Live data from Hacker News

Namecheap vulnerability they refuse to fix: no 2FA on support portal login

crimew.gay

61–70 of 99 posts

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#61
post #40

Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one. If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (p…

> couldn't care less They are usually praised for how fast they take down phishing domains though

Not my experience. I tried their abuse email address, their abuse report form and I even made an account to contact support, but did not even receive a reply. Over 30 websites are still up. But to be fair, the websites are about selling certain pills and not about phishing.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#62
post #56

Earlier quoted context omitted.

What alternative host would you recommend?

[dead]

I've had a horrible experience with zone.ee (aka zone.eu) and will always caution clients against using them.

I had a client with a domain and some VPS hosted in zone.ee, and one day out of the blue with no prior communication, the client received a notice from a zone.ee employee that they had disabled a production service on a VPS, because apparently the Docker configuration of that service was causing some issues in their infrastructure, which was already quite strange.

The real scary part was that the they didn't just turn off the VPS - the employee had actually backdoored into the running VPS and had manually disabled docker.service. The fact that they would do this without any communication beforehand just left me stunned and we immediately migrated away from zone.ee after that.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#63

Earlier quoted context omitted.

They'll take down a single domain and pretend to not know how to take down the other 300 registered on the same user's account. The argument that NameCheap (and its supporters) provide is that this is a good thing that makes them stay because NameCheap shouldn't be policing domains or some other free speech nonsense ignoring that this is pure facilitation of crime. Ignoring that this is blatantly violating their own…

So they actually do care, huh. No, the argument is it's either this "free speech nonsense" or gestapo filtration like the Apple's/Google's app review process, where the big company is the judge and the jury, and I prefer the former.

Ah yes the nazi hammer.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#64
post #56

Earlier quoted context omitted.

[dead]

I've had a horrible experience with zone.ee (aka zone.eu) and will always caution clients against using them. I had a client with a domain and some VPS hosted in zone.ee, and one day out of the blue with no prior communication, the client received a notice from a zone.ee employee that they had disabled a production service on a VPS, because apparently the Docker configuration of that service was causing some issues i…

That sounds unfortunate. I imagine it must've been time-critical, some side-effect of Docker being virtualised? I'd guess the hands-on approach was to avoid a full service disruption that a full shutdown would've caused.

That aside, shielded VM's are very rare, most providers have the ability to see inside VM's, issue commands in them.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#65

Earlier quoted context omitted.

> without giving them adequate time to migrate They gave them a month. That would seem to be plenty of time to find a new registrar and transfer the domain.

They gave less than two weeks: at Feb 28 people recived the letters about "asking" to GTFO by March 6, 2022. I would just point to my comment back then: https://news.ycombinator.com/item?id=30507975 Also I would remind you what other services were cut immediately: > Additionally, and with immediate effect, you will no longer be able to use Namecheap Hosting, EasyWP, and Private Email with a domain provided by another…

The original date was March 6 but was extended to March 22.

https://www.theverge.com/2022/3/1/22956581/russia-ukraine-na...

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#66
post #5

Quoted post unavailable.

> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed

No post body was provided.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#68
post #60

So what is a good registrar that works with lego to do dns acme?

Your paying for a more premium service but DNSimple take security and service fairly seriously.

www.dnsimple.com

Including recently. “Secure your account with WebAuthn & FIDO2 security keys.”

You do need a subscription though: “A DNSimple subscription is required to register, transfer, or renew domain names. Domain registration, transfer, and renewal fees are not included in your subscription.“

That said I’m still currently a namecheap supporter, their backing for an open internet over the years has built my broader confidence in them, but I agree they need to be investing in pinging improvement especially when it comes to security practices.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#69
post #5

Quoted post unavailable.

> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed

> when their Ukrainian offices started getting shelled by Russian invaders.

Do you have a source for this?

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#70
Their email service - Private Email - (which is otherwise pretty decent) also has a similar issue where they support 2FA and application passwords for the web interface, but don't enforce those rules via the IMAP/SMTP/POP/etc APIs - https://twitter.com/symbioquine/status/1362907237048479745
Post reply on HN