Namecheap vulnerability they refuse to fix: no 2FA on support portal login
81–90 of 99 posts
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#82Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#83Earlier quoted context omitted.
Do you have some more supporting evidence for this, without me having to waltz into a blackhat forum? I'm not trying to be the "citation needed" guy, but as someone who regularly reports internet abuse to blacklists (and is sick of all the attacks that "neutral" places like Cloudflare send to my sites), I'd like to know more. I've seen your previous 2020 HN submission on this about Namecheap hosting the domains used…
> 2020: UK National Cyber Security Centre: Figure 1 shows that NameCheap became the most popular host of UK government-themed phishing during 2020. By December 2020 we found that it hosted in excess of 60% of phishing in this category. https://shkspr.mobi/blog/2021/05/why-do-scammers-love-namech... https://www.ncsc.gov.uk/files/Active-Cyber-Defence-ACD-The-F... > 2017: As of today around 38% of the domains reported t…
And double-Wow on that first PDF published by GCHQ. (Pages 8 and 9 are specifically their data on Namecheap as the #1 phishing threat, for anyone else wanting to read it). That's astonishingly bad performance from Namecheap. The data in that PDF is very useful with my own anti-botnet research. I bet the GCHQ data will be persuasive if I do bring this up with politicians considering removing the Safe Harbour provisions for hosts.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#84Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one. If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (p…
> couldn't care less They are usually praised for how fast they take down phishing domains though
The domain is even listed on the USPTO site as a scam operation [2], yet no action has been taken yet.
[1] Looks like this: https://www.uspto.gov/sites/default/files/documents/WTP%20Tr...
[2] https://www.uspto.gov/trademarks/protect/caution-misleading-...
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#85Earlier quoted context omitted.
Yes, I'm aware of the war going on, and that it affects politics and economics, and therefore, valuable lives. But the complaint originated with the lack of 2FA, and then went straight under the bus for completely unrelated items. 2FA is a certainly a useful layer to add, but also not the be-all-and-end-all of account security. There isn't a list of 1) secure trustworthy companies because of 2FA, and 2) everyone else…
Are you using Wells Fargo as an example of a trustworthy company? They're one of the scummiest large companies I know of. https://en.m.wikipedia.org/wiki/Wells_Fargo_account_fraud_sc...
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#86Earlier quoted context omitted.
While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force. If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia…
Where is “here” if you don’t mind me asking.
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#87I’m really glad I migrated off Namecheap. Was a long time customer but when they had that massive dnssec outage and their support had no idea what it was doing, that was the last straw for me. I moved everything over to google (I know I know) and haven’t had a single second of downtime. Would love ideas for better alternatives, preferably privacy oriented.
I’ve been using gandi.net for years. They seem to care about playing by the rules and supporting privacy if their supported projects is anything to go by: https://www.gandi.net/en-US/gandi-supports
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#88Earlier quoted context omitted.
>> Why is NameCheap getting thrown under the bus across the board? from https://en.wikipedia.org/wiki/Namecheap 'In February 2022, Namecheap announced that they would terminate services to Russian accounts due to the Russian invasion of Ukraine, citing "war crimes and human rights violations". Existing users were given a one-week grace period to move their domains. The company also announced that it would be offering…
Yes, I'm aware of the war going on, and that it affects politics and economics, and therefore, valuable lives. But the complaint originated with the lack of 2FA, and then went straight under the bus for completely unrelated items. 2FA is a certainly a useful layer to add, but also not the be-all-and-end-all of account security. There isn't a list of 1) secure trustworthy companies because of 2FA, and 2) everyone else…
Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login
#89Earlier quoted context omitted.
Why not just buy the domains directly from cloudflare then?
To avoid the "all eggs in one basket" issue with companies that have arbitrary rules and little to no support, on purpose. Same reason I don't use Stripe or Shopify or SendGrid.