GoDaddy Security Breach
sec.gov
sec.gov
From the official GoDaddy statement:
Using a compromised password, an unauthorized third party accessed the provisioning system in our legacy code base for Managed WordPress.
-
This could have been an easily avoidable data breach.
> We, GoDaddy leadership and employees, take our responsibility to protect our customers’ data very seriously
So that makes it okay right ?
Static passwords are bad, for sure. But do you have a source for this?
https://www.verizon.com/business/resources/reports/2017_dbir...
For everyone not going to go to the PDF, the text is "81% of hacking-related breaches leveraged either stolen and/or weak passwords."
So I'm not sure that you can say that all data breaches are related to static passwords, but it sure a big number and a problem.
I looked at the 2020 Verizon report, but unfortunately they changed their methodology or reporting so I didn't see a figure for that year for "hacking-related breaches".
Nobody said that.
What I should have said was "So I'm not sure that you can say that ~80% of data breaches are related to static passwords, but it sure a big number and a problem" because:
* hacking-related breaches != data breaches and
* stolen and/or weak passwords != static passwords
But the bigger point stands: passwords are a problem.Page 5 in the executive summary:
https://www.verizon.com/business/resources/reports/2017_dbir...
Not credible. There should be some odd number of tenths: 78.3% is clearly more credible than 78%
Like Twitter has done it https://en.wikipedia.org/wiki/2020_Twitter_account_hijacking ?
It is super easy to give lessons after the fact
We had to call GoDaddy and cancel the domain transfer, they would give us no information on how it happened.
Network Solutions -> GoDaddy -> Namecheap -> Google Domains OR CloudFlare Domains
Seriously, if anyone is still using Netsol or Godaddy, there are much better alternatives, and it's very easy to make the transition- I've helped a good handful of friends.
I'm talking about google domains itself, at the DNS level, will hijack your ENTIRE example.com domain and redirect to a safe browsing page.
I suppose in the end any domain provider could do the same.
https://news.ycombinator.com/item?id=22001822
Now I use cloudflare. No BS, no up-charging, fast, easy, and automatable.
• Up to 1.2 million active and inactive Managed WordPress customers had their email address and customer number exposed. The exposure of email addresses presents risk of phishing attacks.
• The original WordPress Admin password that was set at the time of provisioning was exposed. If those credentials were still in use, we reset those passwords.
• For active customers, sFTP and database usernames and passwords were exposed. We reset both passwords.
• For a subset of active customers, the SSL private key was exposed. We are in the process of issuing and installing new certificates for those customers.
Oh dear. No mention of 2FA mechanisms here. So does that mean GoDaddy's security is not good enough or is in fact very poor?No different to Epik's security breach I guess, but not the worst security breach I've seen in a long time when compared with Twitch [0].
They used to randomly call us, and then ask US to verify our accounts, passcodes in order for them to tell us a domain was close to expiration.
Not an email. An unsolicited phone call where I have to validate my information.
I told them that was phishing 101 tactic and a bad practice to train users on. And if a call is standard, a user may reasonably assume an email may be too.
Ultimately they just removed my from their call list.
It was one of the most asinine things I’ve seen. It reminds me I need to move my companies domains to hover.
(Via https://news.ycombinator.com/item?id=29311286, but no comments there)
The UI is so bad that just figuring out how the contact info they collect in multiple places is used is near-impossible.
Security incidents are going to happen. This particular incident looks to be avoidable (static passwords!). What we should judge the company on is their response and transparency. GoDaddy disclosed, but a new customer on the site wouldn't find this. They also used phrases like "affects our Legacy WordPress Platform" probably to attempt to shift a little blame from the current team or minimize the fall out.
When you have a security incident, be transparent, own it, and deal with it. We can tell when you are trying to sweep it under the rug and hide, and that's bad. This is an opportunity for an org to show that they put customers first and shine.
That might be the only reason we’re even reading about this at all.
This is typically by design and public relations 101. If you don't link "bad" content to your domain it's easier to make it disappear in the future. It's why a company purchases "our-data-breach.net" to handle a public incident instead of just a sub domain or deeply linked page. No long-lived anti-SEO
Amyone who has registered with them knows this.
Go with Goole for $13. You will never hear from them. You won't have to worry about drug fueled marking bs, or unethical behavior.
If I had any choice, though, it'd be Gandi or Namecheap.
Edit: Whoops, CRR operates certain gTLDs, Google LLC operates the buy-a-domain registrar.
Also a long time happy customer.
This is the title: GoDaddy Announces Security Incident Affecting Managed WordPress Service
Saying this is a breach sounds more generalized and makes exponentially more people click the bait to see if their domain accounts were hit (they weren't).
I also see namecheap being recommended a lot. Are they the go-to for domain name registration?
Also, I left because I thought their upsells and harassment were annoying.
The point of that list is to enumerate significant controversies involving GoDaddy, not just those where they look particularly bad.
Even today, I have one domain that I inherited that has been nearly impossible to transfer out, even after talking to support personnel. They keep blaming the receiving registrar even though all the evidence points to GoDaddy's system). I don't know if it's malice or incompetence, but it's kind of hard to tell the difference at this point and give then very real malice in their past, I'm disinclined to give them too much benefit of the doubt.
Lastly I can't prove it, but about 10 years ago or so I'm pretty sure they bought a domain name that I had been searching using their search tool but was on the fence about buying. When I finally did decide to buy it, it had been registered but was "available" to buy through GoDaddy at a nice markup. I saw online (at the time) several other anecdotes of the same thing.
For those wondering what I use now: hover.com has been great to me for many years. I do have an increasing number on Cloudflare as well.
Cloudflare offers domain registration now (not just transfers), and it's at cost, so I don't see a reason to not use it unless you need to set your own nameservers. That's a paid add-on with Cloudflare's registrar service.
They are not a company I would ever do business with on the basis of that alone.
I prefer Dynadot (US company). I’ve also heard good things about Gandi (French company). You can also transfer (but not register) domains to Cloudflare.
Some evidence, please.
But the GP's story is about identity verification; I don't see that as a particularly egregious "shenanigan".
Would maybe be defensible if they asked for actually verifiable information, like a dump of the cryptographically signed contents of your chipped passport (haha).
> For a subset of active customers, the SSL private key was exposed. We are in the process of issuing and installing new certificates for those customers.
Wow.. That's quite severe.. From September 6th to November 17th.. I wonder will they do a full impact summary after they figure it out internally.
I don't buy from companies with a bad history. It's not some kind of behaviour-modification strategy; it's just self-preservation.
I guess that was another part of their ‘legacy platform’?
I transferred the domain to Gandi which offers a couple of email addresses with each domain, something I kept putting off expecting GoDaddy to make it difficult, but it was fine.
But I do wonder how competent a registrar/web/email tech company is if they can’t run email services, and now apparently can’t run websites securely either? I spent a while mulling Fastmail and Rollernet and Mxroute vs paying for Office365 and thinking about how impossible it is to know if a company has the tech skills to back their product offering - and then if they actually do use them - or are just marketing.
For browser access to your mailbox, yes they did move to Office365 (free, not a trial), but POP3 and SMTP still work just fine, no change required.
I have been using GoDaddy for many years for a handful of domains, including my own business, and have had no problems using their interface and avoiding paying for add-on products.
After the move, I had to update my email client to connect to Microsoft servers for POP3/SMTP, it didn't keep working pointing at GoDaddy's securemail address.
Then after two months, they sent me emails saying "Your free trial is expiring soon" and "Urgent: you'll lose access to your email; you'll need to move to a paid plan from your free trial, or you'll lose access to your emails." and when I logged in to the domain management page, a banner saying I'd lose access to my email unless I paid $28/year for a Microsoft Office 365 emails basics plan.
So, if it did actually keep working no change, I'll chalk this up to another GoDaddy dark pattern, and the push to finally move me away from them.
Now that I recognize that, I suppose I see it as acceptable. My SMTP and POP3 mail service has continued uninterrupted, and when I log in to GoDaddy webmail every 3 weeks or so to check for spam that I care about, I just click on the "Outlook" web icon to see my mailbox via the web browser.
I've since moved off them and will never use them again.
RollerNet.us has a really nice setup, I've used them at work for years and they don't get much discussion on HN. They say "Roller Network accounts are very different from our competitors: we don’t charge you for domains, mailboxes, users, aliases, etc. All of those settings and configurable items are intangible items in our database. We only track tangible resources: data transfer, data processing, and data storage."
They do primary and secondary DNS (they will slave to your DNS servers), and SMTP relaying (they will be secondary MX and store and forward email to your higher priority MX if they go offline, or store and ETRN if you have some intermittent connection), SMTP frontend (forwarding and relaying and filtering), outbound SMTP relay, and mailbox server. They have a web interface to maillog and a simple REST API. It's just that they're not a domain registrar and their personal account is $50/year, and I have no personal use for most of the features; Gandi was $15 for a year of domain hosting and email, so it won.
Upon investigating I found out a turkish person was using my account for some scams with crypto alongside a few real-world websites he built for business in Ankara. I went to the police, gave them all the evidence (just so I'm safe legally from the scams he was running in my name, with stolen credit cards that were using my address - but in Ankara not my location), and GoDaddy failed to answer to the local authorities, after 1 year the investigation was shutdown because of lack of cooperation from GoDaddy's side.
I know that the company I work for was hit at least once by this, until we implemented stronger KYC checks.
I understand that it's easy to use from a writer's point of view (after you get it installed, or if someone else is installing it for you), and that there are all kinds of third-party plugins and support available, but man, that codebase is a gigantic steaming pile of technical debt.
> Our WordPress password was leaked or exposed--likely due to utter imcompetence--and no 2FA was in use.
Man, when can I become a Chief Information Security Officer? I could do a better job in my sleep.
when you're ready, you won't have to
Is NameSilo any better? I can't just go for OpenNIC domain because I have to have email accessible to other servers. :(
Never godaddy and never google domains.