Hackers Stole My Website
medium.com
medium.com
So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own.
Stealing email passwords is easy. So easy. No matter how complicated your password is or how often you change it. 2FA is an easy, reliable way to make it orders of magnitude harder for any attacker to breach your account.
I know I'm preaching to the choir here on HN but I'm just flabbergasted this didn't make it into the article.
And step #3 is to keep all your softwares up to date; OS, antivirus, browser, your WordPress, its plugins, your Notepad++, WinRAR, firmware of your ADSL modem, other computers on the network, BIOS, smart TV etc. Everything should be updated to the latest version.
Hyperbolic sarcasm aside, keeping on top of security is starting to feel like Alice and the Red Queen -- it takes as fast as you can run just to remain in place. I'm starting to feel a bit more sympathy for those who give up on good practices and start using the same password/pin everywhere and pray that ill will never befall them.
What do the rest of you do? Only use webmail with 2FA, disable all other access? That seems onerous.
What this means is if you enable 2FA for your gmail account, you can generate a one-time password to authorize any client which does not support a 2FA auth flow. This password is then destroyed by both parties.
If you run your own email server, I think you are at low risk of being attacked in a more general phishing net. An attacker targeting you personally still has many options but that is much less likely.
I don't quite understand this. Won't the email client need the need the password every time to auth with IMAP?
See eg gmail: you can't set up 2fa without supplying a cell (you will be allowed to remove it later, but how many know to do this?) Your phone number is trivially stealable -- see eg youtube video of people just stealing phone numbers with a crying baby and a sob story. https://youtu.be/F78UdORll-Q?t=133
Also, lots and lots of places have trivial routes around 2fa because people losing their password and/or 2fa is an order of magnitude more common than theft.
https://support.google.com/accounts/answer/6103534?hl=en&ref...
It hardly makes your life more difficult, and it does help at least a little bit. So it's worth setting up.
See eg @deray getting hacked.
GMail, for instance, will not allow a password reset with just a phone pin.
That seems like the kind of thing that'd get you on an intelligence agencies watch-list..though these days it's rather hard to find something that wouldn't.
It also happened to me to loose a smartphone without PIN, and I never thought it would happen and I kept postponing that simple step.
Maybe this time I should listen.
Also, if you lose your phone, you can make use of your recovery code.
After I have read this post I wanted to actually enable 2FA right now, but then I discovered that breaking news, terror attack, and again I postponed, the same like I postponed securing my phone with a PIN.
Even better, use a password manager.
> 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking.
Not necessary, use an up to date computer with Windows defender turned on and create a non-admin account for your kids.
> 4. Have antivirus software on your computer
Only use Windows defender, which is what the security community recommends.
Also use 2FA on all services which offer it.
Regarding the domain registrars, I would recommend Namecheap. They have a great support team and also offer 2FA, but I think it's only SMS based 2FA.
This way it's safe to store the database in the cloud without having to worry about attackers trying to brute force my master password if Dropbox gets compromised (since they'd also need the key file, which is only stored locally), and even if the key file is stolen the attacker would still need my master password to access the database.
KeePassX is recommended sometimes too, but is definitely for the more technically-minded.
There's a low level of distrust for Lastpass.
It's really great software, but I don't feel valued as a customer at all.
It is a cross platform PW manager with Browser extensions (i only use it on macOS with FF and Chromium, though), which does NOT store your passwords in the cloud.
You can sync the database via Cloud storage providers/webdav/usb stick. I really like to be in control of where my passwords are stored.
Sharing of passwords (business usecases!?) is not supported afaik.
I do have yubikey keyfob but sites that are supporting it are very few unfortunately. Gmail being one, which is great.
Real 2FA uses a token generator device or an app like google authenticator which does the same thing. This is a real "something you possess" as it can't be compromized without getting access to the device.
> Only use Windows defender, which is what the security community recommends.
Just don't use windows.
This article reads like an AOL scare from 1995 directed at my grandma.
Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash
- - -
But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience?
The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking to stop a wire transfer, hardly a sting) was successful. It's a long-winded rant about HostMonster and GoDaddy being shitty. We already knew these things. If the article was just focused criticism on GoDaddy or clear advice on web security, I wouldn't be so hash. Whatever educational benefits there were in article are lost with the writing.
This has got to be on the front page because of some shilling.
Also, HN Guidelines ask you not to suggest people haven't read the article. If you don't like the article, flag it or make a constructive comment (which I think you did) and move on.
In the 2000s, domain hijackings were very common (as tedunangst mentioned):
http://www.metafilter.com/3789/Adobecom-gets-hijacked http://archive.wired.com/politics/law/news/2000/04/35674?cur...
Later on, it became short Twitter accounts:
https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
https://www.wired.com/2016/06/deray-twitter-hack-2-factor-is...
If your metric is how informative an article is, the above two links about Twitter accounts being hijacked are much more educational than original blogpost.
I think the downvotes are because you're accusing the submitter and the people upvoting this article of shilling based on nothing but circumstantial evidence, not because of your opinion on the quality of the linked article.
People have time to constantly use Twitter/Facebook/YouTube/Reddit/Tumblr/internet forums in general, they can easily post an article on Hacker News once a day.
Some of the other advice in that section is also rather questionable. (E.g. "Your password should not contain “real” words".)
Even Bruce Schneier recommends you do that[1]. The idea is that if your machine is a spambot and you don't know it, there are fewer windows of time where your machine can be blasting the Internet with spam. Or if there's some network-based exploit, you're not vulnerable while your device is off.
1. https://www.schneier.com/blog/archives/2004/12/safe_personal...
How old is that article? Sounds like this is from the days back when dial-up was still popular.
I guess there may be some marginal increase in security by turning off your computer like this, but I don't think it's the kind of thing most users should be worried about.
> if your machine is a spambot and you don't know it, there are fewer windows of time where your machine can be blasting the Internet with spam
If your machine is part of a botnet, you're already compromised and turning it off when you're not using it isn't going to fix that. It might marginally help _other_ people getting DDoSed or spammed by your PC, but it won't improve your own security.
> Or if there's some network-based exploit, you're not vulnerable while your device is off
I guess. But unless you become aware of the exploit and take measures to mitigate it before turning your PC on and connecting it to the internet, leaving it off when you're not using it is unlikely to help with this - you'll just be compromised as soon as you turn your PC on. Not to mention that the kind of zero-day that would allow compromising a fully up-to-date PC with nothing more than network access to it is extremely rare.
I'd argue the security benefits of leaving your computer on so it can auto-install security updates while you're away probably outweighs any marginal benefits you might get from turning it off when not using it. (Though either way the difference is extremely minor.)
While currently it would take a state actor to do this eventually this will trickle down into to the hackers.
Looks like it got a good number of shares and good velocity so makes sense to keep milking it for what it's worth i suppose.
Btw, GoDaddy's response: http://news.softpedia.com/news/GoDaddy-Defends-Itself-in-Ram...
Can you really stop a wire transfer? I thought the whole point of wires is that they are immediate and irreversible?
Also, couldn't the FBI track the bank account info back to the thief? Or I guess it's possible the bank account is opened through a stolen identity. I guess the smartest thing the thief could do is then use that money to buy crypto and eventually funnel that back to his real identity.
How do you place a stop on a wire transfer? I thought irreversibility was the whole point of wire transfers.
What I do think works is reporting that the money was involved in fraud and freezing the money in the destination account, subject to the destination banks cooperation with the source bank and FBI.
https://www.quora.com/Can-wire-transfers-be-reversed-in-case...
However, author seems to know wire transfers as well as she knows internet security - which is not very well. You can trace the wire into the destination account, but if that person moves it immediately and eventually withdraws it out of the banking system, then it's gone. The hacker wouldn't release the domain unless they had control of the funds. I doubt her claims that the hacker doesn't have the money.
This is my story
I enabled 2FA i don't why. I think i read somewhere, how someone got there domains stoled.
Last month ago, I got a text message out of the blue, I googled the number and it was godaddy service.
So this person had got my username and password in godaddy and hit the 2FA, godaddy uses customer IDs and the password i use was a old password but one i didn't use in any other service.
So someone is running through all the customers Id numbers with a password dictonary because i knew this password was on one of those leaked password dictionaries.
They can do this because the godaddy site doesn't lock the account out for 24 hours after 5 wrong times. The hacker can try different combinations multiple times.
This is a major flaw on there site.
Then sometime in 2016, I noticed that the domain didn't belong to me. I tried to look up my history of purchase, there was no such purchase record in my account.
Unless my memory fooled me (which I just can't believe), the whole experience made me really confused.
>I didn’t exactly understand why it was such a huge deal.
>Couldn’t you just explain to people what had happened, prove who you were, and sort it all out?
>it seemed completely impossible to me that someone could actually get away with pretending to be someone else with any real consequences beyond a few phone calls and some irritation.
I have nothing to hide...
"The only thing necessary for the triumph of evil is for good men to do nothing." - Edmund Burke
Then, she contacted the FBI, who gave her an interview and basically did not much, and then she got her domain back by paying for it and then putting a stop on the money transfer? And this is worthy of a Sandra Bullock movie?
Yeah, real nail biter there.
This is just content hacking to get me to read more of the article so she can make more money on medium. I feel a bit cheated.
How did she found out it was a man?
After the loss I moved my own domains to google domains which at least has 2fa to access.
Here is some info from a quick search: https://security.stackexchange.com/questions/6095/xkcd-936-s...
The comic advises using correct-horse style passwords rather than tr0ubaDour-style. That is good advice.
A 7 word diceware passphrase would be a good idea.
> Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense.
Isn't it generally accepted that the XKCD-style "correct horse battery staple" passwords are more secure?
So true! A $100 unrooted Android tablet is almost infinitely more secure than the windows/mac, even with the best antivirus. Or if you like physical keyboard (I do), get a $300 Chromebook and do all your banking there. Just don't login with your primary google account, or someone may install evil chrome extension on it.
My point is, if you want to check online banking, your tablet (ipad|android) is much more secure than your (windows|linux|mac) laptop. For example, here is how I would explain Android security to someone non-technical: "Do not ever enable 'unknown sources' setting, and always refuse if it asks you something about installing a keyboard". Try doing the same for full-featured laptop.