I once had a domain at Namecheap show "Ownership change pending approval" to another username with a cancel link beside it and I recognized the username as someone who made offers before out of band. Never got an email or saw any kind of notification, and I've been in the game 25 years and know those extremely long domain transfer emails and read them carefully. Started transferring domains away after that.
Namecheap vulnerability they refuse to fix: no 2FA on support portal login
41–50 of 99 posts
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#42Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one. If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (p…
> couldn't care less They are usually praised for how fast they take down phishing domains though
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#43Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.
>> Why is NameCheap getting thrown under the bus across the board? from https://en.wikipedia.org/wiki/Namecheap 'In February 2022, Namecheap announced that they would terminate services to Russian accounts due to the Russian invasion of Ukraine, citing "war crimes and human rights violations". Existing users were given a one-week grace period to move their domains. The company also announced that it would be offering…
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#44Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one. If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (p…
> couldn't care less They are usually praised for how fast they take down phishing domains though
The argument that NameCheap (and its supporters) provide is that this is a good thing that makes them stay because NameCheap shouldn't be policing domains or some other free speech nonsense ignoring that this is pure facilitation of crime. Ignoring that this is blatantly violating their own T&Cs and the ICANN guidelines.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#45I once had a domain at Namecheap show "Ownership change pending approval" to another username with a cancel link beside it and I recognized the username as someone who made offers before out of band. Never got an email or saw any kind of notification, and I've been in the game 25 years and know those extremely long domain transfer emails and read them carefully. Started transferring domains away after that.
What alternative host would you recommend?
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#46Earlier quoted context omitted.
While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force. If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia…
Quoted post unavailable.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#47Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.
>> Why is NameCheap getting thrown under the bus across the board? from https://en.wikipedia.org/wiki/Namecheap 'In February 2022, Namecheap announced that they would terminate services to Russian accounts due to the Russian invasion of Ukraine, citing "war crimes and human rights violations". Existing users were given a one-week grace period to move their domains. The company also announced that it would be offering…
2FA is a certainly a useful layer to add, but also not the be-all-and-end-all of account security.
There isn't a list of 1) secure trustworthy companies because of 2FA, and 2) everyone else is untrustworthy and dangerous. Wells Fargo doesn't even require 2FA.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#48I once had a domain at Namecheap show "Ownership change pending approval" to another username with a cancel link beside it and I recognized the username as someone who made offers before out of band. Never got an email or saw any kind of notification, and I've been in the game 25 years and know those extremely long domain transfer emails and read them carefully. Started transferring domains away after that.
What alternative host would you recommend?
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#49Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.
Why not just buy the domains directly from cloudflare then?
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#50Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one. If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (p…
I've seen your previous 2020 HN submission on this about Namecheap hosting the domains used in SMS scams: https://news.ycombinator.com/item?id=24231307