Quoted post unavailable.
Namecheap vulnerability they refuse to fix: no 2FA on support portal login
11–20 of 99 posts
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#12Earlier quoted context omitted.
> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed
Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…
If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#13When switching away from DreamHost, I researched different domain registrars. I chose to try Namecheap and Dynadot, so I sent half of my domains to Namecheap, and the other half to Dynadot. After the transfer lock peroid, I moved my domains from Namecheap to Dynadot. The prices were pretty much the same, but the interface was better, and Dynadot also passes on "name tasting" to the user (users can request a refund if…
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#14Earlier quoted context omitted.
> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed
Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…
They gave them a month.
That would seem to be plenty of time to find a new registrar and transfer the domain.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#15In my experience, the support people ask for a PIN which you can only see by logging in to the main site with 2FA, so while this problem is not great, I don't think it's as bad as this article suggests.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#16When switching away from DreamHost, I researched different domain registrars. I chose to try Namecheap and Dynadot, so I sent half of my domains to Namecheap, and the other half to Dynadot. After the transfer lock peroid, I moved my domains from Namecheap to Dynadot. The prices were pretty much the same, but the interface was better, and Dynadot also passes on "name tasting" to the user (users can request a refund if…
Out of curiosity, was there any particular reason you switched away from Dreamhost?
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#17When switching away from DreamHost, I researched different domain registrars. I chose to try Namecheap and Dynadot, so I sent half of my domains to Namecheap, and the other half to Dynadot. After the transfer lock peroid, I moved my domains from Namecheap to Dynadot. The prices were pretty much the same, but the interface was better, and Dynadot also passes on "name tasting" to the user (users can request a refund if…
> When switching away from DreamHost Out of curiosity, was there any particular reason you switched away from Dreamhost?
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#18Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#19Not OP of this post, just came across it. I'm a heavy namecheap user, and will continue to use them, but this did make me a little concerned. From the post: > so, setting up 2fa on namecheap prevents anyone from just logging into your account if your credentials get leaked or stolen. great, they can't just manage your domains. HOWEVER, the namecheap support portal (at http://support.namecheap.com ) uses the same cred…
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#20Earlier quoted context omitted.
Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…
While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force. If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia…