Live data from Hacker News

Namecheap vulnerability they refuse to fix: no 2FA on support portal login

crimew.gay

1–10 of 99 posts

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#2
Not OP of this post, just came across it. I'm a heavy namecheap user, and will continue to use them, but this did make me a little concerned. From the post:

> so, setting up 2fa on namecheap prevents anyone from just logging into your account if your credentials get leaked or stolen. great, they can't just manage your domains. HOWEVER, the namecheap support portal (at http://support.namecheap.com) uses the same credentials for login BUT it never asks for 2fa. if you get leaked credentials you can just sign in to the support portal. because of how badly designed it is you can even change the support email for the account with no confirmation and no info being sent out to the old email.

> how is that a big deal?

> well, you can just open domain transfer tickets from the support portal and hijack domains anyways, you can probably even pretend to not understand how anything works and ask them to change dns for you, etc...

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#4
When switching away from DreamHost, I researched different domain registrars. I chose to try Namecheap and Dynadot, so I sent half of my domains to Namecheap, and the other half to Dynadot.

After the transfer lock peroid, I moved my domains from Namecheap to Dynadot. The prices were pretty much the same, but the interface was better, and Dynadot also passes on "name tasting" to the user (users can request a refund if they change their mind after buying a domain name).

I've also sinced used Dynadot's customer service one time, and it was good.

My only gripe with Dynadot is at the login screen: I set up 2FA, and they call it a "Google code", when you can use any other 2FA manager besides Google.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#5

Quoted post unavailable.

> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from

Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#6
post #5

Quoted post unavailable.

> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed

I doubt it was their customers bombing them. If anything, taking money out of the country should be a good thing if they don't want to support that country.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#7
post #5

Quoted post unavailable.

> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with Russia). Totally irresponsible and criminally negligent behavior for any registrar. I hope they get sued for for breaking their own contracts and causing widespread destruction via malware.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#8
post #5

Earlier quoted context omitted.

> randomly cancelling thousands of peoples domains on short notice simply due to the country they are from Not wrong, but for more context, they made their Russian customers transfer their domains, when their Ukrainian offices started getting shelled by Russian invaders. It’s hard to stay politically neutral when your staff are literally being bombed

Choosing not to allow renewals would have been been acceptable but they straight cancelled those domains prematurely before the term of registration had ended. Basically pulling the rug out from underneath people without giving them adequate time to migrate. Allowing domains to be sniped by unscrupulous parties who put malware on them which hurt many thousands of people (mostly foreigners who had nothing to do with R…

No post body was provided.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#9

Quoted post unavailable.

> It’s one of those cheap bottom of the barrel vendors which of course takes shortcuts to make the price so cheap.

NameCheap is only the cheapest for _one_ TLD in terms of renewal cost (https://tld-list.com/registrars). Love that site.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#10

Quoted post unavailable.

> It’s one of those cheap bottom of the barrel vendors which of course takes shortcuts to make the price so cheap. NameCheap is only the cheapest for _one_ TLD in terms of renewal cost ( https://tld-list.com/registrars ). Love that site.

Huh I guess they are just taking shortcuts to enrich themselves then - even less noble than I’d thought.
Post reply on HN