Live data from Hacker News

Namecheap announces support for TOTP-based 2FA

namecheap.com

11–20 of 27 posts

Re: Namecheap announces support for TOTP-based 2FA

#11
post #9

Earlier quoted context omitted.

Honestly, we seriously dropped the ball trying something new. It was a mistake on my part and a bad decision looking back. I posted about it on our blog here https://www.namecheap.com/blog/true-totp-2fa-and-u2f-are-com...

Sorry for the thread hijack, but: Let's Encrypt. Ever going to roll it out? I plan to switch away from Namecheap soon unless it's implemented, it's really disappointing to me.

Hello Fej, to be honest, we signed an exclusive contract with Comodo before Let's Encrypt even existed. The length of that contract is ten years. It's put us in a tough situation as far as what we can offer out of the box to our customers. While our customers can still install LE on our hosting services on their own, we can't actively do this for them. The only other option here is to break that contract which will cost us millions of dollars and it's something that I continue to consider.

Re: Namecheap announces support for TOTP-based 2FA

#12

It's about time. This has been a wish list item for years. They had a proprietary 2FA option but that was a non-starter for me.

Any idea why companies would choose a proprietary 2FA solution? I see this with European banks all the time.

I don't know about Namecheap, but I'd suspect the banks use proprietary solutions for the standard 2 reasons: 1) Something expensive feels more secure. The 50yo farts in suits are the ones making the decisions, not the devs who actually know why open standards are inherently more secure. 2) They have someone to blame when something goes wrong. If they implement TOTP insecurely and data gets stolen, they're on the hook. If RSA (or whoever else) screws up, the bank can point their finger at them since their programmers are usually the ones who do the integration.

Re: Namecheap announces support for TOTP-based 2FA

#13
post #6

Earlier quoted context omitted.

I was one of the people who wrote long support requests to you guys detailing how much I disliked the system you had in place. I really respect your forthrightness here.

Thank you, I need to explicitly call out our/my shortcomings if we want to improve as a company going forward. We are making big changes to the way we are doing things and a commitment to full transparency and having open and honest conversations with our customers are the biggest of those.

Thanks Richard for being honest, this is why I choose namecheap

Re: Namecheap announces support for TOTP-based 2FA

#14
post #8

Their old one was so bad I actually learned how to use route 53 just to migrate out of it. Their CEO is just pretending to be forthright here. I have a tweet where he replied to me from February 2014 that said Google Auth support is coming in a couple of months. This all happened because I got locked out of my namecheap account when THEIR system wouldn't sms me the code and they had problems with the voice calling. S…

Agreed, there was a big issue with the communication about 2FA. And then the proprietary app was rolled out, in what seemed more like a checkbox ticking exercise. At that point I also migrated and haven't looked back.

Why a checkbox ticking exercise? Even the Oct 2018 post by the CEO [1] says "[...] our proprietary app, was not well-received by many of you and did not serve you in the way many of you preferred to use 2FA." Apart from being such bullshit corpo speak, how was one single second factor device per person sufficient for critical infrastructure? What was I supposed to do, buy two phones? If a place is so clueless about 2FA, run. You can almost be sure they don't use 2FA internally.

(While I'm here, allow me to name and shame Patreon, who used to support TOTP, but removed that option and now only have SMS [2])

[1] https://www.namecheap.com/blog/true-totp-2fa-and-u2f-are-com...

[2] https://support.patreon.com/hc/en-us/articles/206538086-How-...

Re: Namecheap announces support for TOTP-based 2FA

#15
post #8

Their old one was so bad I actually learned how to use route 53 just to migrate out of it. Their CEO is just pretending to be forthright here. I have a tweet where he replied to me from February 2014 that said Google Auth support is coming in a couple of months. This all happened because I got locked out of my namecheap account when THEIR system wouldn't sms me the code and they had problems with the voice calling. S…

Agreed, there was a big issue with the communication about 2FA. And then the proprietary app was rolled out, in what seemed more like a checkbox ticking exercise. At that point I also migrated and haven't looked back. Why a checkbox ticking exercise? Even the Oct 2018 post by the CEO [1] says "[...] our proprietary app, was not well-received by many of you and did not serve you in the way many of you preferred to use…

No excuses, you're right, we made a bad decision then and losing customers like you was the consequence of that. I apologize for that and any other negative experiences you may have had with us due to this.

Re: Namecheap announces support for TOTP-based 2FA

#16

Earlier quoted context omitted.

Agreed, there was a big issue with the communication about 2FA. And then the proprietary app was rolled out, in what seemed more like a checkbox ticking exercise. At that point I also migrated and haven't looked back. Why a checkbox ticking exercise? Even the Oct 2018 post by the CEO [1] says "[...] our proprietary app, was not well-received by many of you and did not serve you in the way many of you preferred to use…

No excuses, you're right, we made a bad decision then and losing customers like you was the consequence of that. I apologize for that and any other negative experiences you may have had with us due to this.

I do respect you for stepping up here, and my experience with Namecheap was very good (barring 2FA). I guess it comes down to trust, which is hard to gauge.

The other thing that would stop me from returning to or recommending Namecheap is GDPR compliance, or lack thereof. While I don't expect you to fight ICANN, it's a blocker. (Obviously, not many registrars offering compliance at the moment...)

Re: Namecheap announces support for TOTP-based 2FA

#17

Earlier quoted context omitted.

No excuses, you're right, we made a bad decision then and losing customers like you was the consequence of that. I apologize for that and any other negative experiences you may have had with us due to this.

I do respect you for stepping up here, and my experience with Namecheap was very good (barring 2FA). I guess it comes down to trust, which is hard to gauge. The other thing that would stop me from returning to or recommending Namecheap is GDPR compliance, or lack thereof. While I don't expect you to fight ICANN, it's a blocker. (Obviously, not many registrars offering compliance at the moment...)

While we still have some gaps around GDPR we have active workstreams to close them. We've also rolled out free privacy protection to all of our customers, not just those in the EU. I can also say that we've always been extremely careful with sharing any customer data with third parties even before GDPR came into the conversation. Customer privacy is not something I believe should ever be compromised on. While we've made some dumb decisions, I can assure you it was always well intended. Even our previous lack of speed to fixes was due to us making a conscious decision to go back and rebuild our entire infrastructure and code base so that we can be more flexible and agile in the future. It was a hard sacrifice to make and it affected our customers negatively but I believe it will lead to a better future with what we'll be able to deliver to our customers in terms of effectively and seamlessly solving their problems. Hopefully you'll come back some time in the future and you can judge us by our actions and what we are building and delivering and not just my words.

Re: Namecheap announces support for TOTP-based 2FA

#18
post #9

Earlier quoted context omitted.

Sorry for the thread hijack, but: Let's Encrypt. Ever going to roll it out? I plan to switch away from Namecheap soon unless it's implemented, it's really disappointing to me.

Hello Fej, to be honest, we signed an exclusive contract with Comodo before Let's Encrypt even existed. The length of that contract is ten years. It's put us in a tough situation as far as what we can offer out of the box to our customers. While our customers can still install LE on our hosting services on their own, we can't actively do this for them. The only other option here is to break that contract which will c…

Really appreciate the transparency shown in this comment. I recently moved away from Namecheap after 10 years of it being my primary registrar (mainly because of the crappy 2FA) but this is certainly making me reconsider.

Re: Namecheap announces support for TOTP-based 2FA

#19
post #18

Earlier quoted context omitted.

Hello Fej, to be honest, we signed an exclusive contract with Comodo before Let's Encrypt even existed. The length of that contract is ten years. It's put us in a tough situation as far as what we can offer out of the box to our customers. While our customers can still install LE on our hosting services on their own, we can't actively do this for them. The only other option here is to break that contract which will c…

Really appreciate the transparency shown in this comment. I recently moved away from Namecheap after 10 years of it being my primary registrar (mainly because of the crappy 2FA) but this is certainly making me reconsider.

[deleted]

Re: Namecheap announces support for TOTP-based 2FA

#20
post #18

Earlier quoted context omitted.

Hello Fej, to be honest, we signed an exclusive contract with Comodo before Let's Encrypt even existed. The length of that contract is ten years. It's put us in a tough situation as far as what we can offer out of the box to our customers. While our customers can still install LE on our hosting services on their own, we can't actively do this for them. The only other option here is to break that contract which will c…

Really appreciate the transparency shown in this comment. I recently moved away from Namecheap after 10 years of it being my primary registrar (mainly because of the crappy 2FA) but this is certainly making me reconsider.

Thank you and I'm sorry to hear that you left us. Please do try and check back with us at some point. I believe you'll see a difference in our approach to how we do things and the decisions we make going forward.
Post reply on HN