NameSilo

alert Epik Had A Major Breach

SpaceshipSpaceship
Watch

DaveX

@GoDaveXTop Member
Impact
52,011
Last edited:
36
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
AfternicAfternic
The data also includes Auth-Codes...
 
Last edited:
7
•••
6
•••
Last edited:
1
•••
@Rob Monster
Please regenerate all AUTH codes on your side...
 
4
•••
Praying? Blessings? God?!

SERIOUSLY ???!!!

If you have also protected your servers with holy water, the reason why you have been hacked is obvious.

Any website can be hacked. Sadly, if you stand for free speech and are not on "team woke", you're a target. That's actually what should be what's upsetting to you, but no, let's mock Rob's religious beliefs, instead.

I think it's pretty clear to those paying attention, that people like you are offended by someone injecting their religious beliefs within their business. Sure, we get it. However, if that offends you, no one is forcing you to do business with Rob. So why bother acting like a sophomoric child, resorting to spewing insulting snide remarks?

Countless people run their businesses around their beliefs. So why act like the hackers themselves, getting your pants in a bunch, and get all offended just because YOU don't happen to share those same beliefs? You know what Rob isn't doing? He's not publicly race baiting and injecting division and RACE into this daily marketing emails. Gee, who does that? Cough *GoDaddy*.

People who attack someone based on their religion are a disgrace. Let Rob be Rob and move on. His beliefs and his willingness to host third party websites who wish to exercise their free speech, individual sovereignty, and discuss their second amendment rights are literally WHY he was attacked, which is a concept that you would think a child would be able to grasp, yet here we are. Being hacked and having your business dismantled for your own beliefs is wrong, no matter how much people want to avoid that conversation.

If you're argument is that politics and ideology should be left out of business, then you'll need to cough up a strong defense for virtually every corporation who's knee deep in forcing their ideologies onto their customers. This is all we've witnessed in the last few years. For example, if GoDaddy were ever hacked (unlikely since they're on team woke) I still would never claim that it's somehow justified.
 
Last edited:
8
•••
1
•••
Once again, enough with the flame wars. People are busy trying to figure out how to respond; they don't want to read through pages of the same arguments that have been taking place for years--it's not helpful.
 
30
•••
Team Woke lmfao smokin home grown arent you?
Your pro epik, anti daddy and thats it. one is god, one is the devil.
This is high quality entertainment at its finest.
Did alleged hackฤ™rs write below article or Robin Monster? I saw someone reefer to him as robin on some blog. Sorry its tuck
https://archive.is/traih
 
1
•••
Auth codes: how often do they change? At every new registrar or some others factor determines?
Depends on the registrar's policy.
Ask in their LiveChat - how it is scheduled there.
 
2
•••
This is not a political thing. I would want my data to be protected.
There is no reason to inject politics, religion, etc.

A company is supposed to be a good steward of their customer's information.

In fairness, if some of the hack stuff is true then there are likely some serious security issues that need to be addressed.

Brad

Rob could have the security of Pentagon, but if team woke decides to dismantle you, then you're being dismantled. If there is indeed major security flaws at Epik, then that's obviously an issue that needs to be addressed ASAP. That said, the tendency to conflate WHY he was attacked is rampant on this thread. Rob wasn't attacked merely because there may have been extreme security flaws (which we still don't know yet) He was attacked due to who Rob is personally, and the websites he chooses to host.

A website shouldn't be attacked based on a site owner's politics or religion, yet here we are. This is why we're supposed to have the freedom to choose where we wish to spend our money. As a society, we're not supposed to resort to fascist tactics anytime we disagree with someone's belief systems.

Do you really want to live in a sterilized world where a business owner is unable to express his opinions or publicly run his business guided by his religion, without fearing the sheer dismantlement from the state or opposing group think? If your thought process is that injecting political and religion into business is merely a beacon for an attack, and therefore for the sake of safety we should just all be autonomous, neutral flavored robots, that's an incredibly dark path for humanity.
 
Last edited:
9
•••
How many domainers does it take to save a drowning man? Three:
  1. One to say he was conservative and therefore had it coming
  2. One to say a liberal pushed him into the water
  3. One to tell the other two to knock it off
He still drowns.

Unless you have new, useful information to share in order to help your fellow domainers, knock it off.
 
34
•••
Rob posted he thought the data taken was from a system backup, years old. I still think it was an inside job.
 
Last edited:
8
•••
Team Woke lmfao smokin home grown arent you?
Your pro epik, anti daddy and thats it. one is god, one is the devil.
This is high quality entertainment at its finest.
Did alleged hackฤ™rs write below article or Robin Monster? I saw someone reefer to him as robin on some blog. Sorry its tuck
https://archive.is/traih
I love the part "itโ€™s as bullshit as covid19 and 5G."
 
4
•••
Rob posted he thought the data taken was from a system backup, years old. I still think it was an inside job.

Let's stay with the facts. Where did you read the "years old" part?

I only saw Rob say that Epik "engineers believe the hack is from an outdated external backup, not Epik's core production". Almost by definition, a backup is aged. Basically it can mean a backup made last week, last month, three or six months ago. It is still quite serious and can provide plenty of opportunities to gain further access to internal and external systems. Backups are often an easy way to get a lot of critical information at once. Many companies fail to adequately protect their backups. The data in this particular backup seems to span a huge time frame. Having a good backup can save a company at critical moments, but it can also cause a lot of trouble for a company if the data falls into the wrong hands. Whether this was the only attack vector may become clear later.
 
Last edited:
6
•••
7
•••
The data appears to cut off around the end of February/beginning of March of this year.

That's supposedly when the hack happened. Don't know what to believe and it doesn't really matter. What they got is plenty enough to put your assets and private data at risk.

On the upside, transfers seem to go through without issues so at least you can keep your domains save. I changed whois data for all of them after transfer to another email address to be on the safe side.
 
3
•••
~6.5 months are not critical even for AUTH codes.
Many registrars refresh them just once.
 
Last edited:
5
•••
Here is a genuine concern of mine. I have changed my password to be sure to be sure. Is the Federated Identity login a good idea or a bad idea in the current context?

Edited by moderator: Removed remainder of post
 
Last edited by a moderator:
1
•••
Here is a genuine concern of mine. I have changed my password to be sure to be sure. Is the Federated Identity login a good idea or a bad idea in the current context?

Login data may get distributed widely, so 2FA is a good protection. The "Federated Identity" thing is a method of Single Sign On (SSO), I think.

The attackers may still be able to bypass any of these authentication measures. It's up to you and each individual / company / website to assess whether you may be a further target.

See also this posting.
 
Last edited:
4
•••
It does seem to affect (new) registrations:

Screenshot_20210916-195626.png
 
Last edited:
8
•••
Dynadot โ€” .com TransferDynadot โ€” .com Transfer
Spaceship
Domain Recover
CatchDoms
DomainEasy โ€” Live Options
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back