Live data from Hacker News

Namecheap vulnerability they refuse to fix: no 2FA on support portal login

crimew.gay

81–90 of 99 posts

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#82

Why is NameCheap getting thrown under the bus across the board? I've used them for 10+ years without issue. In fact, it's been stellar. Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.

I moved away from Namecheap because they threaten to deactivate one of my domains within 24 hours after receiving a fabricated abuse complaint from a reputation management company. I saw from my logs that Namecheap did not even visit the page in question. I couldn't trust Namecheap after that and moved to Porkbun. I can't say with any certainty Porkbun would handle that situation any better. But I like the fact that if they try to pull some Google-esque automated ban, I can drive to their HQ.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#83
post #76

Earlier quoted context omitted.

Do you have some more supporting evidence for this, without me having to waltz into a blackhat forum? I'm not trying to be the "citation needed" guy, but as someone who regularly reports internet abuse to blacklists (and is sick of all the attacks that "neutral" places like Cloudflare send to my sites), I'd like to know more. I've seen your previous 2020 HN submission on this about Namecheap hosting the domains used…

> 2020: UK National Cyber Security Centre: Figure 1 shows that NameCheap became the most popular host of UK government-themed phishing during 2020. By December 2020 we found that it hosted in excess of 60% of phishing in this category. https://shkspr.mobi/blog/2021/05/why-do-scammers-love-namech... https://www.ncsc.gov.uk/files/Active-Cyber-Defence-ACD-The-F... > 2017: As of today around 38% of the domains reported t…

Wow, thank you very much for this. I honestly wasn't aware of any of it.

And double-Wow on that first PDF published by GCHQ. (Pages 8 and 9 are specifically their data on Namecheap as the #1 phishing threat, for anyone else wanting to read it). That's astonishingly bad performance from Namecheap. The data in that PDF is very useful with my own anti-botnet research. I bet the GCHQ data will be persuasive if I do bring this up with politicians considering removing the Safe Harbour provisions for hosts.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#84
post #40

Casual reminder that 9/10 phishing scam domains you come across will be hosted on NameCheap and the company couldn't care less, probably too valuable as revenue. This is so well known that blackhat discussions recommend NameCheap as the registrar of choice. Maybe they exploit vulnerabilities like this one. If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (p…

> couldn't care less They are usually praised for how fast they take down phishing domains though

Not in my experience either. I received phishing (physical) mail [1] pointing me to a domain that was registered with namecheap. I reported it to them in March, I followed up a few months later, and I still see the website operating today, with no response from namecheap.

The domain is even listed on the USPTO site as a scam operation [2], yet no action has been taken yet.

[1] Looks like this: https://www.uspto.gov/sites/default/files/documents/WTP%20Tr...

[2] https://www.uspto.gov/trademarks/protect/caution-misleading-...

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#85
post #79

Earlier quoted context omitted.

Yes, I'm aware of the war going on, and that it affects politics and economics, and therefore, valuable lives. But the complaint originated with the lack of 2FA, and then went straight under the bus for completely unrelated items. 2FA is a certainly a useful layer to add, but also not the be-all-and-end-all of account security. There isn't a list of 1) secure trustworthy companies because of 2FA, and 2) everyone else…

Are you using Wells Fargo as an example of a trustworthy company? They're one of the scummiest large companies I know of. https://en.m.wikipedia.org/wiki/Wells_Fargo_account_fraud_sc...

My Chase account does not require 2FA for my car payment login. Thats a more reputable example.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#86

Earlier quoted context omitted.

While I don't really care about the Ukraine crisis (its just being used as a political tool here), Namecheap offices were being blown up by an invading force. If Russia wants to have free commerce with Ukraine, including domain registration, then it shouldn't have invaded. As soon as war started, all trade requirements cease. In fact, I'm surprised it didn't become illegal immediately to have any commerce with Russia…

Where is “here” if you don’t mind me asking.

United States. Biden and Congress are just using "Ukraine Aid" as money for special interests (read corruption) and funding the military industrial complex as arms dealers.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#87
post #73

I’m really glad I migrated off Namecheap. Was a long time customer but when they had that massive dnssec outage and their support had no idea what it was doing, that was the last straw for me. I moved everything over to google (I know I know) and haven’t had a single second of downtime. Would love ideas for better alternatives, preferably privacy oriented.

I’ve been using gandi.net for years. They seem to care about playing by the rules and supporting privacy if their supported projects is anything to go by: https://www.gandi.net/en-US/gandi-supports

+1 for gandi.net's reputation. 10y straght of good service

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#88

Earlier quoted context omitted.

>> Why is NameCheap getting thrown under the bus across the board? from https://en.wikipedia.org/wiki/Namecheap 'In February 2022, Namecheap announced that they would terminate services to Russian accounts due to the Russian invasion of Ukraine, citing "war crimes and human rights violations". Existing users were given a one-week grace period to move their domains. The company also announced that it would be offering…

Yes, I'm aware of the war going on, and that it affects politics and economics, and therefore, valuable lives. But the complaint originated with the lack of 2FA, and then went straight under the bus for completely unrelated items. 2FA is a certainly a useful layer to add, but also not the be-all-and-end-all of account security. There isn't a list of 1) secure trustworthy companies because of 2FA, and 2) everyone else…

From your comment above I assumed that you were saying that Namecheap was being criticized in other recent threads.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#89
post #28

Earlier quoted context omitted.

Why not just buy the domains directly from cloudflare then?

To avoid the "all eggs in one basket" issue with companies that have arbitrary rules and little to no support, on purpose. Same reason I don't use Stripe or Shopify or SendGrid.

I’ve had excellent experience with support from Cloudflare, Stripe, and I don’t recall ever having issues with SendGrid over the 3+ years I used them.
Post reply on HN