How else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this. (Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying th…
Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
51–60 of 99 posts
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#52Earlier quoted context omitted.
None of what you’re saying is true. > Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing. Why do you think so? You don’t lose out on any legal protections without explicitly stating that.
I think you meant legal protections for the security researcher? I was talking about legal troubles for the Namecheap. Company can't encourage/allow security researchers to access private data of the users, at best this is against GDPR but it can also cause monetary damage to users which can be far worse.
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#53Earlier quoted context omitted.
NameSilo or Cloudflare
As for Cloudflare I'd recommend NOT hosting your DNS with your domain name provider, just in case one of them does something stupid (but often if your domain goes sideways there's not much you can do anyway ...)
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#54Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#55How else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this. (Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying th…
Wait ...what? Like, seriously?
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#56Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#57Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#58He doesn't even want to know how you did it.
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#59Off topic- is there a way to see info on twitter without creating an account? I used to look at tweets from my local meteorologist on twitter but now I can’t seem to be able to view info on twitter without a modal blocking the window and asking me to sign uo
Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
#60> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…
Or qualify with "harmless changes", like inserting a TXT entry with your name.