Namecheap vulnerability they refuse to fix: no 2FA on support portal login
crimew.gay
crimew.gay
If the CTO or CEO or whatever C-level comes on here to do damage control every now and then tries to disagree (probably citing how big their $3/hour Eastern European legal team is) keep in mind it's all PR junk and the proof is in the pudding. It's been years -- no action, no change. Just more scams.
They are usually praised for how fast they take down phishing domains though
The argument that NameCheap (and its supporters) provide is that this is a good thing that makes them stay because NameCheap shouldn't be policing domains or some other free speech nonsense ignoring that this is pure facilitation of crime. Ignoring that this is blatantly violating their own T&Cs and the ICANN guidelines.
No, the argument is it's either this "free speech nonsense" or gestapo filtration like the Apple's/Google's app review process, where the big company is the judge and the jury, and I prefer the former.
The domain is even listed on the USPTO site as a scam operation [2], yet no action has been taken yet.
[1] Looks like this: https://www.uspto.gov/sites/default/files/documents/WTP%20Tr...
[2] https://www.uspto.gov/trademarks/protect/caution-misleading-...
I've seen your previous 2020 HN submission on this about Namecheap hosting the domains used in SMS scams: https://news.ycombinator.com/item?id=24231307
https://shkspr.mobi/blog/2021/05/why-do-scammers-love-namech...
https://www.ncsc.gov.uk/files/Active-Cyber-Defence-ACD-The-F...
> 2017: As of today around 38% of the domains reported to us since we began recording on 8/23/17 are sponsored by NameCheap INC. These domains are allowed to continue to scam consumers long after they are reported. An example of this is “ecojetexpress.us” which has been reported repeatedly by both petscams.com and victims who have lost money. When victims of this scam filed an abuse report NameCheap did not “take reasonable and prompt steps to investigate”. Instead they forwarded the abuse report with the victims information to the criminal. 5 months later, ecojetexpress.us was still online scamming new victims.
https://petscams.com/news/namecheap-hurting-internet/
> Facebook sues Namecheap to unmask hackers who registered malicious domains. The social networking giant claims that Namecheap has refused to cooperate in an investigation into a series of malicious domains that have been registered through its service and which impersonated the Facebook brand.
> Some of the sample domains included the likes of instagrambusinesshelp.com, facebo0k-login.com, and whatsappdownload.site.
> Dubois said lookalike domains like these -- which abuse the Facebook brand -- are often used for phishing, fraud, and scams.
https://www.zdnet.com/article/facebook-sues-namecheap-to-unm...
And double-Wow on that first PDF published by GCHQ. (Pages 8 and 9 are specifically their data on Namecheap as the #1 phishing threat, for anyone else wanting to read it). That's astonishingly bad performance from Namecheap. The data in that PDF is very useful with my own anti-botnet research. I bet the GCHQ data will be persuasive if I do bring this up with politicians considering removing the Safe Harbour provisions for hosts.
I really wish the effort put into curtailing piracy went into curtailing spam and phishing instead. Would be actually beneficial to society.
> so, setting up 2fa on namecheap prevents anyone from just logging into your account if your credentials get leaked or stolen. great, they can't just manage your domains. HOWEVER, the namecheap support portal (at http://support.namecheap.com) uses the same credentials for login BUT it never asks for 2fa. if you get leaked credentials you can just sign in to the support portal. because of how badly designed it is you can even change the support email for the account with no confirmation and no info being sent out to the old email.
> how is that a big deal?
> well, you can just open domain transfer tickets from the support portal and hijack domains anyways, you can probably even pretend to not understand how anything works and ask them to change dns for you, etc...
In my experience, the support people ask for a PIN which you can only see by logging in to the main site with 2FA, so while this problem is not great, I don't think it's as bad as this article suggests.
I've used them for 10+ years without issue. In fact, it's been stellar.
Sure, the interface is a little outdated. But does anyone honestly spend any amount of time there, other than pointing the nameservers to Cloudflare? After that, I rarely ever even log in.
0: https://news.ycombinator.com/item?id=31573854
1: https://community.cloudflare.com/t/domain-not-working-after-...
Does anyone know if cloudflare has provided any justification?
Are we at HN's mercy to publically shame them to get them to fix this if it's happens to us?
from https://en.wikipedia.org/wiki/Namecheap
'In February 2022, Namecheap announced that they would terminate services to Russian accounts due to the Russian invasion of Ukraine, citing "war crimes and human rights violations". Existing users were given a one-week grace period to move their domains. The company also announced that it would be offering free anonymous domain registration and web hosting to all protest and anti-war websites in Russia or Belarus. Namecheap at the same time said it had over 1,000 employees located in Ukraine, comprising most of its support staff, mostly in Kharkiv (which was a major location of fighting).'
2FA is a certainly a useful layer to add, but also not the be-all-and-end-all of account security.
There isn't a list of 1) secure trustworthy companies because of 2FA, and 2) everyone else is untrustworthy and dangerous. Wells Fargo doesn't even require 2FA.
https://en.m.wikipedia.org/wiki/Wells_Fargo_account_fraud_sc...
After the transfer lock peroid, I moved my domains from Namecheap to Dynadot. The prices were pretty much the same, but the interface was better, and Dynadot also passes on "name tasting" to the user (users can request a refund if they change their mind after buying a domain name).
I've also sinced used Dynadot's customer service one time, and it was good.
My only gripe with Dynadot is at the login screen: I set up 2FA, and they call it a "Google code", when you can use any other 2FA manager besides Google.
Out of curiosity, was there any particular reason you switched away from Dreamhost?
DNSSEC signing happens at the nameservers run by the registry (verisign for .com, for example). Unless it was an issue with their API servers not properly calling the upstream APIs, I don't think namecheap is to blame here.
I personally think namecheap is dangerously close to being the next Godaddy, but I wouldn't hold DNSSEC issues against Namecheap any other registrar.
MarkMonitor used to be a thing. Trusted by big companies but even the act of attempting to get information about their services has been met with difficulty. Regardless they have been acquired by an investment firm and there has been some concerns of quality-of-service because of that.
Not affiliated, just a happy customer paying about $500 a year for a bunch of domains at Porkbun.
www.dnsimple.com
Including recently. “Secure your account with WebAuthn & FIDO2 security keys.”
You do need a subscription though: “A DNSimple subscription is required to register, transfer, or renew domain names. Domain registration, transfer, and renewal fees are not included in your subscription.“
That said I’m still currently a namecheap supporter, their backing for an open internet over the years has built my broader confidence in them, but I agree they need to be investing in pinging improvement especially when it comes to security practices.