Isn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward. https://www.techtimes.com/articles/271004/20220125/apple-rew... https://www.pcgamer.com/security-researchers-aka-hackers-mak...
Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
21–30 of 99 posts
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#22Guess I should move elsewhere. What is everyone using for domains and DNS these days?
NameSilo or Cloudflare
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#23> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…
Or qualify with "harmless changes", like inserting a TXT entry with your name.
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#24Really glad I moved my domains to Porkbun recently. This is Namecheaps second blunder this year in terms of being a reliable service provider. First engaging in politically cheap racial discrimination (their ban on Russia seemingly having hit anyone who ever in their history used a Russian IP adress and demanding evidence of a users current location before lifting it), now giving hackers carte blanche to screw with e…
What unreliable pieces of shit. How dare they?
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#25Guess I should move elsewhere. What is everyone using for domains and DNS these days?
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#26Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#27> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#28Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#29Isn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward. https://www.techtimes.com/articles/271004/20220125/apple-rew... https://www.pcgamer.com/security-researchers-aka-hackers-mak...
No, this is illegal and can put namespace into huge trouble. Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing. This is why legal departments exist, you cannot just say this as a CEO without consulting to your advisors.
> Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing.
Why do you think so? You don’t lose out on any legal protections without explicitly stating that.