16 ms·
My website was stolen by a hacker and I got it back
- mcherm 13y agoI am curious: does anyone here on HN have a registrar to recommend who they know (preferably from experience) would actually be more helpful in this circumstance? Because from the sound of it, the unwillingness of the registrars (both of them) to take action here without being compelled to by a lawsuit is the root of the problem. The FBI's willingness to be helpful is nice, but doesn't solve the root problem, and as a law enforcement agency they can only really help in cases where they manage to "catch the criminal". And paying off the criminal just isn't an acceptable solution (although stopping the payment immediately is cool and all). I would be willing to select a registrar on the basis of their policies, not their prices. Policies like this sort of dispute resolution and policies about how they handle DMCA notices or government subpoenas (and non-subpoenas), if only I knew which registrars had the best reputations for these things.
- rajat 13y agoI second this. I'm beginning to hear more an more of this problem, and while this is anecdotal, it does seem to be increasing.
- shiftpgdn 13y agoLook at it from the GoDaddy's point of view: This woman is claiming she has rights to a domain in one of their customer's accounts. As far as they know it was legitimately transferred in by one of their paying customers. Her real issue rests with HostMonster and the ICANN dispute resolution system.
- unreal37 13y agoGoDaddy could seize the domain until the dispute is settled. If everyone recognized she was the previous owner, that should be enough to cause an investigation into the transfer. Not saying a claim from anyone should cause a seizure, but the legitimate previous owner should be able to dispute it for a time period. Domains are stolen all the damn time.
- shiftpgdn 13y agoI worked in webhosting for nearly a decade so I'm quite familiar with the volume of fraud and stolen domains. But to play the devils advocate how would you feel if somebody claimed a domain you own was stolen just to freeze your account and waste your time. You'd be furious at GoDaddy for freezing your account over a fictitious claim.
- philbarr 13y agoThey only need to freeze the account if the domain was moved very recently.
- dsrguru 13y agoThis. I want to upvote this comment a hundred times. If there's a dispute with probable cause, temporarily freezing the domain while launching an immediate investigation seems by far the best balance of thwarting domain theft and minimizing fraudulent claims.
- shiftpgdn 13y agoBy ICANN policy domains can only be moved once every 60 days. Did you want the domain name taken offline?
- dsrguru 13y agoI'm not very familiar with their policies. Does that apply even in the case of theft? Didn't the article's author recover her domain within a few days?
- shiftpgdn 13y agoIt's no matter what you are only allowed to move domains once every 60 days. It is to prevent somebody from stealing a domain and moving it through 10 different registrars to wash the history of ownership.
- rhizome 13y agoThe business goals of GoDaddy preclude them from giving a shit because they can't hire enough people to support issues like this.
- Geekette 13y agoNo, GoDaddy was never in doubt: "No one at either company questioned my statement (supported by written proof) that the website belonged to me. No one doubted that it had been transferred without my authority". So GoDaddy's refusal to help was ridiculous. At the very least, they could have frozen control of the site for a day or two while investigating.
- shiftpgdn 13y agoBy ICANN policy domains can only be moved once every 60 days. How did you want them to go about freezing the site? ICANN has a dispute resolution policy in place.
- Geekette 13y agoThey could have disabled access to it by the thief. The 60 day policy does not apply to cases where it is "being transferred back to the original Registrar in cases where both Registrars so agree ..." http://www.icann.org/en/resources/registrars/transfers/policy http://www.icann.org/en/resources/registrars/transfers/polic... And given that both registrars acknowledged that she was the real owner, I'd expect the transfer (to the thief) would not be counted as a legitimate one within that period.
- Cenk 13y agoNamecheap offers two-factor-authentication.
- notduncansmith 13y agoI've used Namecheap for years and they've been great for me (never had a situation like this happen though).
- foxylad 13y agoThanks, good to know.
- rafaelm 13y agoMoniker claims that they have never lost a domain. I've got several domains (over 50) registered with them and never had a problem in almost 8 years. Many of them belonged to high traffic sites that might be desirable to thieves. I also have many with Name cheap right now and haven't had a problem them either.
- coldcode 13y agoI use them as well and have had no issues; however just because two of us have had no issues, it's not much of a data point.
- phreanix 13y agoTrue, I'd be more interested in their actual resolution process and the steps they take to safeguard domain owners. It works both ways though I think, the same steps they take to secure your domain are the same ones that will make it hard for you to get it back.
- pkfrank 13y agoI use Moniker as well. I pay for their "Portfolio MaxLock" (https://www.moniker.com/domainnames/domainsecurity.jsp https://www.moniker.com/domainnames/domainsecurity.jsp) service. Whenever I want to make a change (even DNS), I'm forced to answer the security questions that only I would know. In order to get around that, I'd have to contact their security team directly and provide a substantial amount of identification. Aside from the security features, Moniker's site and technology seems to be fairly unimpressive. I'd definitely be open to exploring other options if people have suggestions for truly-safer registrars.
- lingben 13y agomoniker is not the domain registrar you want: http://www.dnforum.com/f208/warning-privacy-whois-issues-failures-moniker-com-keydrive-again-thread-505269.html http://www.dnforum.com/f208/warning-privacy-whois-issues-fai...
- Fuxy 13y agoI use gandi.net never had any serious issues with them and since their located in France (yes i intentionally avoided American companies) all this suing problem may not apply to them or at least it would be a lot more difficult. One thing is certain though most people i know have had issues with GoDaddy and avoid it like the plague.
- WildUtah 13y agoGandi now has offices in the USA, so they are effectively an American company as far as being subject to the US legal system and extraconstitutional orders from agencies and such. You won't get any privacy protection or immunity from illegal orders from Gandi.
- Fuxy 13y agoOh well off to find another good company for may gray area domains then. Too bad I liked them why are all of them going to America. I don't want my stuff subject to American laws.
- chris_wot 13y agoI think you mean extraterritorial jurisdiction. Extraconsitutional orders would be... against the U.S. Consitution and illegal :-)
- soulshake 13y agoGandi does have an office in San Francisco, but our registrar service is accredited and located in France. It is under EU law. Those who have been following the industry's responses to the massively reprehensible, illegal dragnet surveillance will know better than to take any company at their word as they swear up and down that they care about their users' right to privacy. So I know this will be taken with a grain of salt (hell, I take it with a grain of salt and I work here)... But as far as I know, and I've asked around, we _actually_ do protect our customers' privacy to the maximum possible legal extent. The day I find out otherwise is the day I no longer work here.
- zimbatm 13y agohttp://gandi.net http://gandi.net - I have never had my domain stolen but in general Gandi.net are good people and they care about their customers.
- jellicle 13y agoI lost a domain because Gandi refused to do anything about it; although I was well within the renewal period and tried to contact them many times Gandi refused to process any sort of renewal until it expired and was deleted by their system. Gandi ONLY accepts support requests through their web form (no email, no phone), and generally ignores those or provides nonsense answers several days later. As long as you never ever need any sort of support, Gandi is fine.
- soulshake 13y ago@jellicle, that doesn't sound like us. Can I look into your case further? If we messed up, we'll make it right.
- jellicle 13y agoThis was several years ago; what's done is done. I moved all my domains to another provider shortly afterwards. I'm not giving you another chance to screw me.
- Shinkei 13y agoYou publicly complained about their customer service. They have offered to right the wrong. You have a poor sense of fairness if you are willing to make a public claim and then aren't willing to address the issue when the company calls you out on it.
- jellicle 13y agoOh, the stupidity, it burns. What sort of righting do you think they could do, several years past the fact? Gandi refused to respond to their web form for a period of about four weeks or more; they let my domain expire and be deleted (if I recall, the only problem was that my credit card expiration date needed to be updated in their system and the charge processed). Besides the immediate hassle and serious annoyance of having an uncontactable company ignore their support form, it ended up costing me a few hundred dollars to buy the domain back from a domain speculator who snatched it up. What price should I put on that? What price is it worth to Gandi? Are they going to offer me a year's free domain registration with them? That offer has negative value to me; I wouldn't take it unless paid a lot of money to do so. Are they going to offer me a pile of money (no they aren't, it's not worth it to them). So what exactly are they going to offer here to right the wrong? The point here - which the top of this thread made, but maybe it wasn't explicit enough for you - is that services such as domain registration can easily have effects disproportionate to the cost of providing them. If all of Google's domains were deleted tomorrow, the cost to Google would easily exceed ($10 x number_of_domains). So a poor service experience can easily do more damage than the sum total of all revenue ever received from a particular customer. Thus the commenter looking for companies which try hard to provide good service. Gandi.net is not such a company, in my experience. (Hint: companies which provide good service have email addresses and phone numbers to contact them.) That's my only comment.
- mwww 13y agoDomeny.tv (http://www.domeny.tv/en http://www.domeny.tv/en) protects its login via 2FA: http://www.domeny.tv/en/two-factor-authentication http://www.domeny.tv/en/two-factor-authentication
- the_ancient 13y agoI use NameSilo 2 Factor Authentication and other security policies
- jypepin 13y agoI use iwantmyname.com and their service is amazingly good and fast. I never got my domain name stolen, but I'm confident they would do anything they could for me to recover it!
- frigg 13y ago>I would be willing to select a registrar on the basis of their policies, not their prices. Yes, absolutely this. I've searched through forums and read various reviews of various registrars and some say gandi is good, some name.com, some others, but at the end of the day nobody said "I've had this problem where my domain was stolen and this company was willing to help". I'm also willing to pay more for good support when serious problems arise.
- zaph0d 13y agonamecheap.com is definitely one of the best per my experience and what I have heard.
- zaph0d 13y agonamecheap.com is definitely one of the best per my experience and what I have heard.
- joshmlewis 13y agoI use DNSimple.com. They've been great and are quick at support.
- biot 13y agoI use EasyDNS. Here's why: http://blog.easydns.org/2014/01/29/welcome-to-easydns-press-1-for-support-press-2-to-get-the-last-4-digits-of-your-credit-card-number-on-file-here/ http://blog.easydns.org/2014/01/29/welcome-to-easydns-press-...
- caleb23 13y agoI would recommend Melbourne IT or Namecheap for what you are looking for. I would recommend you take advantage of WHOIS protection, two factor authentication, locking your domain at the registrar level (not just with Namecheap for example, but with the actual registrar), using strong passwords, etc. The company can only do so much, so make sure you do everything you can do as well to make your domains as secure as possible.
- Kiro 13y agoHow was it hacked? I find that info in the article except that they used HostMonster's email confirmation system somehow?
- shiftpgdn 13y agoSounds like it was just social engineered out of HostMonster. Almost all of the EIG hosts (HostMonster, BlueHost, iPage, HostGator, etc) use awful outsourced support that are only rated on amount of tickets closed/solved. They are very lackadaisical with customer information and verify accounts based on the last four digits of the card used. I'm guessing the "hacker" in this case guessed the last four of the card via livechat or a support ticket and then got in and moved the domain over to GoDaddy.
- chomp 13y ago"I remembered the notification from YouTube that someone had accessed my account from a different location – a notification I had ignored, assuming that I had logged in on a mobile device or that my husband had accidentally logged into my account instead of his own." All of her accounts were compromised - seems more likely to be malware than social engineering. Also the hosts you mentioned use in-house support.
- shiftpgdn 13y agoActually many of their support staff are outsourced through GlowTouch which is an Indian based support firm. It's in the EIGI S1 filing here: http://secfilings.nasdaq.com/filingFrameset.asp?FileName=0001193125-13-361255%2Etxt&FilePath=%5C2013%5C09%5C09%5C&CoName=ENDURANCE+INTERNATIONAL+GROUP+HOLDINGS%2C+INC%2E&FormType=S-1&RcvdDate=9%2F9%2F2013&pdf= http://secfilings.nasdaq.com/filingFrameset.asp?FileName=000...
- chomp 13y agoYeah, they are in charge of Hostgator India. They have no reach into the US based brands. Source: I work at one of the aforementioned brands.
- thejosh 13y agoSo apart from the 4 pretty much "how not to happen", try using a host that supports 2FA.
- astrodust 13y agoGot a list? It seems like every day GoDaddy is leaking domains. I've been using Hover a lot, but I'm not sure what their exposure is like.
- zrail 13y agoNamecheap does 2FA.
- potench 13y agoCurious why this is being down voted? Is it because namecheap does not offer 2FA? Seems to simply be answering the question above.
- r1ch 13y agoFor me, their 2FA is essentially unusable. It uses a UK SMS gateway (no Authy / Google Authenticator support) and out of the 20 or so times I've tried to set it up, only once has the code actually come through to my phone. I've had an open support ticket for 6 months, 3 months since the last reply.
- zrail 13y agoI just set it up (US cell phone) and it took less than 5 minutes end to end. Have you tried lately?
- the_ancient 13y agoNameSilo supports both Authy and Google Authenticator
- xeroxmalf 13y ago
- devanti 13y agoI'm curious as to how the FBI helped, because it doesn't really say in the article
- Fuxy 13y agoThey were considerate i guess and they asked a lot of questions. Not sure if they did anything useful but they certainly looked more interested then GoDaddy.
- deleted 13y ago[deleted]
- glimcat 13y agoI use Namesilo with Google Authenticator. (Probably other registrars support it as well, that's just the data point I have first-hand knowledge of.)
- coldcode 13y agoI never trust shared hosts provided by a registrar. I have my own blog software running on AWS and I am the programmer and only user. The fewer people involved is better security but that's not generally possible for the average person. At least I can't lose both the domain and the content.
- noonespecial 13y agoI feel for her but I do need to point out that some of the suggestions she makes for making it easier to get her stolen domain back would also make it easier for bad actors to cause mischief in the first place. But GoDaddy sucks. True dat.
- poopsintub 13y agoGoDaddy has two-step authentication. If you make any type of money off of a website or other account, you should use two-factor authentication. Facebook, email, and godaddy would be a decent start. A similar incident occurred when the man lost his $50k? twitter account because he didn't use two-factor anywhere.
- the_ancient 13y agoGodaddy also has proven their Phone Support personell are easy victims to social hacking, which negates any electronic security. If I can call up godaddy and have them change account details or the mobile number on the 2 factor settings then your 2 factor security is pointless. GoDaddy may have great electronic protections, but I do not trust their phone support personnel at all
- quackerhacker 13y agoIs there any domain register that offers 2 factor authentication to make changes that are detrimental to a site? I have Network Solutions, KVC Hosting, and have tried 1and1, but all of them...from a security standpoint...are lackadaisical when it comes to security. Network solutions WANTS their clients to bundle userid's into 1 account...that makes it easy. KVC, I emailed them to update my domain contact info, then I transferred one of my domains out with that new email. I never did any test with 1and1...but then again the 2 above (with kvc and netsol) weren't even tests. Another security breach involving GoDaddy(1)? (1): Naoki lost his twitter (https://medium.com/cyber-security/24eb09e026dd https://medium.com/cyber-security/24eb09e026dd)
- toomuchtodo 13y agoNamecheap.com uses 2FA. http://community.namecheap.com/blog/2013/10/08/two-factor-authentication/ http://community.namecheap.com/blog/2013/10/08/two-factor-au...
- Shank 13y agoHover has 2fa as well.
- tombrossman 13y agoGandi, mentioned several other times in this thread, also supports 2FA. https://wiki.gandi.net/en/contacts/login/2-factor-activation https://wiki.gandi.net/en/contacts/login/2-factor-activation You can also create a second account there and delegate limited rights to it for making changes. The odds of losing both accounts are remote.
- resistor3672 13y agoGandi also does IP restriction: http://wiki.gandi.net/en/contacts/login/ip-restriction http://wiki.gandi.net/en/contacts/login/ip-restriction
- orjan 13y agoEven Dreamhost has two factor authentication.
- kevinchen 13y agoI'm unsure why this is relevant to a site like HN. People are compromised all the time. It's not news. It's not even helpful for avoiding the same mistake: the author does not tell the details of the attack and gives some pretty bad advice for avoiding "cyber hackers" (such as turning off your computer to prevent your email getting hacked).
- quackerhacker 13y agoI agree with you with the "bad advice," opinion. There's no glamour or valor with how she got her domain back. In reality...it appears from her article that she really just paid to get it back. So I guess her suggestion is to have $30k stashed to make up for lack of security. From what I read...she's still out money, even though she did get her domain back.
- graedus 13y agoShe retained the money. And then I called the wire transfer company and placed a stop on the payment. It's unclear to me how this works. At first, it seems as though she and Anthony pursued this action independently, which would seem quite risky: risk of the apparently-fraudulent stop payment not being processed in time, or at all, resulting in the loss of 30k; risk of legal action from the seller, however seemingly ridiculous and unlikely, is scary. Later it sounds like maybe this was done with the FBI's blessing (point 5 under "Here's what to do").
- quackerhacker 13y agoI don’t have my money back yet, but the man who stole my site from me doesn’t have it, either, and won’t be getting it, ever. I don't think she got her money back, it may be held, but the method in which she got her domain back involved money transfer. The FBI, was really just sprinkled in the article. I understand the shock in how they handled the case immediately taking statements, but the resolution she had involved her money to get her domain back.
- akcreek 13y ago
- lutusp 13y agoThe most unfortunate part of this story is that the site owner had to use underhanded tactics of her own to regain control of her site. She didn't get her site back by going through formal legal channels, she got it back by using tactics similar to those used by the criminal she was dealing with. Different intent and legal standing, but same methods. It would be interesting to know what would have happened if she had instead waited for the legal methods to play out. Instead, it's a story of one trick undoing another trick.
- mannykannot 13y agoThat's a more unfortunate part of the story than the registrars' inaction? Or the theft itself? I don't think so.
- lutusp 13y ago> That's a more unfortunate part of the story than the registrars' inaction? Okay, fair enough, I'll give that fact a close second in the rankings. But to me, the fact that she had to descend to the level of the criminals she was dealing with, had to do things that under slightly different circumstances would have made her a criminal, is the most discouraging part of the account.
- jstalin 13y agoI don't see how much she paid to get it back. A civil suit filing with a demand for a temporary restraining order and preliminary injunction could be filed in a few hours and since godaddy and hostmonster are US companies, they would have had to comply. She'd have her domain back in a matter of hours for maybe a couple grand.
- ShaneOG 13y agoShe didn't pay anything. She stopped/cancelled the wire transfer
- sireat 13y agoThis was the most interesting (unique) thing about the whole ordeal. I did not realize that wire transfers can be cancelled after the receiver has already had the funds placed in the account(else the thief would not have released the domain).
- jacquesm 13y agoIt's an escrow service, not a wiretransfer company. The bit that I don't get is that escrow.com (the one party that didn't actually do anything wrong here) now has acted in a way which they probably should not have done, from their point of view the transaction actually is legit (buyer has control of the domain name, so funds should be released). If Escrow.com can't be trusted to release the funds when the recipient has the goods then what point is there to use them in the first place?
- epsylon 13y agoThat's what surprised me as well, but maybe the FBI intervening in the case was what pushed them to not honor the wire transfer.
- nick_14 13y agoI use Escrow.com a lot as a domainer, so I was initially concerned that a hold could be placed on the wire transfer after receiving the domain. The whole point of Escrow.com is that you are not able to cancel wire transfers and run away with my domain. However, it looks like they were operating under special circumstances due to the FBI investigation. Brandon Abbey is the president of Escrow.com and said “Escrow.com is holding the funds based on the proper legal authorities filing the necessary paperwork with the judicial system. We strictly follow the Escrow Law. That is what licensed escrow companies do.” Looks like it was just not explained correctly in the initial article.
- whileonebegin 13y agoIsn't escrow.com supposed to prevent payments from being stopped after the domain is released? Obviously, in this case it's justified, but for regular customers, you don't want escrow releasing a domain and then the buyer stops payment.
- eli 13y agoI believe the thief demanded payment first, outside of escrow. Which seems odd considering they actually did return the name. Maybe they were afraid Escrow.com would determine the domain was stolen and simply return it to its owner?
- DEinspanjer 13y agoTotally guessing, but it might be the thief was getting antsy and wanted to conclude a deal quickly. Maybe they did in fact have another buyer on the hook. Rather than spend all the extra time going through escrow and the potential risk of the buyer doing exactly what she intended to do (rely on raising the dispute of the domain after escrow had both halves of the transaction), the thief tried to pressure a quick sale through less regulated means. From what I understand though, it isn't all that easy to actually stop a wire transfer once it is being processed. I wouldn't be at all surprised to hear that both sides might have actually gotten the money and the backing bank will be left trying to go after one or both of them for it.
- akcreek 13y agoThe buyer can't stop the payment as the wire is already complete and money in escrow.com's account. Escrow.com had to stop the payment and in this case they did so because there was a request from law enforcement.
- DavidAdams 13y agoYes, I'm pretty sure this is where the FBI comes in. So the solution to this is: you agree to buy back your stolen property using an escrow service, then the FBI tells the escrow service not to release the money to a thief. Eventually you get your money back.
- zacinbusiness 13y agoI am absolutely shocked at how simple it is for this sort of fraud to take place. If someone calls GoDaddy, for instance, and says "Hi, I'd like to transfer a domain name. Here's all of my proof that I am who I say that I am." I understand that GoDaddy, ever dutifully obliged to their customers, will transfer the domain with haste. However, should there not be some sort of probationary period? 45 days or so where both GoDaddy and the new "owner" of the domain both have full, master control? It seems to me that an account manager in GoDaddy could handle this task easily enough. Simply coordinate with the new owner, notify that there's a dispute, and lock everything down until a resolution has been completed. Am I missing something here or are these companies simply lazy and unmotivated?
- harvestmoon 13y agoThe author did not mention that you can pay extra money to lock down a domain. If it is locked down, it can not be transferred without, iirc, a picture of your driver's license or something like that. There may also be time delays. For my valuable sites, I pay for this service.
- rwallace 13y agoThat sounds like a good idea. How do you do it?
- harvestmoon 13y agoQuote from GoDaddy: Go Daddy offers Protected Registration, which prevents a domain name from being transferred to another registrar. The product includes our privacy service, as well as a Deadbolt lock. Our Deadbolt lock means that in order to cancel the service, you must show documented proof of your identification, which makes the lock more robust than a standard registrar lock. This may seem “cumbersome,” but that is the point; if the domain name is valuable to you, you would be well-served to use product that safeguards against making it easy for a hijacker to gain access.
- euphemize 13y ago> 1. Have a really, really good password, and change it often. Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. http://xkcd.com/936/ http://xkcd.com/936/ But really, I'm a bit puzzled by her 5 "recommendations". Turn off your devices while you're not using them? I feel like the most important one is missing - don't use HostMonster or Godaddy, their representatives are not paid enough to care about the implications of you losing your domain name.
- arh68 13y agoUse PwdHash, it only improves the situation. [1] Even a bad password like "123456" turns into "rY9RHtJZ" (for HN). Turning computers off seems weird, but if that computer's got your ssh keys or your cached passwords, off is safest. [1] https://www.pwdhash.com/ https://www.pwdhash.com/ > don't use HostMonster or Godaddy http://internetshitlist.org http://internetshitlist.org is free for the taking :)
- lelandbatey 13y agoTo follow up, I will say that my favorite way to create a password is to use sayings from two or more of your favorite books or other sources. So, if you like Harry Potter and Enders Game, what are the phrases that come to mind? Harry Potter - expelliarmus Enders Game - win all the future fights Now you have a great password: "winallthefuturefightsexpelliarmus" Nice and long (33 chars), with some made up stuff. Maybe tack some numbers on the end.
- TazeTSchnitzel 13y agoMore modern guessing methods might try that one.
- pilom 13y agoModern password crackers are pulling all of wikipedia and youtube for seed words. If your words are in either of those, don't expect the password to stand to a dedicated attacker
- driverdan 13y agoDon't the companies have the lawsuit issue backwards? By not helping aren't they opening themselves up to being sued whereas if they immediately fixed the problem the person would have almost no reason to initiate a law suit.
- lingben 13y agoHere are 3 simple changes that can prevent this: * use 2 factor authentication (if your registrar doesn't find one that does or better yet, have ICANN rule that all registrars must have it) * ICANN rule that says if a domain has been recently moved it can be frozen by previous owner until the matter is cleared up * whois privacy will not only hide who the owner of the site is but also who the registrar is (if you don't know who the registar is among the hundreds out there, you can't target the right one with social engineering!)
- pjbrunet 13y agoWelcome to 1999. This reminds me of when sex.com was stolen with fake stationary. I see the "unauthorized transfer" in the blog post but I wonder if she forgot to renew the domain? Happens to good people all the time. I'm not a lawyer, but in that case, unless she's incorporated as "ramshackleglam" there's no cybersquatting argument. That's why it's helpful to use your real name--then a thief has no leg to stand on.
- andrewljohnson 13y agoSimple way to secure your passwords: * 1) Use 1Password to generate and store them * 2) Use DropBox or similar to share your encrypted vault between your devices * 3) Secure your shard vault with a strong computer-generated password, and keep it written down somewhere I wonder why strong password management isn't built into operating systems, thus educating everybody and making them ubiquitous. What am I missing? Where is MacPass? WinPass? The advice on the blog and this comment thread isn't any good, but there's really no good advice besides use a password manager.
- axman6 13y agoOS X/iOS have cross device password syncing using keychain these days.
- joshmlewis 13y ago> 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Or don't let your kids use your work computer when you have very important privileges at stake? I would definitely keep all of this in a very encrypted environment that isn't accessible by my kids or anyone else.
- genofon 13y ago-Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense I think this is a bad advice. You only need long password that are not feasible for a brute force attack and not trivial (personal data). If you have a password you can't remember you are going to write it somewhere and that can be a security issue
- zackmorris 13y agoI wonder if her or her husband ever accessed any of their accounts using their cell phones. I've seen tons of stories lately about Samsung Galaxy phones being compromised so at this point I just assume that if top of the line phones are pwned, then all cell phones are. I'm kind of shocked that there have been no class action lawsuits on phone manufacturers. Especially from banks.. just imagine the liability of millions of customers getting keylogged no matter what the bank uses to secure its site (even two factor authentication). It's almost unfathomable. Someone really should make a one time pad login that doesn't work a second time even if you look over the user's shoulder. For example their password could be their favorite song and the site would ask them to enter the 2nd, 3rd and 4th letters of the 5th, 6th and 7th word respectively or something. Or how about a custom grid of letters printed on the back of the phone they’d look up positions on so it would have to at least be in someone's physical possession. Or how about a dongle in the headphone jack that's hardcoded and can't be hacked, that the user would type rolling codes through. There has to be a better way of doing this!
- ChuckMcM 13y agoIt is not reassuring to see the level of compromise, the cost of disclosure, and the abuse of antiquated protocols rising faster than the institutions that depend on them can respond. In particular there was a lot of resistance early on to using credit cards on the Internet, now it is nearly compulsory, and yet many of the fears that banks and others raised in the early days of e-commerce are coming to pass. I have to believe there are some seriously rich criminals out there. What do they expect to do with their ill gotten gains?
- abshack 13y agoI'm partial to the "t33nz 1o1 \o/" cipher. input: correcthorsebatterystaple output: ~~krct^hrs333bttstpl$$:) input: password output: lulz!isma:PASSWORD#sorrynotsorry
- lhgaghl 13y agoThis is why corporations with 12 million users need to establish personal relationships with every client. If that was the case, they'd have just known she was the real owner.
- leccine 13y agoI can't understand why people still use GoDaddy. They lose domains to hackers every week, you can just call them and they are more than happy to change contact information or email address for you. Freakin' amazing.
- Casseres 13y agoI once called a registrar (that I've never heard of before or since) to inform them that a domain they registered was missing WHOIS data, they asked me what I wanted to put in for the WHOIS data. I facepalmed. While I wanted the domain, I wasn't going to steal it.
- caleb23 13y agoThis has a lot of good information in it and I put a lot of time into it, but I do realize it is hard to read since Hacker News doesn't start things on new lines. If someone can tell me how to do that if it is possible that would be great. If not here it is on Pastebin - http://pastebin.com/MspKq8sz http://pastebin.com/MspKq8sz. Here is what I recommend for website security (this is a lot of advice and is not perfect - if you want me to write this up in a detailed blog post and cover more things let me know)... I also provided my contact information at the bottom if you have any questions or need any help settings this up. Domain Registrar: 1. Melbourne IT - https://www.melbourneit.com.au/ https://www.melbourneit.com.au/ 2. Namecheap - https://www.namecheap.com/ https://www.namecheap.com/ 3. Gandi - https://www.gandi.net/ https://www.gandi.net/ - Enable WHOIS protection - Enable domain locking - if you want more details on how to set this up let me know - Enable email notifications and make sure you keep your account information up to date - Log in from a computer using a VPN (I use and recommend proXPN - https://proxpn.com/ https://proxpn.com/) which encrypts your connection DNS 1. Any of the domain registrars mentioned above 2. CloudFlare - https://www.cloudflare.com/ https://www.cloudflare.com/ (offers performance benefits as well) Their DDOS protection, DNS, and performance benefits are why I use and recommend them. They are not very good in terms of their WAF or website security and that is why I use and recommend Sucuri as well. 3. DNS Made Easy - http://www.dnsmadeeasy.com/ http://www.dnsmadeeasy.com/ - Follow advice from passwords section - Delete unnecessary DNS records - Enable DNSSEC if possible Email Hosting 1. I recommend that you use Google Apps for Business - https://www.google.com/enterprise/apps/business/ https://www.google.com/enterprise/apps/business/. - Follow advice from passwords section - Take advantage of the security Google offers Passwords 1. Create strong passwords using a password generator. I use GRC's Password Generator by Steve Gibson. - https://www.grc.com/passwords.htm https://www.grc.com/passwords.htm 2. Store your passwords in a password manager such as LastPass. - https://lastpass.com/ https://lastpass.com/ 3. With LastPass use a strong master password, limit login attempts to your country and the ones you travel to frequently, use two factor authentication, don't use a password reminder, don't write down your master password - only memorize it and don't ever share it, change your master password at least slightly every 3 months, and disable logins from the TOR network. 4. Use the same password only once (Don't use the same password on multiple sites). 5. Don't store your passwords in the browser or save them, so you are automatically logged in. 6. Make sure your password is at least 15+ characters (I use 50+ characters) and it contains lowercase letters, uppercase letters, numbers, and special characters. 7. If a site requires a secret question, make sure the answer to that question no one else would know or make it a password or phrase that you would remember. 8. Use the browser add-on HTTPS Everywhere and use Mozilla Firefox or Google Chrome as your browser. 9. Try to not share your passwords - I would like to say never share your passwords, but I know that is not possible :). If you have to share your passwords, do so using LastPass, change the password after they are done, make sure they haven't done anything that looks malicious, have a clear plan of what they need to do, and ask them how long it will take them. Website Security 1. Backup your site - I recommend and use Sucuri Backups - http://sucuri.net/services/website-backups http://sucuri.net/services/website-backups (it is $5 a month per website) 2. Use monitoring, alerting, and a removal service - I recommend and use Sucuri - http://sucuri.net/signup http://sucuri.net/signup It is $89.99 per year for one website. The service includes 3 main areas which are monitoring (http://sucuri.net/services/website-scan-malware-detection http://sucuri.net/services/website-scan-malware-detection), alerting (http://sucuri.net/services/alerting http://sucuri.net/services/alerting), and removal (http://sucuri.net/services/malware-removal http://sucuri.net/services/malware-removal). You can use any of those links for further details. 3. Use a WAF - I recommend and use Sucuri CloudProxy - http://cloudproxy.sucuri.net/signup http://cloudproxy.sucuri.net/signup ($9.99 a month for the most basic plan - the two other plans are $19.98 and $69.93 per month) 4. There could be a lot more in this area, but that should do a pretty good job for you. If you are using a CMS such as WordPress, Joomla, or Drupal you have quite a bit more you can do in this area. Hosting 1. It honestly depends on your needs, so I am not going to recommend anyone specifically. If you want help with this or anything you can find my contact information at the bottom. Network Security 1. Use WPA2 for the encryption protocol 2. Make your network name random 3. Make your password to connect to your network very strong 4. Change the default login credentials to login to your network to a secure username and password. 5. Disable Wi-Fi Protected Setup (WPS) 6. Configure OpenDNS at the router level - http://www.opendns.com/ http://www.opendns.com/ 7. Follow the passwords section for your passwords Computer Security 1. Use a antivirus program (Antivirus for Mac by Sophos for MAC computers and Microsoft Security Essentials or Avast for Windows) 2. Use an anti-malware program (Malwarebytes Antimalware and Malwarebytes Anti-Exploit for Windows) 3. Use a firewall (Windows Firewall or TinyWall for Windows) 4. Keep your operating system updated 5. Keep your programs updated (Secunia PSI or FileHippo Update Checker for Windows and AppFresh for MAC) 6. Remove Java and Quicktime if you don't need them 7. Replace Adobe Reader with Foxit Reader or Sumatra PDF 8. Make sure you keep Adobe Flash Player up to date 9. Uninstall programs that you don't need or don't use 10. Only download things from trusted sources (the browser extension Web of Trust would help with this) 11. For your browser make sure you are using Google Chrome or Mozilla Firefox. For Google Chrome and Mozilla Firefox, I recommend that you use Adblock Plus, Disconnect, and HTTPS Everywhere). If you want to be very secure and are somewhat technical, I recommend that you also use NoScript for Mozilla Firefox and NotScripts for Google Chrome. If you have any questions you can email me at [redacted].
- deleted 13y ago[deleted]
- blueskin_ 13y ago>cyber hacking For when just 'cyber' and just misuse of the word hacking aren't enough. Edit: >assuming that... my husband had accidentally logged into my account instead of his own I think this shows her attitude to security could at best be described as lax. >3. Turn off your computer and personal devices when they’re not in use. I... this is... wow, what.