Live data from Hacker News

Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

twitter.com

51–60 of 99 posts

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#51

How else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this. (Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying th…

Thanks for your comment and you are correct with your latter point and assumption. It's hard to word things properly when you're limited with the amount of allowed characters on twitter.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#52
post #29

Earlier quoted context omitted.

None of what you’re saying is true. > Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing. Why do you think so? You don’t lose out on any legal protections without explicitly stating that.

I think you meant legal protections for the security researcher? I was talking about legal troubles for the Namecheap. Company can't encourage/allow security researchers to access private data of the users, at best this is against GDPR but it can also cause monetary damage to users which can be far worse.

No, this isn't "against GDPR".

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#53
post #22

Earlier quoted context omitted.

NameSilo or Cloudflare

As for Cloudflare I'd recommend NOT hosting your DNS with your domain name provider, just in case one of them does something stupid (but often if your domain goes sideways there's not much you can do anyway ...)

Like you said, if your registrar shuts down your domain it doesn't matter where your DNS is hosted. So your recommendation makes no sense.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#54
I'm way less upset by this than a large number of people in that twitter brawl. I can agree that this probably isn't the best way to go about things, but in the end, all I see is a CEO taking a firm stance of confidence behind his products - let's just hope this doesn't turn into a real bad situation for namecheap customers. Ballsy? Yeah. But pitchfork and torch worthy? Not really.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#55

How else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this. (Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying th…

> you'd be shocked how many people try to claim bug bounties from us because they "hacked" their own account using their own credentials.

Wait ...what? Like, seriously?

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#57
post #43
post #36

Earlier quoted context omitted.

My best guess for the second one is "human trafficking".

Or perhaps a Runescape fan. "buying gf, 100 gp" I wonder if they also have an armour trimming service.

I became overwhelmed with osrs flashbacks after reading this

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#59
post #50

Off topic- is there a way to see info on twitter without creating an account? I used to look at tweets from my local meteorologist on twitter but now I can’t seem to be able to view info on twitter without a modal blocking the window and asking me to sign uo

Replace twitter.com with nitter.net, that's worked for me

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#60

> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…

Or qualify with "harmless changes", like inserting a TXT entry with your name.

Namecheap's primary business is as a domain registrar. Sensible customers don't let their domain registrar act as their authoritative DNS, you'd need to change something else; but maybe mild defacement of the contact name or address in whois would qualify, without being harmful.
Post reply on HN