Live data from Hacker News

Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

twitter.com

1–10 of 99 posts

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#3

completely violating your users trust is an interesting way to react to a disclosure of a potential security vulnerability

"Nefarious actors are attempting these things 24/7 regardless. As a registrar for millions of domains names, we are constantly under attack so this isn't anything new." - https://twitter.com/NamecheapCEO/status/1564077063480418307

I guess this makes sense. On the other hand such actions might have had legal implications before. I mean until the CEO actively allowed / awarded them.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#4
> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked.

> and to clarify, said account must be protected by 2fa to begin with.

I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mechanism.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#5
post #3

completely violating your users trust is an interesting way to react to a disclosure of a potential security vulnerability

"Nefarious actors are attempting these things 24/7 regardless. As a registrar for millions of domains names, we are constantly under attack so this isn't anything new." - https://twitter.com/NamecheapCEO/status/1564077063480418307 I guess this makes sense. On the other hand such actions might have had legal implications before. I mean until the CEO actively allowed / awarded them.

This doesn’t have any meaningful legal implications.

You will still be in trouble if you deface some random Namecheap customers website to claim this bounty.

Post reply on HN