tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.
I know a few other people that were impacted.
81–90 of 190 posts
tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.
I know a few other people that were impacted.
Earlier quoted context omitted.
They're not even cheap these days, either. I'm still with them as a matter of laziness but I really need to migrate out.
Cloudflare offers domain registration/renewal with no markup if you're looking for an option. I moved to them after AWS increased fees.
This kind of story makes me wonder what's the most popular/valuable domain I can take control of simply by being convincing over the phone. Sounds tempting! I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!
Earlier quoted context omitted.
Did you have 2FA enabled too?
Password reset would bypass 2fa.
Namecheap forces users to log in to identify themselves. So far, OK. But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over -…
Link is just payments processing done by Stripe. https://stripe.com/payments/link If you've bought anything online recently, especially if it's not obvious who's collecting the payment details or it looks like first party on the checkout page, you've probably used Stripe.
Imagine going to a grocery store and when you want to buy your pack of soda and chips, they tell you: Woah there, pardner! You need an account with MyPaymentProvider before you pay for those groceries! Oh, and you'll need to set up a password and give them your mobile number...
Earlier quoted context omitted.
...seriously? Where do I jump ship to now?
Two more are NearlyFreeSpeech and UnstoppableDomains. The latter also supports crypto domains which have no chance of a takeover except by government order, although crypto domains require the client to install a browser extension or other software to resolve. The good thing about crypto domains is that there should be no renewal fee, although there will be a fee to update the record.
Earlier quoted context omitted.
Given Cloudflare's reputation for shakedowns once you pass their undisclosed thresholds I wouldn't trust them with my domains. I'm not expecting something for nothing, we all need to eat. I'm happy to stay within any limits or even have no free tier at all. I just don't want the fear of waking up to a sales email one morning demanding I suddenly fork out more then I earn in a year off the project for an enterprise pl…
Can you expand more on cloudflare's shakedowns? I have some domains on Cloudflare and thought they were a trustworthy service. Is there there anything particular you can point to?
Namecheap has been owned by a private equity firm for several months now. It would be nice to have a nonprofit registrar so jumping every few years isn't necessary.
This makes total sense to me. I'm not saying it solves all problems but it eliminates so many of them, including a meta problem: the risk of new classes of problems being unexpectedly introduced (by say a private equity acquisition or similar).
If domains themselves are the profit center, you are likely in trouble if there's really any incentive for them to make incremental revenue in such a competitive market. Doing 'the right thing' just of course will not factor in if there's really no reputation at stake.
Earlier quoted context omitted.
...seriously? Where do I jump ship to now?
Porkbun. Yes, Cloudflare Domains exists but let's support the small guys.
Earlier quoted context omitted.
Registration info usually also includes a physical address and names.
i agree that's important to hide, but also irrelevant to preventing what happened here.