Live data from Hacker News

Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

twitter.com

41–50 of 99 posts

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#41
post #29

Earlier quoted context omitted.

No, this is illegal and can put namespace into huge trouble. Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing. This is why legal departments exist, you cannot just say this as a CEO without consulting to your advisors.

None of what you’re saying is true. > Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing. Why do you think so? You don’t lose out on any legal protections without explicitly stating that.

I think you meant legal protections for the security researcher? I was talking about legal troubles for the Namecheap.

Company can't encourage/allow security researchers to access private data of the users, at best this is against GDPR but it can also cause monetary damage to users which can be far worse.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#42

> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…

I think that's reasonable. I was thinking in terms of cutting out the gaming aspect when I made that statement. I probably should have been more specific. The premise of the entire conversation was based on someone making an unjustified accusation without even following it through and testing it to begin with.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#43
post #36
post #34

Earlier quoted context omitted.

> kingofkyiv.com > buyagf.com What the hell am I looking at?

My best guess for the second one is "human trafficking".

Or perhaps a Runescape fan.

"buying gf, 100 gp"

I wonder if they also have an armour trimming service.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#44
post #31
post #26

If the result of this tweet is that one of my domains is altered, and that I lose income, users, or other useful metrics to measure the value of my site, this seems like a great piece of evidence to be litigious towards Namecheap

How is this different from any other bug bounty program as an incentive to compromise live functionality/user data always exists?

Well run bug bounty programs have strict guidelines on what is and is not out of scope, and changes like this would certainly be out of scope (in fact, generally social engineering as part of the exploit chain is itself wholly out of scope).

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#45
How else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this.

(Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying that because with white-hat(ish) hackers, you'd be shocked how many people try to claim bug bounties from us because they "hacked" their own account using their own credentials.)

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#47
Coincidentally I just received an email request to reset my password on Namecheap (not issued by me), anyone else? On top of that, my account has been locked for 24 hours for three consecutive failed password or username entry attempts.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#48

Earlier quoted context omitted.

Or qualify with "harmless changes", like inserting a TXT entry with your name.

Inserting a TXT entry isn't a harmless change these days, because it's one way to authenticate ownership of a domain. Like recovering a google apps admin login.

It can be used harmfully (as everything) but adding one isn't as harmful as for example deleting an A entry or changing CNAMEs to another domain

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#49
post #23

Earlier quoted context omitted.

Whats the point? It’s not like it makes any difference. His tweet will not protect you if you choose to make harmful changes to someone else’s stuff.

It may or may not make a difference with what happens in the court system, but I assure you there is a set of people who think the tweet would be permission to hijack a domain. And some of that set overlaps with the group that might accept the $10k challenge. Whether they actually follow-through and are able to, hopefully not. A bug bounty really ought to be thought out carefully.

>I assure you there is a set of people who think the tweet would be permission to hijack a domain. And some of that set overlaps with the group that might accept the $10k challenge.

And then from all those people you'd still need to find someone who 1) would successfully pull it off and 2) be stupid enough to demonstrate this in a damaging manner.

It’s also worth noting that this offer was made to only one person.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#50
Off topic- is there a way to see info on twitter without creating an account? I used to look at tweets from my local meteorologist on twitter but now I can’t seem to be able to view info on twitter without a modal blocking the window and asking me to sign uo
Post reply on HN