Live data from Hacker News

Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

twitter.com

31–40 of 99 posts

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#31
post #26

If the result of this tweet is that one of my domains is altered, and that I lose income, users, or other useful metrics to measure the value of my site, this seems like a great piece of evidence to be litigious towards Namecheap

How is this different from any other bug bounty program as an incentive to compromise live functionality/user data always exists?

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#33
post #23

Earlier quoted context omitted.

Or qualify with "harmless changes", like inserting a TXT entry with your name.

Whats the point? It’s not like it makes any difference. His tweet will not protect you if you choose to make harmful changes to someone else’s stuff.

It may or may not make a difference with what happens in the court system, but I assure you there is a set of people who think the tweet would be permission to hijack a domain. And some of that set overlaps with the group that might accept the $10k challenge. Whether they actually follow-through and are able to, hopefully not.

A bug bounty really ought to be thought out carefully.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#35
post #31
post #26

If the result of this tweet is that one of my domains is altered, and that I lose income, users, or other useful metrics to measure the value of my site, this seems like a great piece of evidence to be litigious towards Namecheap

How is this different from any other bug bounty program as an incentive to compromise live functionality/user data always exists?

It’s the difference between stepping in a bear trap and poking a lion.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#37
post #34

Quoted post unavailable.

> kingofkyiv.com > buyagf.com What the hell am I looking at?

The kingofkyiv account frequently tries to plug their sketchy eastern-european-women-"love"-connection huckster website on HN.

Preying on desperate nerds could be profitable.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#38

> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…

Or qualify with "harmless changes", like inserting a TXT entry with your name.

Inserting a TXT entry isn't a harmless change these days, because it's one way to authenticate ownership of a domain. Like recovering a google apps admin login.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#39

Isn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward. https://www.techtimes.com/articles/271004/20220125/apple-rew... https://www.pcgamer.com/security-researchers-aka-hackers-mak...

Not really, they don't often advertise that you should attack their customers directly. The closest I can remember was the LifeLock guy putting his social security number up publicly. Otherwise, they prefer you hit test or personal accounts rather than paying customers...

> The closest I can remember was the LifeLock guy putting his social security number up publicly.

ha. Did anything "good" (or bad) come of this?

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#40

Earlier quoted context omitted.

Not really, they don't often advertise that you should attack their customers directly. The closest I can remember was the LifeLock guy putting his social security number up publicly. Otherwise, they prefer you hit test or personal accounts rather than paying customers...

> The closest I can remember was the LifeLock guy putting his social security number up publicly. ha. Did anything "good" (or bad) come of this?

quick search:

> Davis publicly posted his Social Security number as part of a 2007 ad campaign to promote the company's identity theft protection services. However, Davis was a victim of 13 cases of identity theft between 2007 and 2008.

https://en.wikipedia.org/wiki/LifeLock#:~:text=Davis%20publi....

Post reply on HN