More bluntly, what is it that you think your current registrar is lacking?
I read a few comments on Gandi and support of GPG keys. I'm guessing this is what you're referring to: https://wiki.gandi.net/en/gandi/documents
101–110 of 426 posts
More bluntly, what is it that you think your current registrar is lacking?
I read a few comments on Gandi and support of GPG keys. I'm guessing this is what you're referring to: https://wiki.gandi.net/en/gandi/documents
Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
I love namecheap but 5 sounds like victim blaming. Come on. EDIT: My use of the term is a bit strong. I feel frustrated that company execs cannot explicitly admit a mistake or apologize. I should have worded it differently. EDIT2: just for Tamar. By explicit I mean literally using the words "sorry", "apologize", or "mistake". What we have is the standard corporate nonapology. EDIT3: congrats to Tamar for being promot…
Earlier quoted context omitted.
> email them a scan of your passport What? Why do they do this?
Apparently, OP wanted to transfer the domain from Gandi.
Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
If you give a shit about it, back it up.
Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
We offer full backups with all managed servers/services Self-managed a customer is responsible for their own backups. Just like with DO and that full server loss a couple of months back.
Are those backups purgeable from the account control panel?
Honestly I'm not a huge fan of same-provider backup solutions. It seems like asking a fox to guard your sheep.
Earlier quoted context omitted.
That doesn't really make sense. We're a great domain and hosting provider.
This isn't your part of the business but there is room for improvement when it comes to kb articles in domain https://www.namecheap.com/support/knowledgebase/article.aspx... The domain registration process isn't automated from my experience but it works well. However, I think the meta is (I think many people will agree) to not mix domain and hosting with the same provider. For example, if you get your domain from nam…
Our KB platform is getting some attention as articles are improved and then the UX will be overhauled. We have work to do here and we're doing it.
I'm traveling constantly. I always have a different country's SIM in my phone meaning I can't receive SMSs to a static number.
Is SMS only 2FA acceptable?
Earlier quoted context omitted.
We have had this at Amazon AWS. We had 2FA, one phone call was enough to disable 2FA. The only thing they asked were the last four digits of our credit card.
That is a little unnerving if true.
Edit. Had some details wrong. It was a reporter at Gizmodo, and basically a collection of data was gathered from various online services (mailing address, last 4 digits of CC) to ultimately social engineer his Apple account and remote wipe his computer. A number of factors were involved, but ultimately he was done in by not having 2FA on google, and not backing up his machine.
Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
Second biggest lesson here: do not use weak passwords for emails.