Hacker News new | ask | show | jobs
by paxys 5 days ago
How is domain privacy relevant here? That only hides your email from public records. What if the attacker already knows it (as they did in this case)? Email address is quite literally something you are meant to share publicly. It is not a password.
2 comments

I think their point was that if WHOIS data were hidden, a password reset request that relied on providing the email address would've been impossible. But since NC's account management allows visitors to provide just a domain name to generate an unlock email, domain privacy wouldn't be a protective layer here.
I still don’t get the argument. Say I call your bank and convince them to give me full control of your account. Are you going to go “well the bank didn’t publish my account number anywhere, so they are in the clear”?
I agree, it's not an excuse to hand over an account. I think that commenter was considering practical mitigations for a broken system, not necessarily absolving NC of responsibility had my WHOIS been public.
Registration info usually also includes a physical address and names.
i agree that's important to hide, but also irrelevant to preventing what happened here.
Seems pretty relevant to a social engineering attack to have more correct pieces of info to give to support.
by "what happened here" i mean this specific post. in this specific post, address information was not required.
That's not clear to me.

> He convinced them the domain registered in my name and address really belonged to his club

Convinced how? Often such things are via "knowing things" about the account holder.

the author explicitly said they had domain privacy on. so we know that the caller did not have the address information.

and we can be certain that domain privacy wouldn't have helped in this case (because it didn't).

https://news.ycombinator.com/item?id=49028611

>Convinced how? Often such things are via "knowing things" about the account holder.

i have some experience with social engineering attacks (former infosec turned teacher) and it was probably a combination of:

    - caller confidence that they were the club owner/manager (because they were)
    - offering/sending club-specific information that matched information on the site (flyers, pamphlets, etc.)
    - "call the number on the website and i will answer it"
    - an official college website page that had the caller listed as an owner/manager of the club
    - some poor 20-something year old working in a hellish, windowless tier 1 tech support center