Live data from Hacker News

Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

twitter.com

21–30 of 99 posts

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#21

Isn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward. https://www.techtimes.com/articles/271004/20220125/apple-rew... https://www.pcgamer.com/security-researchers-aka-hackers-mak...

Well the CEO said they didnt think it was a problem because there is additional security (also a pin code required) to access the account. That is pretty standard for big companies. Saying that actually isnt a problem and either not fixing it or fixing it and not paying a bounty on it.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#22

Guess I should move elsewhere. What is everyone using for domains and DNS these days?

NameSilo or Cloudflare

As for Cloudflare I'd recommend NOT hosting your DNS with your domain name provider, just in case one of them does something stupid (but often if your domain goes sideways there's not much you can do anyway ...)

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#23

> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…

Or qualify with "harmless changes", like inserting a TXT entry with your name.

Whats the point? It’s not like it makes any difference. His tweet will not protect you if you choose to make harmful changes to someone else’s stuff.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#24

Really glad I moved my domains to Porkbun recently. This is Namecheaps second blunder this year in terms of being a reliable service provider. First engaging in politically cheap racial discrimination (their ban on Russia seemingly having hit anyone who ever in their history used a Russian IP adress and demanding evidence of a users current location before lifting it), now giving hackers carte blanche to screw with e…

Oh yeah, it’s truly shocking that a company with most of their staff in Ukraine decided to cut off Russia.

What unreliable pieces of shit. How dare they?

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#25

Guess I should move elsewhere. What is everyone using for domains and DNS these days?

Time to move somewhere else because the CEO is so confident they can't be hacked he publically offers money to anyone who can do it? You want to be with one that thinks it is insecure?

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#27

> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…

No post body was provided.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#29

Isn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward. https://www.techtimes.com/articles/271004/20220125/apple-rew... https://www.pcgamer.com/security-researchers-aka-hackers-mak...

No, this is illegal and can put namespace into huge trouble. Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing. This is why legal departments exist, you cannot just say this as a CEO without consulting to your advisors.

None of what you’re saying is true.

> Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing.

Why do you think so? You don’t lose out on any legal protections without explicitly stating that.

Post reply on HN