Slashdot Mirror


Name.com Resets All Passwords Following Security Breach

An anonymous reader writes "Internet registrar Name.com on Wednesday revealed it was hit by a security breach. The company sent an email to its customers informing them that their usernames, email addresses, passwords, and credit card account information "may have been accessed by unauthorized individuals.""

35 comments

  1. sounds similar to... by Anonymous Coward · · Score: 0

    the linode incident?

    1. Re:sounds similar to... by brian1078 · · Score: 1

      I believe this is the linode incident.

      I'm a name.com (and linode) customer and haven't received jack from them.

    2. Re:sounds similar to... by JonahsDad · · Score: 1

      I'm a name.com (and linode) customer and haven't received jack from them.

      They're being a bit slow about it. Just received my email.

    3. Re:sounds similar to... by kermidge · · Score: 1

      got mine about ten hours ago

  2. I am a name.com customer by Anonymous Coward · · Score: 1

    And I did not receive any emails from them today.

    1. Re:I am a name.com customer by Anonymous Coward · · Score: 1

      i did. check your spam folder

    2. Re:I am a name.com customer by Anonymous Coward · · Score: 0

      Kang: Hmm... Abortions for some, miniature American flags for others.

  3. My Password Wasn't Reset by Secret+Agent+Man · · Score: 5, Interesting

    I went in and changed it manually after I saw this, but it was never reset by name.com in the first place...

    1. Re:My Password Wasn't Reset by corychristison · · Score: 2

      My first thought was that it was a phishing attempt, but after inspecting the email I decided to go directlt to name.com amd do a password reset through the "I forgot my password" thing. Used my trusty KeePassX and generated a new 32 character password.

    2. Re:My Password Wasn't Reset by Anonymous Coward · · Score: 0

      Mine wasn't either.

      I didn't set up automatic renewal because the only way to use those free whois privacy coupons is to renew manually.

      Now I'm glad I didn't.

  4. Nothing new ... by Cammi · · Score: 5, Interesting

    This is NOT news. Name.com has had an annual security breach for a minimum of 5 years. This is not news at all.

    1. Re:Nothing new ... by quasius · · Score: 1

      I'm glad you're not concerned with it, but as a name.com customer, it does concern me and I'm pretty glad this story was posted so I could take action.

    2. Re:Nothing new ... by Cammi · · Score: 1

      You get notices already as a name.com customer, same as I as a name.com customer. You get emails with the following subject lines ... Failed Login Warning Request for Password Change Usually by criminals at the following ip address: 93.36.180.153

    3. Re:Nothing new ... by Jane+Q.+Public · · Score: 2

      "This is NOT news. Name.com has had an annual security breach for a minimum of 5 years. This is not news at all. Reply to This Share"

      Almost beside the point. Who in their right minds stores credit card information on their web servers these days? To say that's against Best Practices is a bit of an understatement.

    4. Re:Nothing new ... by Mitreya · · Score: 1

      Who in their right minds stores credit card information on their web servers these days? To say that's against Best Practices is a bit of an understatement.

      I don't see why not. If someone were to breach my account and steal my credit card info, the damage would be limited to an hour it takes for me to replace my auto-paying accounts. And perhaps the waiting for the replacement card to arrive.

      Best practices or not, my credit card account gets unauthorized charges every 2-3 years at least. It's not like I am ever responsible for that.

      I'd be more worried about my cell phone number (or even email) going into the wilderness than I would about someone stealing my credit card info.

    5. Re:Nothing new ... by Big+Hairy+Ian · · Score: 1

      Good grief if their security is that bad why the **** are their customers letting them store CC details?

      --

      Build a Man a Fire, and He'll Be Warm for a Day. Set a Man on Fire, and He'll Be Warm for the Rest of His Life.

    6. Re:Nothing new ... by pspahn · · Score: 1

      You really don't want to know how many, because, well, it's a lot! I have at least three former clients that do this (ignoring my suggestions).

      --
      Someone flopped a steamer in the gene pool.
    7. Re:Nothing new ... by Jane+Q.+Public · · Score: 1

      "I don't see why not."

      Well, you may not care, but I can assure you that a great many people do.

      But the point is: unless you are making recurring payments via your own system (itself not really best practice... you should have an outside merchant service that automatically does recurring payments), then as a programmer you are taught -- and rightly so -- that NO credit or debit card gets stored by your application. None. Sites I worked on before had it arranged that the main site app never even saw the credit card information, so it could not store that information, even if somebody wanted to.

  5. meausre by Anonymous Coward · · Score: 0

    They can't even spell measure properly. Why would you trust them with any personal information?

    1. Re: meausre by Anonymous Coward · · Score: 0

      Because that's unrelated to security...

  6. Also affects domainsite.com customers by pfraser · · Score: 5, Informative

    Domainsite.com (owned by name.com) were also affected and notified their customers accordingly this morning.

  7. Fishy by Anonymous Coward · · Score: 0

    I'm not convinced there aren't still issues - I have two-factor authentication on my Name.com account via a Verisign authenticator, and Name.com always asks for a code from the card the instant I type the last character of my username. They're not asking for that code now, which seems rather odd. Anyone else had the same experience?

  8. Making your way in the world today by Anonymous Coward · · Score: 3, Funny

    takes everything you've got.
    Finding a site with decent security, sure would help a lot.

    Wouldn't you like some SSH?

    Sometimes you want to go

    Where everybody knows your name,
    and the Chinese are always there to blame.
    You wanna be where you can see,
    our passwords are all the same
    You wanna be where everybody knows
    Your name.

     

  9. lol... by Anonymous Coward · · Score: 0

    htp5

  10. Take some additional steps to protect your account by Anonymous Coward · · Score: 5, Interesting

    This all stemmed from a hacking group trying to get access to Linode through Name.com. You can read more about it here, but keep in mind that Name.com is a very small part of the overall story: https://news.ycombinator.com/item?id=5667027

    For those that don't understand, even changing your password won't protect you at this point. The breach hasn't been filled, if that makes sense, as they used a zero day exploit on Name.com (and a few other registrars). Basically, they can still access your account if they want to, whether you change the password or not. I could be entirely wrong about that, but they make no mention of the technical fix, nor has the hacker group said anything about NOT having access any longer.

    It is correct that these hackers do not have access to your credit card number, but they can still make charges with your Payment Profile setup in the account. I'd suggest removing any payment profiles to be on the safe side. Also, they can still access your EPP codes because they are able to get into your account. Sure, the codes aren't stored at Name.com (same with the CC info) but they have access to your account. All the hackers need to do is log in to the account, click on a domain, and look at the EPP code being displayed, very simple.

    This email they sent out isn't very descriptive of what happened and what could happen. Even users with the NameSafe feature aren't protected, as having admin access bypasses that system. There is a good reason why there wasn't a response for over 24 hours by Name.com and why there still (as of the time I'm writing this) no blog post. Even if a blog post DOES get made, it won't be much more descriptive than the email that went out.

    Wonder if Demand Media is regretting that purchase now?

  11. As easy as 1-2-3 by justthinkit · · Score: 1
    (1) Turn over all passwords to the NSA
    .

    (2) Tell the world that something bad happened

    (3) Profit

    --
    I come here for the love
    1. Re:As easy as 1-2-3 by tobiah · · Score: 1

      this

      --
      "The ability to delude yourself may be an important survival tool" - Jane Wagner -
  12. Related to the Linode hack by Necroman · · Score: 3, Informative

    https://news.ycombinator.com/item?id=5667391

    In the above HN comment, basically it explains the linode hack, saying they got access to linodes registrar and were going to use it to steal passwords from linode customers. But they ended up finding the Coldfusion hole made it possible to break directly into linode, so they used that instead.

    --
    Its not what it is, its something else.
  13. The email from name.com by sticks_us · · Score: 1

    Found this, seems legit:

    http://pastebin.com/We3xgT4J

    --
    "Beware of bugs in the above code; I have only proved it correct, not tried it." -- Donald Knuth
    1. Re: The email from name.com by Anonymous Coward · · Score: 0

      Yes. That's what it said...

    2. Re: The email from name.com by sticks_us · · Score: 1

      hehehe, that's what I get for not RTFing entire A, I didn't see they'd inlined the entire thing in it. Derp!

      --
      "Beware of bugs in the above code; I have only proved it correct, not tried it." -- Donald Knuth
  14. Hack The Planet by Anonymous Coward · · Score: 0

    lol ?

  15. Re:Take some additional steps to protect your acco by game+kid · · Score: 1

    Wonder if Demand Media is regretting that purchase now?

    Why would they? They can just "Due to the unfortunate circumstances of a continuing bad economy, we have had to shutdown name.com. Sorry for the inconvenience, lol." and done. Their hands are wiped clean, the low-level IT workers are Romney'd in one fell swoop, the fat cats still get cash from their bulk-writing SEO scheme, and they can just buy up whoever else decides to take over whatever domain( name)?s they managed.

    --
    You can hold down the "B" button for continuous firing.
  16. How can passwords get leaked? by gnasher719 · · Score: 1

    How on earth is it possible at all that an IT related company stores passwords in a form that the information can get leaked?

  17. Eggg. I had a domain transfer request yesterday.. by slashkitty · · Score: 1

    That I didn't order.. I went in a change my password anyway... Wondering how close my domain was to getting stolen?

    --
    -- these are only opinions and they might not be mine.