Live data from Hacker News

Tell HN: Namecheap gave my account to an unverified third party

news.ycombinator.com

11–20 of 190 posts

Re: Tell HN: Namecheap gave my account to an unverified third party

#11
I've been a long, long term customer of Namecheap as well.

Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.

The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.

This clearly isn't an answer for NC's customer support personnel and company policies.

But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.

Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.

Re: Tell HN: Namecheap gave my account to an unverified third party

#12
post #8

I've had the exact same issue with a small local registrar. Had an account where I managed multiple clients. One of the clients had their "IT guy" contact the registrar for a DNS change. The registrar promptly gave the guy full access to my account, changing the password and locking me out in the process. As soon as I regained access I moved everything off there.

Don’t be shy. Tell us the name.

This is unacceptable and such companies should change their policy or be out of business.

Re: Tell HN: Namecheap gave my account to an unverified third party

#13
post #11

I've been a long, long term customer of Namecheap as well. Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost. The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset. This clearly isn't an answer for NC…

I did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name.

I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.

Re: Tell HN: Namecheap gave my account to an unverified third party

#14

Just a few weeks ago I moved from Namecheap to Porkbun. That's not an advertisement - I simply Googled popular registrars. But it is an indictment of Namecheap. They are going the way of GoDaddy. Please move away from them immediately. They are shifting to short-term strategies (high prices, immoral data practices, etc). Edit: Apparently they were bought by private equity just weeks before I noticed something was wro…

Is it time to change registrars already? I fled Gandi a while ago because of private equity fuckery. And now I need to go somewhere else. Who won't adopt enshitification-as-a-business-plan for a few years? No wonder people are leaving tech to go be goat farmers.

I am also looking for something that will last for a good while.

Re: Tell HN: Namecheap gave my account to an unverified third party

#15

Just a few weeks ago I moved from Namecheap to Porkbun. That's not an advertisement - I simply Googled popular registrars. But it is an indictment of Namecheap. They are going the way of GoDaddy. Please move away from them immediately. They are shifting to short-term strategies (high prices, immoral data practices, etc). Edit: Apparently they were bought by private equity just weeks before I noticed something was wro…

Is it time to change registrars already? I fled Gandi a while ago because of private equity fuckery. And now I need to go somewhere else. Who won't adopt enshitification-as-a-business-plan for a few years? No wonder people are leaving tech to go be goat farmers.

> Who won't adopt enshitification-as-a-business-plan for a few years?

I don't have a crystal ball, but NearlyFreeSpeech was recommended to me in 2010 and I've been using it since 2012. I don't think it's changed at all in that time.

https://www.nearlyfreespeech.net/services/domains

https://www.nearlyfreespeech.net/services/respect

Re: Tell HN: Namecheap gave my account to an unverified third party

#17

Just a few weeks ago I moved from Namecheap to Porkbun. That's not an advertisement - I simply Googled popular registrars. But it is an indictment of Namecheap. They are going the way of GoDaddy. Please move away from them immediately. They are shifting to short-term strategies (high prices, immoral data practices, etc). Edit: Apparently they were bought by private equity just weeks before I noticed something was wro…

Is it time to change registrars already? I fled Gandi a while ago because of private equity fuckery. And now I need to go somewhere else. Who won't adopt enshitification-as-a-business-plan for a few years? No wonder people are leaving tech to go be goat farmers.

[deleted]

Re: Tell HN: Namecheap gave my account to an unverified third party

#18
post #11

I've been a long, long term customer of Namecheap as well. Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost. The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset. This clearly isn't an answer for NC…

I did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name. I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.

Glad you posted your experience. I'll definitely be keeping my eye out for shenanigans on my own domains.

Re: Tell HN: Namecheap gave my account to an unverified third party

#20
post #11

I've been a long, long term customer of Namecheap as well. Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost. The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset. This clearly isn't an answer for NC…

How is domain privacy relevant here? That only hides your email from public records. What if the attacker already knows it (as they did in this case)? Email address is quite literally something you are meant to share publicly. It is not a password.
Post reply on HN