small deal that it hardly seems worth worrying about. Just keep an eye on your statement, which you should really be doing anyway. You don't have to pay for charges you didn't authorize. In my experience, the card issuer typically detects the fraud automatically.
- deleted 13y ago[deleted]
- chopsueyar 13y agoMake sure your domains are pointing to the nameservers you originally specified.
- carlsednaoui 13y agoI will, thank you.
- nemothekid 13y agoOddly enough, as a name.com customer I kind of surprised that I found this out through HN first.
- graue 13y agoDid you not get the email? I'm a Name.com customer too and I didn't get this email.
- rada 13y agoI got the email an hour ago.
- carlsednaoui 13y agoThat's strange, I did receive their email (at 1:45PM EST to be exact). Did you check your SPAM folder?
- notahacker 13y agoI haven't get an email yet either (wasn't in my spam folder and the whois details are correct). I hope that's not a sign of bigger issues.
- sobering 13y agoDitto. I still have yet to receive the email. Checked spam to no avail.
- nthj 13y agoI received my email 90 minutes ago
- stevesaldana 13y agoI just received their email (5:35pm EST)
- jasonlotito 13y agoReceived mine early this morning.
- deleted 13y ago
- blacktulip 13y agoFor anyone who wasn't following HN yesterday: https://news.ycombinator.com/item?id=5667027 https://news.ycombinator.com/item?id=5667027 https://news.ycombinator.com/item?id=5667391 https://news.ycombinator.com/item?id=5667391
- chadscira 13y agoi changed my password yesterday when i saw that. took name.com quite a while to contact us...
- edmond_dantes 13y agoNotice they said "encrypted" passwords not (salted password hashes) passwords. I don't trust "encrypted" password because my experience with Host Gator: I contacted Host Gator support to reset my password and they were able to send me my previous PLAINTEXT password. I asked them how this was possible and they told me that the passwords were encrypted and only a few people had access to it. People who also have access to it: Anyone who can see the Host Gator email que and the mail-servers the email passed through. I promptly closed my account with them.
- 3JPLW 13y agoI also found it interesting how vague they were in "implementing additional security measures". I would hope that they've identified and fixed the core security issue that HTP exploited, and that these extra measures aren't simply asking their customers to change their passwords. They also only mention personal information theft, while there was also supposedly a risk of configuration changes to domains hosted there.... were they able to track any malicious changes? Or are they confident none happened? Or did they have no idea about the breach until HTP publicized it? More information would certainly help my confidence with them as a registrar.
- pwman 13y agoOne of the reasons we liked name.com was their multi-factor support and email on action support, but it's all an illusion if hackers can get in at this level and go undetected until they helpfully post it publicly!
- subsection1h 13y agoYeah, one of the main reasons I use Name.com is MFA. I'm not happy that my domain registrar was hacked by a group that wasn't even targeting the company; it was simply the weakest link. Not good.
- btipling 13y agoEncrypted is not the same as hashed. An encrypted password could be secure as long as the means to decrypt the password, for example the key used to encrypt, is not leaked. Sending you passwords over email however is horrible. If your password is hashed, which it usually should be, then the service would not be able to give it to you. The reason services sometimes instead opt to encrypt instead of hash is for support reasons. Encrypting a password could be ok, as long as they never expose the password over something like email.
- xSwag 13y agoI made an account on name.com 5 days ago. Anybody know when the breach happened?
- 3JPLW 13y agoIt was back in April, in association with an attack on Linode [1]. See this HN comment by RoboTeddy from yesterday for a great summary of the group's story about these attacks [2]. However, Name.com has not disclosed much information. I don't know if they were aware of the attack until the group released their story yesterday. The systems could have still been compromised. [1] https://blog.linode.com/2013/04/16/security-incident-update/ https://blog.linode.com/2013/04/16/security-incident-update/ [2] https://news.ycombinator.com/item?id=5667391 https://news.ycombinator.com/item?id=5667391
- mattwdelong 13y agoIt looks like they may have used RSA encryption with a 4096 bit key [1] and as far as I know, if the private key is not compromised; this is pretty darn secure...Can anyone confirm? [1] - https://twitter.com/namedotcom/status/332260201535266816 https://twitter.com/namedotcom/status/332260201535266816
- eli 13y agoHNer kouiskas suggests it is a weak, unsalted hash. https://news.ycombinator.com/item?id=5677550 https://news.ycombinator.com/item?id=5677550
- mattwdelong 13y agoThanks for the heads up, I did not notice that.
- andrewmunsell 13y agoThat seems to be for the password, right? Credit cards should be encrypted with a much stronger algorithm (hence the reference to the private keys).
- eli 13y agoOh, I guess so. I'd be much more concerned about my password than my credit card.
- agwa 13y agoWell, name.com seems to be taking this in good humor on Twitter: "@HackThePlanet Can you just send a postcard next time?" https://twitter.com/namedotcom/status/332304801050271744 https://twitter.com/namedotcom/status/332304801050271744 "@xDictate Yes. It's been a huge pain in the ass, yet it's hard not to appreciate great technical savvy." https://twitter.com/namedotcom/status/332308994255384577 https://twitter.com/namedotcom/status/332308994255384577 Regarding elephants: "@BobSnooks Even though it feels like we're getting trampled by them, we still won't shoot." https://twitter.com/namedotcom/status/332232278078001153 https://twitter.com/namedotcom/status/332232278078001153 Hopefully this is an indication they'll be willing to release full details of the incident. In contrast, Linode seems to take their image way too seriously and refuses to say anything that might make them look bad. (Of course, not saying anything makes them look worse, but they don't seem to realize that.)
- windexh8er 13y agoName.com seems to be on the same path Go Daddy was 8 years ago (sans scantily clad women for marketing). I wouldn't appreciate the "humor" (Twitter) around this event if I were a customer. My only hope is that if anything like this happens to Gandi that they handle it with, true to style, no-bullshit transparency - spare the crap.