Name.com Tells Customers To Change Password Due To Breach
thedomains.com
thedomains.com
"@HackThePlanet Can you just send a postcard next time?" https://twitter.com/namedotcom/status/332304801050271744
"@xDictate Yes. It's been a huge pain in the ass, yet it's hard not to appreciate great technical savvy." https://twitter.com/namedotcom/status/332308994255384577
Regarding elephants: "@BobSnooks Even though it feels like we're getting trampled by them, we still won't shoot." https://twitter.com/namedotcom/status/332232278078001153
Hopefully this is an indication they'll be willing to release full details of the incident. In contrast, Linode seems to take their image way too seriously and refuses to say anything that might make them look bad. (Of course, not saying anything makes them look worse, but they don't seem to realize that.)
I don't trust "encrypted" password because my experience with Host Gator: I contacted Host Gator support to reset my password and they were able to send me my previous PLAINTEXT password. I asked them how this was possible and they told me that the passwords were encrypted and only a few people had access to it.
People who also have access to it: Anyone who can see the Host Gator email que and the mail-servers the email passed through.
I promptly closed my account with them.
They also only mention personal information theft, while there was also supposedly a risk of configuration changes to domains hosted there.... were they able to track any malicious changes? Or are they confident none happened? Or did they have no idea about the breach until HTP publicized it? More information would certainly help my confidence with them as a registrar.
I'm not happy that my domain registrar was hacked by a group that wasn't even targeting the company; it was simply the weakest link. Not good.
If your password is hashed, which it usually should be, then the service would not be able to give it to you. The reason services sometimes instead opt to encrypt instead of hash is for support reasons. Encrypting a password could be ok, as long as they never expose the password over something like email.
However, I disagree with you when you say, "Encrypting a password could be ok," because compromises happen and the attacker could do a memory dump, check the environment variables or perhaps find a location where the password is hardcoded (config or script, yes this happens). It's a sloppy practice that we should discourage. Hashing passwords is the most basic level of security and it's been known for decades.
I've seen _very_ few good reasons for encrypting passwords instead of hashing them - and that's certainly not one of them. Sure, "support" might need access credentials to my account - but it needs to be _their_ access credentials, not mine. Sure, you can build the infrastructure required to securely manage encrypted passwords and the decryption key storage - but you can almost certainly build an alternative system where support never need _my_ password instead.
Good!
I was curious what algorithm is behind the MySQL PASSWORD() method. According to the MySQL reference manual, "you should not use it in your own applications. For that purpose, consider MD5() or SHA1() instead."[1]
1: https://dev.mysql.com/doc/refman/4.1/en/encryption-functions...
Hint: I'm the head of ops, the password matched what I had set (16 characters, mix of letters, numbers and symbols, not used anywhere else).
Want to add an SSL certificate to a subdomain? You have to provide them your main account login, which is logged in plain text in their ticket system.
They also took it upon themselves to look through one of my databases because they thought it was taking up too much of my unlimited quota.
What would HN suggest doing in a case like this (aside from changing passwords)? Just let it be? Monitor credit card? Change registrar?
Looking forward to your feedback.
However I still changed my credit card since it was in the Linode database.
I considered changing registrar. But I really can't know to which one I can go. How do you know they won't be (or already are) compromised?
[1] - https://twitter.com/namedotcom/status/332260201535266816
FBI moles, compromise of a fairly large registrar, etc.
I suppose I don't understand why it's necessary to know if HTP was being 100% honest when the big details have been confirmed.
I wouldn't appreciate the "humor" (Twitter) around this event if I were a customer. My only hope is that if anything like this happens to Gandi that they handle it with, true to style, no-bullshit transparency - spare the crap.
However, Name.com has not disclosed much information. I don't know if they were aware of the attack until the group released their story yesterday. The systems could have still been compromised.
[1] https://blog.linode.com/2013/04/16/security-incident-update/