Live data from Hacker News

Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

twitter.com

71–80 of 99 posts

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#71
post #52

Earlier quoted context omitted.

I think you meant legal protections for the security researcher? I was talking about legal troubles for the Namecheap. Company can't encourage/allow security researchers to access private data of the users, at best this is against GDPR but it can also cause monetary damage to users which can be far worse.

No, this isn't "against GDPR".

If this tweet is being interpreted as namecheap granting permission to someone to try and access customers' data, it actually is against GDPR for namecheap to do so.

As data controller, namecheap has the following duty "the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject." (GDPR 28.1)

Of course, if that tweet is treated as empty boasting, then there are no consequences - but if you take it at face value, namecheap is granting permission to access data without a proper limiting contract, and it is explicitly illegal for namecheap to do so (GDPR 28.3 - "Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller"); they have a duty to ensure that any subcontractors or licensees or partners or whatever accessing the data do so only in a strictly controlled manner.

This is why every proper external pentest in EU will have explicit GDPR clauses about the limitations of personal data handling if the pentester/auditor has any chance of accessing systems with such data - it's not acceptable for a company to hire external auditors without such restrictions, they can't simply grant access to other peoples' data to third parties.

And before someone says "...but terms&conditions..", no, terms and conditions can't override law, these restrictions apply no matter what namecheap has contracted with the individuals whose data they're storing. There are some clauses of GDPR which state "don't do X without informing the data subject" (in which case the T&C might inform the customer that you'll be doing X) but that's not the case for these requirements.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#72

How else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this. (Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying th…

Thanks for your comment and you are correct with your latter point and assumption. It's hard to word things properly when you're limited with the amount of allowed characters on twitter.

kek I thought this was a troll account until I saw your post history. I like your straight forward approach to username creation.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#73
post #52

Earlier quoted context omitted.

No, this isn't "against GDPR".

If this tweet is being interpreted as namecheap granting permission to someone to try and access customers' data, it actually is against GDPR for namecheap to do so. As data controller, namecheap has the following duty "the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of t…

> If this tweet is being interpreted as namecheap granting permission to someone to try and access customers' data, it actually is against GDPR for namecheap to do so.

I’m not sure that’s a credible interpretation, the CEO betting against you being able to work around their data protection measures does not turn you into a processor.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#74

Earlier quoted context omitted.

I think that's reasonable. I was thinking in terms of cutting out the gaming aspect when I made that statement. I probably should have been more specific. The premise of the entire conversation was based on someone making an unjustified accusation without even following it through and testing it to begin with.

Quoted post unavailable.

https://stallman.org/articles/on-hacking.html

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#75
post #55

How else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this. (Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying th…

> you'd be shocked how many people try to claim bug bounties from us because they "hacked" their own account using their own credentials. Wait ...what? Like, seriously?

I'd say that >90% of "security incidents" that I've seen reported are completely bogus. And we don't even have a bug bounty program. They will still beg for free stuff like t-shirts and other tiddletat.

I think the majority is just ignorance rather than malice though.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#76
post #64
post #37

Earlier quoted context omitted.

The kingofkyiv account frequently tries to plug their sketchy eastern-european-women-"love"-connection huckster website on HN. Preying on desperate nerds could be profitable.

That's what the first site is. Wtf is the second one??

Not going to click through to find out, I want nothing to do with KoK. Confident they don't have our best interests at heart.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#77
post #73

Earlier quoted context omitted.

If this tweet is being interpreted as namecheap granting permission to someone to try and access customers' data, it actually is against GDPR for namecheap to do so. As data controller, namecheap has the following duty "the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of t…

> If this tweet is being interpreted as namecheap granting permission to someone to try and access customers' data, it actually is against GDPR for namecheap to do so. I’m not sure that’s a credible interpretation, the CEO betting against you being able to work around their data protection measures does not turn you into a processor.

The big question is whether CEO betting against you being able to work around their data protection counts as namecheap permitting you to access that data.

If it does not (which IMHO is a reasonable interpretation), there is no issue and that's just empty boasting. But if it does, that's a violation - GDPR prohibits namecheap to allow anyone outside of company to handle that data without a proper controller-processor contract.

Not being a processor is a bad thing in this case, because being a processor is the only way how this can proceed legally. If you're not a processor, it's a violation for namecheap to give you that data; and if you're not a processor, it's a violation for you to process that data since you're also not a controller, you did not legally obtain this from the data subject, this is also not a purely household activity, no other exceptions seem to apply so the default condition applies i.e. that it's illegal for you to handle that data as you have no legal basis permitting it. (GDPR is a deny-by-default law; processing of private data is lawful if and only if specific conditions listed in GDPR are met. If some private data 'fell out of a truck', you can't legally do stuff with it).

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#78
post #49

Earlier quoted context omitted.

It may or may not make a difference with what happens in the court system, but I assure you there is a set of people who think the tweet would be permission to hijack a domain. And some of that set overlaps with the group that might accept the $10k challenge. Whether they actually follow-through and are able to, hopefully not. A bug bounty really ought to be thought out carefully.

>I assure you there is a set of people who think the tweet would be permission to hijack a domain. And some of that set overlaps with the group that might accept the $10k challenge. And then from all those people you'd still need to find someone who 1) would successfully pull it off and 2) be stupid enough to demonstrate this in a damaging manner. It’s also worth noting that this offer was made to only one person.

Arguably the offer was made to everyone. I don't know about your other point because, like I said in my post I think those people may exist. Perhaps you don't, but, you kind of made the initial statement that it doesn't matter, right? So isn't it on you to prove it?

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#79
post #49

Earlier quoted context omitted.

>I assure you there is a set of people who think the tweet would be permission to hijack a domain. And some of that set overlaps with the group that might accept the $10k challenge. And then from all those people you'd still need to find someone who 1) would successfully pull it off and 2) be stupid enough to demonstrate this in a damaging manner. It’s also worth noting that this offer was made to only one person.

Arguably the offer was made to everyone. I don't know about your other point because, like I said in my post I think those people may exist. Perhaps you don't, but, you kind of made the initial statement that it doesn't matter, right? So isn't it on you to prove it?

> Arguably the offer was made to everyone

How so? It’s clearly a tweet to a single individual.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#80

> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…

I think that's reasonable. I was thinking in terms of cutting out the gaming aspect when I made that statement. I probably should have been more specific. The premise of the entire conversation was based on someone making an unjustified accusation without even following it through and testing it to begin with.

>without even following it through and testing it to begin with

You do realize that many companies will prosecute people just "following through and testing it", right?

Though the person you did say it to very likely has an international warrant out for them anyway for pissing off the DoD, so I guess it's all water under the bridge.

Post reply on HN