Live data from Hacker News

Namecheap vulnerability they refuse to fix: no 2FA on support portal login

crimew.gay

11–20 of 99 posts

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#12
post #5

Earlier quoted context omitted.

> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…

While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force.

If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#13

When switching away from DreamHost, I researched different domain registrars. I chose to try Namecheap and Dynadot, so I sent half of my domains to Namecheap, and the other half to Dynadot. After the transfer lock peroid, I moved my domains from Namecheap to Dynadot. The prices were pretty much the same, but the interface was better, and Dynadot also passes on "name tasting" to the user (users can request a refund if…

That's a pretty common problem. Nintendo also does this.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#14
post #5

Earlier quoted context omitted.

> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…

> without giving them adequate time to migrate

They gave them a month.

That would seem to be plenty of time to find a new registrar and transfer the domain.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#15
Namecheap's support pages seem to be a completely different system to their main site. I've sometimes been unable to log into the support page even though I can get into the main site fine, and contacting support about it got nowhere. Maybe the support is outsourced?

In my experience, the support people ask for a PIN which you can only see by logging in to the main site with 2FA, so while this problem is not great, I don't think it's as bad as this article suggests.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#16

When switching away from DreamHost, I researched different domain registrars. I chose to try Namecheap and Dynadot, so I sent half of my domains to Namecheap, and the other half to Dynadot. After the transfer lock peroid, I moved my domains from Namecheap to Dynadot. The prices were pretty much the same, but the interface was better, and Dynadot also passes on "name tasting" to the user (users can request a refund if…

> When switching away from DreamHost

Out of curiosity, was there any particular reason you switched away from Dreamhost?

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#17
post #16

When switching away from DreamHost, I researched different domain registrars. I chose to try Namecheap and Dynadot, so I sent half of my domains to Namecheap, and the other half to Dynadot. After the transfer lock peroid, I moved my domains from Namecheap to Dynadot. The prices were pretty much the same, but the interface was better, and Dynadot also passes on "name tasting" to the user (users can request a refund if…

> When switching away from DreamHost Out of curiosity, was there any particular reason you switched away from Dreamhost?

Their domain name prices are higher, and I feel like their might have been something else, but I don't remember. I still have shared hosting with them because I haven't bothered to shop around on that yet (I have more domain names than sites I host).

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#18
I once had a domain at Namecheap show "Ownership change pending approval" to another username with a cancel link beside it and I recognized the username as someone who made offers before out of band. Never got an email or saw any kind of notification, and I've been in the game 25 years and know those extremely long domain transfer emails and read them carefully. Started transferring domains away after that.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#19
post #2

Not OP of this post, just came across it. I'm a heavy namecheap user, and will continue to use them, but this did make me a little concerned. From the post: > so, setting up 2fa on namecheap prevents anyone from just logging into your account if your credentials get leaked or stolen. great, they can't just manage your domains. HOWEVER, the namecheap support portal (at http://support.namecheap.com ) uses the same cred…

I only used support once many many years ago and was asked for a one time support code from the main account. So I never worried about the lack of 2factor. But now I worry…

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#20

Earlier quoted context omitted.

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…

While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force. If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia…

Where is “here” if you don’t mind me asking.
Post reply on HN