Namecheap vulnerability they refuse to fix: no 2FA on support portal login
1–10 of 99 posts
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#2> so, setting up 2fa on namecheap prevents anyone from just logging into your account if your credentials get leaked or stolen. great, they can't just manage your domains. HOWEVER, the namecheap support portal (at http://support.namecheap.com) uses the same credentials for login BUT it never asks for 2fa. if you get leaked credentials you can just sign in to the support portal. because of how badly designed it is you can even change the support email for the account with no confirmation and no info being sent out to the old email.
> how is that a big deal?
> well, you can just open domain transfer tickets from the support portal and hijack domains anyways, you can probably even pretend to not understand how anything works and ask them to change dns for you, etc...
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#3Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#4After the transfer lock peroid, I moved my domains from Namecheap to Dynadot. The prices were pretty much the same, but the interface was better, and Dynadot also passes on "name tasting" to the user (users can request a refund if they change their mind after buying a domain name).
I've also sinced used Dynadot's customer service one time, and it was good.
My only gripe with Dynadot is at the login screen: I set up 2FA, and they call it a "Google code", when you can use any other 2FA manager besides Google.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#5Quoted post unavailable.
Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#6Quoted post unavailable.
> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#7Quoted post unavailable.
> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#8Earlier quoted context omitted.
> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed
Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#9Quoted post unavailable.
NameCheap is only the cheapest for _one_ TLD in terms of renewal cost (https://tld-list.com/registrars). Love that site.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#10Quoted post unavailable.
> It’s one of those cheap bottom of the barrel vendors which of course takes shortcuts to make the price so cheap. NameCheap is only the cheapest for _one_ TLD in terms of renewal cost ( https://tld-list.com/registrars ). Love that site.