Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one. If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (p…
> couldn't care less They are usually praised for how fast they take down phishing domains though
Namecheap vulnerability they refuse to fix: no 2FA on support portal login
61–70 of 99 posts
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#62Earlier quoted context omitted.
What alternative host would you recommend?
[dead]
I had a client with a domain and some VPS hosted in zone.ee, and one day out of the blue with no prior communication, the client received a notice from a zone.ee employee that they had disabled a production service on a VPS, because apparently the Docker configuration of that service was causing some issues in their infrastructure, which was already quite strange.
The real scary part was that the they didn't just turn off the VPS - the employee had actually backdoored into the running VPS and had manually disabled docker.service. The fact that they would do this without any communication beforehand just left me stunned and we immediately migrated away from zone.ee after that.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#63Earlier quoted context omitted.
They'll take down a single domain and pretend to not know how to take down the other 300 registered on the same user's account. The argument that NameCheap (and its supporters) provide is that this is a good thing that makes them stay because NameCheap shouldn't be policing domains or some other free speech nonsense ignoring that this is pure facilitation of crime. Ignoring that this is blatantly violating their own…
So they actually do care, huh. No, the argument is it's either this "free speech nonsense" or gestapo filtration like the Apple's/Google's app review process, where the big company is the judge and the jury, and I prefer the former.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#64Earlier quoted context omitted.
[dead]
I've had a horrible experience with zone.ee (aka zone.eu) and will always caution clients against using them. I had a client with a domain and some VPS hosted in zone.ee, and one day out of the blue with no prior communication, the client received a notice from a zone.ee employee that they had disabled a production service on a VPS, because apparently the Docker configuration of that service was causing some issues i…
That aside, shielded VM's are very rare, most providers have the ability to see inside VM's, issue commands in them.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#65Earlier quoted context omitted.
> without giving them adequate time to migrate They gave them a month. That would seem to be plenty of time to find a new registrar and transfer the domain.
They gave less than two weeks: at Feb 28 people recived the letters about "asking" to GTFO by March 6, 2022. I would just point to my comment back then: https://news.ycombinator.com/item?id=30507975 Also I would remind you what other services were cut immediately: > Additionally, and with immediate effect, you will no longer be able to use Namecheap Hosting, EasyWP, and Private Email with a domain provided by another…
https://www.theverge.com/2022/3/1/22956581/russia-ukraine-na...
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#66Quoted post unavailable.
> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#67Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#68So what is a good registrar that works with lego to do dns acme?
www.dnsimple.com
Including recently. “Secure your account with WebAuthn & FIDO2 security keys.”
You do need a subscription though: “A DNSimple subscription is required to register, transfer, or renew domain names. Domain registration, transfer, and renewal fees are not included in your subscription.“
That said I’m still currently a namecheap supporter, their backing for an open internet over the years has built my broader confidence in them, but I agree they need to be investing in pinging improvement especially when it comes to security practices.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#69Quoted post unavailable.
> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed
Do you have a source for this?