Live data from Hacker News

Namecheap vulnerability they refuse to fix: no 2FA on support portal login

crimew.gay

51–60 of 99 posts

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#53

Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one. If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (p…

Then again you can create heuristics that block suspicious domains registered at NameCheap, silver lining or something.

I really wish the effort put into curtailing piracy went into curtailing spam and phishing instead. Would be actually beneficial to society.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#54
post #40

Earlier quoted context omitted.

> couldn't care less They are usually praised for how fast they take down phishing domains though

They'll take down a single domain and pretend to not know how to take down the other 300 registered on the same user's account. The argument that NameCheap (and its supporters) provide is that this is a good thing that makes them stay because NameCheap shouldn't be policing domains or some other free speech nonsense ignoring that this is pure facilitation of crime. Ignoring that this is blatantly violating their own…

So they actually do care, huh.

No, the argument is it's either this "free speech nonsense" or gestapo filtration like the Apple's/Google's app review process, where the big company is the judge and the jury, and I prefer the former.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#55

Quoted post unavailable.

You seem knowledgeable, so, what do you think about Porkbun?

Not OP, I just took a look at Porkbun.

They appear to take security seriously. You can choose to receive emails upon each successful and/or failed login. You can view a list of recent logins to your account on the website. You can force log out all sessions. Additional authentication methods include two-factor codes, WebAuthn w/ physical keys. You can download a set of backup, one-time-use codes. You can restrict IP addresses allowed for login. They also check if your email address is present in known password leaks, and prompt you to turn on 2FA for added security.

The web interface is quick, has a simple design (Bootstrap/Foundation? for CSS), and doesn't feel flimsy.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#56
post #18

I once had a domain at Namecheap show "Ownership change pending approval" to another username with a cancel link beside it and I recognized the username as someone who made offers before out of band. Never got an email or saw any kind of notification, and I've been in the game 25 years and know those extremely long domain transfer emails and read them carefully. Started transferring domains away after that.

What alternative host would you recommend?

[dead]

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#57
post #45

Earlier quoted context omitted.

What alternative host would you recommend?

Porkbun and Cloudflare are the best and cheap

CloudFlare unfortunately still have a very limited subset of TLDs available.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#58
post #28

Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.

Why not just buy the domains directly from cloudflare then?

There's a limited number of TLDs available on CloudFlare.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#59
post #51
post #45

Earlier quoted context omitted.

Porkbun and Cloudflare are the best and cheap

What's Porkbun's support like?

I contacted them once before moving over and once after and they were good to me. I'm happy with them for domains but I wouldn't recommend them for email.
Post reply on HN