Live data from Hacker News

Namecheap announces support for TOTP-based 2FA

namecheap.com

21–27 of 27 posts

Re: Namecheap announces support for TOTP-based 2FA

#21
TOTP is far too easily phishable. User studies have shown that in any large organisation, some small percentage of even the most technical staff will enter an OTP into a phishing page. You might think 'I'm not that dumb', but study after study shows you are!

The future is hardware U2F tokens. They can securely check the web-origin of a request and only give the token to the correct origin.

Re: Namecheap announces support for TOTP-based 2FA

#22

TOTP is far too easily phishable. User studies have shown that in any large organisation, some small percentage of even the most technical staff will enter an OTP into a phishing page. You might think 'I'm not that dumb', but study after study shows you are! The future is hardware U2F tokens. They can securely check the web-origin of a request and only give the token to the correct origin.

Depends on your threat model, not everyone is going to pay for a hardware U2F . Not every application needs that high security. TOTP is an option definitely better than just plain password, which is what most services use today

Re: Namecheap announces support for TOTP-based 2FA

#23
post #9

Earlier quoted context omitted.

Sorry for the thread hijack, but: Let's Encrypt. Ever going to roll it out? I plan to switch away from Namecheap soon unless it's implemented, it's really disappointing to me.

Hello Fej, to be honest, we signed an exclusive contract with Comodo before Let's Encrypt even existed. The length of that contract is ten years. It's put us in a tough situation as far as what we can offer out of the box to our customers. While our customers can still install LE on our hosting services on their own, we can't actively do this for them. The only other option here is to break that contract which will c…

So we can expect it in 2024 then?

Re: Namecheap announces support for TOTP-based 2FA

#24
I hated having to use a proprietary app for this (even if it was based on the Authy SDK), so this is a nice improvement.

I'd really like to see U2F support though as well, domains are very valuable assets and deserve the strongest protection possible.

Re: Namecheap announces support for TOTP-based 2FA

#25
post #8

Their old one was so bad I actually learned how to use route 53 just to migrate out of it. Their CEO is just pretending to be forthright here. I have a tweet where he replied to me from February 2014 that said Google Auth support is coming in a couple of months. This all happened because I got locked out of my namecheap account when THEIR system wouldn't sms me the code and they had problems with the voice calling. S…

Maybe I'm missing something (or just lucky) :-), but I have been using Namecheap for years (and recommended them to others) and I haven't had issue with the 2FA. What's the specific issue? Thanks.

Re: Namecheap announces support for TOTP-based 2FA

#26

Earlier quoted context omitted.

Any idea why companies would choose a proprietary 2FA solution? I see this with European banks all the time.

Honestly, we seriously dropped the ball trying something new. It was a mistake on my part and a bad decision looking back. I posted about it on our blog here https://www.namecheap.com/blog/true-totp-2fa-and-u2f-are-com...

I requested this multiple times in surveys you presented me. Thank you for finally implementing it! I feel like my input was actually worth it!

Re: Namecheap announces support for TOTP-based 2FA

#27
post #9

Earlier quoted context omitted.

Sorry for the thread hijack, but: Let's Encrypt. Ever going to roll it out? I plan to switch away from Namecheap soon unless it's implemented, it's really disappointing to me.

Hello Fej, to be honest, we signed an exclusive contract with Comodo before Let's Encrypt even existed. The length of that contract is ten years. It's put us in a tough situation as far as what we can offer out of the box to our customers. While our customers can still install LE on our hosting services on their own, we can't actively do this for them. The only other option here is to break that contract which will c…

Sorry for the low quality comment but what a nice thing to say.

You guys are hosting my email and I couldn't be happier.

Post reply on HN