Live data from Hacker News

Tell HN: Namecheap gave my account to an unverified third party

news.ycombinator.com

111–120 of 190 posts

Re: Tell HN: Namecheap gave my account to an unverified third party

#111

In the absence of actual details its hard to say what was considered for making this decision. If I have to take a wild guess then being able to demonstrate the control on the webserver hosting the content could have been one way to prove ownership over the domain. It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain. The part wher…

Webserver control is never used and must not be used to prove domain ownership. If you're pwned and have to re-point to a server stood up from backup, having registrar relying on someone being able to put up a random file on a compromised machine would be a total security disaster.

On a different note, adding a file on webserver is one of the ACME methods (HTTP-01) to get a SSL/TLS certificate so it is indeed considered as possession method in real world already

Re: Tell HN: Namecheap gave my account to an unverified third party

#113
post #20

Earlier quoted context omitted.

How is domain privacy relevant here? That only hides your email from public records. What if the attacker already knows it (as they did in this case)? Email address is quite literally something you are meant to share publicly. It is not a password.

I think their point was that if WHOIS data were hidden, a password reset request that relied on providing the email address would've been impossible. But since NC's account management allows visitors to provide just a domain name to generate an unlock email, domain privacy wouldn't be a protective layer here.

I still don’t get the argument. Say I call your bank and convince them to give me full control of your account. Are you going to go “well the bank didn’t publish my account number anywhere, so they are in the clear”?

Re: Tell HN: Namecheap gave my account to an unverified third party

#114
post #96

This kind of story makes me wonder what's the most popular/valuable domain I can take control of simply by being convincing over the phone. Sounds tempting! I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!

In many countries that’s probably illegal, even if it’s easy. Just because a crime is easy to commit doesn’t mean it isn’t a crime. So, keep it hypothetical.

I can’t think of a jurisdiction where it would not be illegal. The “I was only testing your security, in fact I should get rewarded for it” defense never works outside of nerd fantasies.

Re: Tell HN: Namecheap gave my account to an unverified third party

#115
post #113

Earlier quoted context omitted.

I think their point was that if WHOIS data were hidden, a password reset request that relied on providing the email address would've been impossible. But since NC's account management allows visitors to provide just a domain name to generate an unlock email, domain privacy wouldn't be a protective layer here.

I still don’t get the argument. Say I call your bank and convince them to give me full control of your account. Are you going to go “well the bank didn’t publish my account number anywhere, so they are in the clear”?

I agree, it's not an excuse to hand over an account. I think that commenter was considering practical mitigations for a broken system, not necessarily absolving NC of responsibility had my WHOIS been public.

Re: Tell HN: Namecheap gave my account to an unverified third party

#116

Namecheap forces users to log in to identify themselves. So far, OK. But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over -…

I just renewed my domain last February, I think, and didn't have to do that. When did that start?

Re: Tell HN: Namecheap gave my account to an unverified third party

#117

Earlier quoted context omitted.

Webserver control is never used and must not be used to prove domain ownership. If you're pwned and have to re-point to a server stood up from backup, having registrar relying on someone being able to put up a random file on a compromised machine would be a total security disaster.

On a different note, adding a file on webserver is one of the ACME methods (HTTP-01) to get a SSL/TLS certificate so it is indeed considered as possession method in real world already

You're missing that HTTP-01 challenge grants you no ability beyond what the check has demonstrated, i.e. you have proven that you're able to serve random file from a webserver, so the grant is to allow you to serve them via TLS connection.

There are no comparable _technical_ proof-of-registration methods because all of them would require actual access to registrar control panel and be outright silly ('point the domain to a random nameserver').

So no, proper registrars never use webserver control as means to prove identity or ownership.

Re: Tell HN: Namecheap gave my account to an unverified third party

#119

Scrolling through the current comments. In the meantime, been with NameCheap for I don't recall how long with no issues whatsoever.

Lack of a negative is the least compelling anecdote possible.

How about 16 years of lacking a negative? Does that count?

How about never heard of any issues till this unverified, anonymous thread. Shouldn't that make one suspicious of it? Does that count?

Re: Tell HN: Namecheap gave my account to an unverified third party

#120
post #70

I have important domains on Namecheap. Should I move them to Porkbun or Cloudflare? I only buy cheap, throwaway-type domains with Cloudflare, as I find them too corporate-like to support me for my cheap $10 domain, and that's why I kept good ones with Namecheap despite their 2x pricing. I want to work with an American company with real support. (But not with godaddy of course).

If you ignore this thread, did you even consider it before now? I've been with Namecheap for at least 16 years but this is the first I've read of complaints and never had any complaints myself. Which should make one question this whole thing altogether.
Post reply on HN