Live data from Hacker News

Namecheap vulnerability they refuse to fix: no 2FA on support portal login

crimew.gay

91–99 of 99 posts

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#91
While this incident is certainly concerning a bigger question is which registrars can properly ward off attempts at social-engineering and other account access fraud and not sweep it under the rug. Even seemingly well intentioned companies utilize plain-text email for customer communication which is not exactly reassuring either.

MarkMonitor used to be a thing. Trusted by big companies but even the act of attempting to get information about their services has been met with difficulty. Regardless they have been acquired by an investment firm and there has been some concerns of quality-of-service because of that.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#92
post #28

Earlier quoted context omitted.

Why not just buy the domains directly from cloudflare then?

Cloudflare's domain management has sadly also had some questionable actions/decisions. 0: https://news.ycombinator.com/item?id=31573854 1: https://community.cloudflare.com/t/domain-not-working-after-...

I have over 20 domains with cloudflare. I have been transferring all my domains to cloudflare one by one over the years and now I am worried about getting randomly flagged like this.

Does anyone know if cloudflare has provided any justification?

Are we at HN's mercy to publically shame them to get them to fix this if it's happens to us?

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#94

Earlier quoted context omitted.

They gave less than two weeks: at Feb 28 people recived the letters about "asking" to GTFO by March 6, 2022. I would just point to my comment back then: https://news.ycombinator.com/item?id=30507975 Also I would remind you what other services were cut immediately: > Additionally, and with immediate effect, you will no longer be able to use Namecheap Hosting, EasyWP, and Private Email with a domain provided by another…

The original date was March 6 but was extended to March 22. https://www.theverge.com/2022/3/1/22956581/russia-ukraine-na...

You know, "gave plenty of time (1 week)" and "gave plenty of time ONLY AFTER PEOPLE ACTIVELY COMPLAINED (still less than 4 weeks)" are two different things.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#95
post #73

I’m really glad I migrated off Namecheap. Was a long time customer but when they had that massive dnssec outage and their support had no idea what it was doing, that was the last straw for me. I moved everything over to google (I know I know) and haven’t had a single second of downtime. Would love ideas for better alternatives, preferably privacy oriented.

> dnssec outage

DNSSEC signing happens at the nameservers run by the registry (verisign for .com, for example). Unless it was an issue with their API servers not properly calling the upstream APIs, I don't think namecheap is to blame here.

I personally think namecheap is dangerously close to being the next Godaddy, but I wouldn't hold DNSSEC issues against Namecheap any other registrar.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#96

I really don't understand why people are still using this amateur site. Please don't give money to these idiots when they have better alternatives.

What are some of your favorite alternatives?

Porkbun has always been pretty solid. They support 2FA with TOTP and HOTP, the support is no bullshit email support that's reasonably fast, and the prices are quite low too.

Not affiliated, just a happy customer paying about $500 a year for a bunch of domains at Porkbun.

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#97
post #95
post #73

I’m really glad I migrated off Namecheap. Was a long time customer but when they had that massive dnssec outage and their support had no idea what it was doing, that was the last straw for me. I moved everything over to google (I know I know) and haven’t had a single second of downtime. Would love ideas for better alternatives, preferably privacy oriented.

> dnssec outage DNSSEC signing happens at the nameservers run by the registry (verisign for .com, for example). Unless it was an issue with their API servers not properly calling the upstream APIs, I don't think namecheap is to blame here. I personally think namecheap is dangerously close to being the next Godaddy, but I wouldn't hold DNSSEC issues against Namecheap any other registrar.

It’s been a while but I recall it was a Namecheap issue.

https://ianix.com/pub/dnssec-outages/20190221-namecheap/

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#98
post #18

I once had a domain at Namecheap show "Ownership change pending approval" to another username with a cancel link beside it and I recognized the username as someone who made offers before out of band. Never got an email or saw any kind of notification, and I've been in the game 25 years and know those extremely long domain transfer emails and read them carefully. Started transferring domains away after that.

What alternative host would you recommend?

I’m quite happy with Glauca [1], they’re not quite as cheap but their DNS stuff is pretty good and they are friendly and helpful. Only downside is their website being a bit slow sometimes.

[1] https://glauca.digital

Re: Namecheap vulnerability they refuse to fix: no 2FA on support portal login

#99
post #96

Earlier quoted context omitted.

What are some of your favorite alternatives?

Porkbun has always been pretty solid. They support 2FA with TOTP and HOTP, the support is no bullshit email support that's reasonably fast, and the prices are quite low too. Not affiliated, just a happy customer paying about $500 a year for a bunch of domains at Porkbun.

Thanks!
Post reply on HN