Live data from Hacker News

Namecheap vulnerability they refuse to fix: no 2FA on support portal login

crimew.gay

21–30 of 99 posts

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#21

Earlier quoted context omitted.

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…

> without giving them adequate time to migrate They gave them a month. That would seem to be plenty of time to find a new registrar and transfer the domain.

The minimum length of registration at practically all registrars is 1 year. Its practically unheard of, and against all professional standards for registrars to cancel a persons domains prematurely. Nobody expects it and they knew that and they pulled the rug anyway because apparently they value virtue signaling more than security.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#22

Earlier quoted context omitted.

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…

While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force. If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia…

I get it, but this is like kicking Barron Trump (the kid) out of your home because you don’t like his father.

I get that you’re angry, I get that they’re related, but the kid doesn’t really have a say in how the father behaves. Same with Putin and most Russians.

I could be protesting in Moscow and you’re still pulling the domain from me. That’s not ok.

-

I don’t have a stake in this, I just don’t want to deal with shit if my prime minister 10k miles away is an asshole.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#23
Why is NameCheap getting thrown under the bus across the board?

I've used them for 10+ years without issue. In fact, it's been stellar.

Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#24

Earlier quoted context omitted.

> without giving them adequate time to migrate They gave them a month. That would seem to be plenty of time to find a new registrar and transfer the domain.

The minimum length of registration at practically all registrars is 1 year. Its practically unheard of, and against all professional standards for registrars to cancel a persons domains prematurely. Nobody expects it and they knew that and they pulled the rug anyway because apparently they value virtue signaling more than security.

> virtue signaling

Or maybe they just don't want to incur the risk of doing business with a sanctioned country.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#25

Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.

[deleted]

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#26

Earlier quoted context omitted.

While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force. If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia…

I get it, but this is like kicking Barron Trump (the kid) out of your home because you don’t like his father. I get that you’re angry, I get that they’re related, but the kid doesn’t really have a say in how the father behaves. Same with Putin and most Russians. I could be protesting in Moscow and you’re still pulling the domain from me. That’s not ok. - I don’t have a stake in this, I just don’t want to deal with sh…

It wasn't how a registrar should act. But it was a completely understandable way to act, and given their emotional distress at the time, I think they deserve a fuckton of slack when judging how bad this mistake was.

I probably would have done the same thing in their shoes.

As for prime ministers being assholes affecting you, that is just the reality of global politics. I could say 'vote better' but that doesn't help much.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#27

Earlier quoted context omitted.

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…

While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force. If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia…

No post body was provided.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#28

Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.

Why not just buy the domains directly from cloudflare then?

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#29

Earlier quoted context omitted.

> without giving them adequate time to migrate They gave them a month. That would seem to be plenty of time to find a new registrar and transfer the domain.

The minimum length of registration at practically all registrars is 1 year. Its practically unheard of, and against all professional standards for registrars to cancel a persons domains prematurely. Nobody expects it and they knew that and they pulled the rug anyway because apparently they value virtue signaling more than security.

According to other comments here, their offices were being shelled by the Russians. At that point, taking action against Russians isn't virtue signalling.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#30

Earlier quoted context omitted.

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…

While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force. If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia…

> I'm surprised it didn't become illegal immediately to have any commerce with Russia

Because you mistake Russian citizens for Russian Federation. Also someone needs that chea^W not so cheap now gas.

Post reply on HN