Live data from Hacker News

Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

twitter.com

11–20 of 99 posts

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#14
Isn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward.

https://www.techtimes.com/articles/271004/20220125/apple-rew...

https://www.pcgamer.com/security-researchers-aka-hackers-mak...

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#15

Isn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward. https://www.techtimes.com/articles/271004/20220125/apple-rew... https://www.pcgamer.com/security-researchers-aka-hackers-mak...

You're not supposed to cause actual substantive changes to actual customers. In addition to being questionably ethical, that would usually disqualify a researcher from any possible bug bounties and forfeit legal protections offered by the program.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#16

Isn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward. https://www.techtimes.com/articles/271004/20220125/apple-rew... https://www.pcgamer.com/security-researchers-aka-hackers-mak...

Hacking accounts without consent of the victim is probably illegal. So normally you'd use an account you own (or your friend/colleague owns), but the challenge is excluding those. The company setting up special test accounts can be a good option as well, but needs to be done in good faith and is problematic when the attack is social engineering based.

So the challenge is either giving attackers permission to hack accounts of strangers, or requires the attacker to engage in potentially illegal behaviour. Neither of which is acceptable.

I assume this is just badly phrased, and what was actually intended was a requirement that the victim doesn't collude with or help the attacker.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#17

Isn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward. https://www.techtimes.com/articles/271004/20220125/apple-rew... https://www.pcgamer.com/security-researchers-aka-hackers-mak...

Not really, they don't often advertise that you should attack their customers directly. The closest I can remember was the LifeLock guy putting his social security number up publicly.

Otherwise, they prefer you hit test or personal accounts rather than paying customers...

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#18

> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…

Or qualify with "harmless changes", like inserting a TXT entry with your name.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#19
Really glad I moved my domains to Porkbun recently.

This is Namecheaps second blunder this year in terms of being a reliable service provider.

First engaging in politically cheap racial discrimination (their ban on Russia seemingly having hit anyone who ever in their history used a Russian IP adress and demanding evidence of a users current location before lifting it), now giving hackers carte blanche to screw with existing customers.

Extremely unreliable.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#20

Isn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward. https://www.techtimes.com/articles/271004/20220125/apple-rew... https://www.pcgamer.com/security-researchers-aka-hackers-mak...

No, this is illegal and can put namespace into huge trouble.

Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing.

This is why legal departments exist, you cannot just say this as a CEO without consulting to your advisors.

Post reply on HN