Live data from Hacker News

Namecheap vulnerability they refuse to fix: no 2FA on support portal login

crimew.gay

31–40 of 99 posts

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#31
post #16

Earlier quoted context omitted.

> When switching away from DreamHost Out of curiosity, was there any particular reason you switched away from Dreamhost?

Their domain name prices are higher, and I feel like their might have been something else, but I don't remember. I still have shared hosting with them because I haven't bothered to shop around on that yet (I have more domain names than sites I host).

Thanks for the response. I have been a Dreamhost customer for about 20 years and have never had a significant problem with them. I don't find their domain name prices to be an issue, but I might be less price sensitive about that than others.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#32
post #27

Earlier quoted context omitted.

While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force. If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia…

Quoted post unavailable.

[deleted]

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#33

Earlier quoted context omitted.

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…

> without giving them adequate time to migrate They gave them a month. That would seem to be plenty of time to find a new registrar and transfer the domain.

They gave less than two weeks: at Feb 28 people recived the letters about "asking" to GTFO by March 6, 2022.

I would just point to my comment back then: https://news.ycombinator.com/item?id=30507975

Also I would remind you what other services were cut immediately:

> Additionally, and with immediate effect, you will no longer be able to use Namecheap Hosting, EasyWP, and Private Email with a domain provided by another registrar in zones .ru, .xn--p1ai (рф), .by, .xn--90ais (бел), and .su. All websites will resolve to 403 Forbidden, however, you can contact us to assist you with your transfer to another provider.

Also I would point out to the other comment in that thread: https://news.ycombinator.com/item?id=30505934 Looks like someone wasn't satisfied with the ban by the country and resolved by greping by the names/last names. Doesn't remind you anything?

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#34

Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.

>> Why is NameCheap getting thrown under the bus across the board?

from https://en.wikipedia.org/wiki/Namecheap

'In February 2022, Namecheap announced that they would terminate services to Russian accounts due to the Russian invasion of Ukraine, citing "war crimes and human rights violations". Existing users were given a one-week grace period to move their domains. The company also announced that it would be offering free anonymous domain registration and web hosting to all protest and anti-war websites in Russia or Belarus. Namecheap at the same time said it had over 1,000 employees located in Ukraine, comprising most of its support staff, mostly in Kharkiv (which was a major location of fighting).'

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#35
post #28

Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.

Why not just buy the domains directly from cloudflare then?

Cloudflare's domain management has sadly also had some questionable actions/decisions.

0: https://news.ycombinator.com/item?id=31573854

1: https://community.cloudflare.com/t/domain-not-working-after-...

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#36
post #5

Earlier quoted context omitted.

> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…

>Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended.

As a Russian who was (and technically still is) one of their custmores: this is not accurate or at least only is true for some domains.

I've had two domains registered and managed via NC and decided to only transfer the former.

As of now the other one is still up.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#37

Earlier quoted context omitted.

> without giving them adequate time to migrate They gave them a month. That would seem to be plenty of time to find a new registrar and transfer the domain.

They gave less than two weeks: at Feb 28 people recived the letters about "asking" to GTFO by March 6, 2022. I would just point to my comment back then: https://news.ycombinator.com/item?id=30507975 Also I would remind you what other services were cut immediately: > Additionally, and with immediate effect, you will no longer be able to use Namecheap Hosting, EasyWP, and Private Email with a domain provided by another…

>Received the same email. I'm based in Lithuania and I have a Russian first name. No Russian addresses, IPs, billing info etc (because I have never been there!). How do you even select people to target with this? It's past midnight, I'm trying to figure out my options here. How exactly do the Euros I pay you from EU contribute to the Russian aggression?

This is utterly appalling. Im at loss for words.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#38
post #26

Earlier quoted context omitted.

I get it, but this is like kicking Barron Trump (the kid) out of your home because you don’t like his father. I get that you’re angry, I get that they’re related, but the kid doesn’t really have a say in how the father behaves. Same with Putin and most Russians. I could be protesting in Moscow and you’re still pulling the domain from me. That’s not ok. - I don’t have a stake in this, I just don’t want to deal with sh…

It wasn't how a registrar should act. But it was a completely understandable way to act, and given their emotional distress at the time, I think they deserve a fuckton of slack when judging how bad this mistake was. I probably would have done the same thing in their shoes. As for prime ministers being assholes affecting you, that is just the reality of global politics. I could say 'vote better' but that doesn't help…

No post body was provided.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#39
Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one.

If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (probably citing how big their $3/hour Eastern European legal team is) keep in mind it's all PR junk and the proof is in the pudding. It's been years -- no action, no change. Just more scams.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#40

Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one. If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (p…

> couldn't care less

They are usually praised for how fast they take down phishing domains though

Post reply on HN