Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.
>> Why is NameCheap getting thrown under the bus across the board? from https://en.wikipedia.org/wiki/Namecheap 'In February 2022, Namecheap announced that they would terminate services to Russian accounts due to the Russian invasion of Ukraine, citing "war crimes and human rights violations". Existing users were given a one-week grace period to move their domains. The company also announced that it would be offering…
Namecheap vulnerability they refuse to fix: no 2FA on support portal login
71–80 of 99 posts
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#72So what is a good registrar that works with lego to do dns acme?
Your paying for a more premium service but DNSimple take security and service fairly seriously. www.dnsimple.com Including recently. “Secure your account with WebAuthn & FIDO2 security keys.” You do need a subscription though: “A DNSimple subscription is required to register, transfer, or renew domain names. Domain registration, transfer, and renewal fees are not included in your subscription.“ That said I’m still cu…
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#73Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#74Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#75I’m really glad I migrated off Namecheap. Was a long time customer but when they had that massive dnssec outage and their support had no idea what it was doing, that was the last straw for me. I moved everything over to google (I know I know) and haven’t had a single second of downtime. Would love ideas for better alternatives, preferably privacy oriented.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#76Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one. If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (p…
Do you have some more supporting evidence for this, without me having to waltz into a blackhat forum? I'm not trying to be the "citation needed" guy, but as someone who regularly reports internet abuse to blacklists (and is sick of all the attacks that "neutral" places like Cloudflare send to my sites), I'd like to know more. I've seen your previous 2020 HN submission on this about Namecheap hosting the domains used…
https://shkspr.mobi/blog/2021/05/why-do-scammers-love-namech...
https://www.ncsc.gov.uk/files/Active-Cyber-Defence-ACD-The-F...
> 2017: As of today around 38% of the domains reported to us since we began recording on 8/23/17 are sponsored by NameCheap INC. These domains are allowed to continue to scam consumers long after they are reported. An example of this is “ecojetexpress.us” which has been reported repeatedly by both petscams.com and victims who have lost money. When victims of this scam filed an abuse report NameCheap did not “take reasonable and prompt steps to investigate”. Instead they forwarded the abuse report with the victims information to the criminal. 5 months later, ecojetexpress.us was still online scamming new victims.
https://petscams.com/news/namecheap-hurting-internet/
> Facebook sues Namecheap to unmask hackers who registered malicious domains. The social networking giant claims that Namecheap has refused to cooperate in an investigation into a series of malicious domains that have been registered through its service and which impersonated the Facebook brand.
> Some of the sample domains included the likes of instagrambusinesshelp.com, facebo0k-login.com, and whatsappdownload.site.
> Dubois said lookalike domains like these -- which abuse the Facebook brand -- are often used for phishing, fraud, and scams.
https://www.zdnet.com/article/facebook-sues-namecheap-to-unm...
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#77Earlier quoted context omitted.
I get it, but this is like kicking Barron Trump (the kid) out of your home because you don’t like his father. I get that you’re angry, I get that they’re related, but the kid doesn’t really have a say in how the father behaves. Same with Putin and most Russians. I could be protesting in Moscow and you’re still pulling the domain from me. That’s not ok. - I don’t have a stake in this, I just don’t want to deal with sh…
It wasn't how a registrar should act. But it was a completely understandable way to act, and given their emotional distress at the time, I think they deserve a fuckton of slack when judging how bad this mistake was. I probably would have done the same thing in their shoes. As for prime ministers being assholes affecting you, that is just the reality of global politics. I could say 'vote better' but that doesn't help…
So we agree. If you act the wrong way, I won’t give you business. It’s not a hard concept, regardless of the motivations behind it.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#78Namecheap's support pages seem to be a completely different system to their main site. I've sometimes been unable to log into the support page even though I can get into the main site fine, and contacting support about it got nowhere. Maybe the support is outsourced? In my experience, the support people ask for a PIN which you can only see by logging in to the main site with 2FA, so while this problem is not great, I…
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#79Earlier quoted context omitted.
>> Why is NameCheap getting thrown under the bus across the board? from https://en.wikipedia.org/wiki/Namecheap 'In February 2022, Namecheap announced that they would terminate services to Russian accounts due to the Russian invasion of Ukraine, citing "war crimes and human rights violations". Existing users were given a one-week grace period to move their domains. The company also announced that it would be offering…
Yes, I'm aware of the war going on, and that it affects politics and economics, and therefore, valuable lives. But the complaint originated with the lack of 2FA, and then went straight under the bus for completely unrelated items. 2FA is a certainly a useful layer to add, but also not the be-all-and-end-all of account security. There isn't a list of 1) secure trustworthy companies because of 2FA, and 2) everyone else…
https://en.m.wikipedia.org/wiki/Wells_Fargo_account_fraud_sc...
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#80Earlier quoted context omitted.
>> Why is NameCheap getting thrown under the bus across the board? from https://en.wikipedia.org/wiki/Namecheap 'In February 2022, Namecheap announced that they would terminate services to Russian accounts due to the Russian invasion of Ukraine, citing "war crimes and human rights violations". Existing users were given a one-week grace period to move their domains. The company also announced that it would be offering…
Don't western sanctions effectively FORCE namecheap to do this?