GoDaddy Breach Widens
wordfence.com
wordfence.com
0: https://newsroom.godaddy.net/newsroom/overview/default.aspx
Mine is copied below the line.
Here’s the rub though. We haven’t hosted any Wordpress with them, or anything for that matter. We only registered some Vanity domains with them. They aren’t even the registrar on our primary domains.
———————————————-
Dear Company,
We are writing to inform you of a security incident impacting our GoDaddy Managed WordPress environment you once purchased and used. According to our records your Managed WordPress account is no longer active.
On November 17, we identified suspicious activity in our WordPress hosting environment and immediately began an investigation with the help of an IT forensics firm and have contacted law enforcement. Our investigation is ongoing, but we have determined that, on or about September 6, 2021, an unauthorized third party gained access to your customer number, email address associated with your previously used Managed WordPress account; and the password you first used when setting up your WordPress Admin login.
If you use that same password for other accounts, we recommend you change your password to those accounts and adopt data security best practices, such as choosing a strong unique password, regularly changing it, and enabling multi-factor authentication where available. We also recommend that you remain vigilant for potentially fraudulent communications sent to your email address purporting to be from GoDaddy or other third parties.
For residents living in California, Colorado, Delaware, Illinois, New York, New Jersey, Oregon, Vermont, Washington, and Wyoming, please visit https://www.godaddy.com/help/a-41004 for additional resources that describe additional steps you can take to help protect your information, including recommendations by the Federal Trade Commission regarding identity theft protection and details on how to place a fraud alert or a security freeze on your credit file.
Thank you,
Demetrius Comes
Chief Information Security Officer
Seriously, why list out those specific states rather than just saying 'check our help guide available at https://www.godaddy.com/help/a-41004 for additional resources that describe additional steps you can take to help protect your information, including recommendations by the Federal Trade Commission regarding identity theft protection and details on how to place a fraud alert or a security freeze on your credit file.'?
Just seems a bit poorly thought through.
https://aboutus.godaddy.net/newsroom/company-news/news-detai...
EDIT: OK, well maybe not proper. They'll add your domain to the Letsencrypt cert being served there I guess (since mine is listed in the list of valid domains on the invalid cert for your site).
"GoDaddy was storing sFTP credentials either as plaintext, or in a format that could be reversed into plaintext."
Goddamn, anyone else, feeling a deep anger rising, when reading this in 2021? "According to the report filed by GoDaddy with the SEC..."
In 2021, everyone has to be pissed off by javascript popups about cookie storage, but your passwords safety, screw that. Storing SFTP passwords reversible to plaintext, that's still fine, right?As long as there is a SEC report... We look professional!
Look at most of the stories on the front-page of HN these days. Often some shiny tool to allow front-end JS devs to write and deploy full-stack applications automatically upon commit. I guarantee you they’re making similar newbie mistakes. Instead of SFTP it’ll be a serverless endpoint that returns entire User records, unhashed password and all, without any sort of auth check.
I'd rather risk it with the newbies, modern stacks usually have good tutorials and standard solutions to most security sensitive problems.
Last time I dodged a product because its website looked like it was designed in the early 2000's it was SolarWinds just over a year ago..
I’m feeling nostalgic remembering helping clients migrate away from their breached shared hosting around the turn of the century, especially how this ended up being cheaper because GoDaddy was way over market rates.
And of course, every API key and secret was just hanging out in the repo as well.
Maybe the CEO should be required to be put in stocks in the town square or something. With no real penalty, there is no change.
I could Google it, but what else is bad with godaddy and should I switch?
*NOI if you’re reading this, Darren
As much as I am looking forward to getting away from them, I'm not looking forward to jumping through the hoops they'll inevitably put in my way.
I was shocked at how terrible their service and prices were. Whenever I renew a domain I'm met with an absurd stunt billing attempt. Support is horrible, they can't even do email with tickets. Instead they have a chat system which automatically closes and the support staff game it by stalling.
And then it's "well we bought five years so let's wait to renew it somewhere else"
You do realize you can transfer at any time after the 60-day ICANN change of registrant lock period, and it’ll just add to your five years at the new registrar, right?
Have been a very happy customer of WPEngine - and have had a lot of clients thank me for WPEngine's brilliant support.
Get 5 months free on annual shared plans, effective 11/22 - 11/30 - for cyber week.
Here's an affiliate link if you feel like supporting me. https://wpengine.com/plans/?coupon=cyberweek2021&SSAID=13835...
1and1 / IONOS isn't much better, and I'd recommend switching from them as well.
Hover.com FTW.