Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tamar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
tamar
10y ago
Yep, it's said here: https://www.namecheap.com/support/knowledgebase/article.aspx...
32.
▲
by
tamar
10y ago
Re: Your edit - just a note, it is very clear here that in points 1-4, Namecheap has acknowledged a mistake. That's exactly why there was a lot of training (and retraining) internally to ensure this mistake does not recur. But we do
33.
▲
by
tamar
10y ago
It's not victim blaming. It's simply a reiteration that it helps to have this in place if you are specifically opting to rent/lease a server that does not offer it. Also, it's stated in the knowledgebase that it is advis
34.
▲
by
tamar
10y ago
That comment I made refers to data integrity across platforms. You should be smart about data, no matter where it arises, if it is important to you. For example, let me give you a look at what my Windows hard drive looks like. My important
35.
▲
by
tamar
10y ago
That's part of the whole issue. It wasn't simply an issue of retraining. The entire company is well aware of this issue and is using it to improve, not simply to reprimand a single person.
36.
▲
by
tamar
10y ago
No, they are offsite.
37.
▲
by
tamar
10y ago
I hate to break it to you, but "uniform" security standards that are out there in the open would be like a whole can of worms. That is like showing someone "here's a lock and what's inside of it." In time, some
38.
▲
by
tamar
10y ago
Hey Bill - when I was remote staff at AOL in the 90s, we had SecurIDs too (which is basically a key fob with 6 numbers that changed every 60 seconds, pretty reminiscent of 2FA on phones/Authy/Google Authenticator). Problem is if y
39.
▲
by
tamar
10y ago
I don't think it was personal, simply a reminder that it always helps to have good backup procedures in place. Even my managed services have offsite backups. Better be safe than sorry, I always say.
40.
▲
by
tamar
10y ago
If you have specific information, you are welcome to contact us with full details. Policies and procedures are in place to ensure no one falls victim to social engineering and as you call it, "intimidation."
41.
▲
by
tamar
10y ago
It wouldn't happen to you. As you may see by other comments here (written by @matthewdrussell), this was an isolated incident that occurred specifically to an already-compromised email account. Still, we could always do better, and t
42.
▲
by
tamar
10y ago
matthewdrussell is also commenting in this HN thread @movluro - he's Namecheap's CIO. I, too, represent Namecheap.
43.
▲
by
tamar
10y ago
It's true :) We hear about it on Twitter all the time that the same number we use for 2FA is also texting 2FA codes for the other services I mentioned. (disclosure: obviously I work for Namecheap.)
44.
▲
by
tamar
10y ago
There are identification methods requested via chat. Matt invited you to try it. Go for it.
45.
▲
by
tamar
10y ago
I guess take Matt up on his offer where he said this: "Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and wh
46.
▲
by
tamar
10y ago
And this is an argument for making sure your email provider has two factor authentication to avoid having an external breach that could give someone access to accounts that do not support 2FA.
47.
▲
by
tamar
10y ago
Namecheap has had two factor authentication and was the first provider to have it. Knowing public whois would not grant someone access to anyone's account at Namecheap. They'd still need to know your Namecheap username, your passw
48.
▲
by
tamar
10y ago
This was a self-managed server. Managed services at Namecheap have backups.
49.
▲
by
tamar
10y ago
Namecheap uses the same 2FA provider as Tumblr, Yahoo, Microsoft, and a slew of other services.
50.
▲
by
tamar
10y ago
Khao - the matter was addressed and the staff was retrained to close the gaps in procedure.
51.
▲
by
tamar
11y ago
Looks like things are working out right now - feel free to keep me posted. You know where to find me now ;)
52.
▲
by
tamar
11y ago
Hey romanhn - so sorry for this. Can you share your ticket number? I think there was a definite mistake in the process here as that should have been broached and if it requires some updated training for the billing team, I'll put in my
53.
▲
by
tamar
11y ago
Please see my comments above - there are ways around this but it appears that that path was never pursued.
54.
▲
by
tamar
11y ago
Not really a gotcha. Some TLDs require that early renewal and one month is how we handle to avoid any disconnection in service. But yes, if you move away after a domain is renewed (e.g. your domain expires in 2017, most registrars -- but no
55.
▲
by
tamar
11y ago
lpsz - Tamar from Namecheap here. We're working on the padding. It's not that it's falling on deaf ears; it's just that it's taking time for us to implement and QA. Also, the issue with all domains being shown is a
56.
▲
by
tamar
11y ago
Hey romanhn - did you contact support and try to make it right by reversing the chargeback? This isn't about blackmail as jewsin writes in the comments, it's about the reputation a business suffers with a chargeback. All you would
57.
▲
by
tamar
11y ago
I don't think we're making a blanket statement about "all free CAs" here. Encryption is one important aspect that free SSL providers offer, validation and trust is another that isn't offered by most.
58.
▲
by
tamar
11y ago
Hey - so I tweeted that...and to be very clear, nothing in that tweet should have been implied as a yes. But since it was potentially construed as a yes, it was deleted to avoid confusion.
59.
▲
by
tamar
11y ago
Hey - I'm Tamar from Namecheap. Our DNS is not down but we just upgraded our servers (see https://blog.namecheap.com/enhancing-our-dns-platform/ ). The issue you're referring to was fixed. Your issue is likely
60.
▲
Ultimate Guide to Getting a Software Engineering Job After College (8700+ Words)
(careerdean.com)
7 points
by
tamar
11y ago
|
0 comments
More ›