Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
twitter.com
twitter.com
(Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying that because with white-hat(ish) hackers, you'd be shocked how many people try to claim bug bounties from us because they "hacked" their own account using their own credentials.)
Wait ...what? Like, seriously?
For example, they'll inspect traffic and nab a session cookie. Then they'll use that session cookie on another internal API request to change a setting, and claim they were able to modify a setting by reverse engineering things.
They seem really scary at first, and then you dig into it and you're like "oh...".
I think the majority is just ignorance rather than malice though.
> and to clarify, said account must be protected by 2fa to begin with.
I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mechanism.
A bug bounty really ought to be thought out carefully.
And then from all those people you'd still need to find someone who 1) would successfully pull it off and 2) be stupid enough to demonstrate this in a damaging manner.
It’s also worth noting that this offer was made to only one person.
How so? It’s clearly a tweet to a single individual.
Are you saying that based on quality of the service or something else?
I thought your original comment made it sound like there was some obvious reason for keeping DNS and registrars separate.
On the other hand, a registrar transfer is usually simple and quick and has no user visible changes. Unlock the domain, get a transfer code, do any confirmation stuff, make sure the glue records didn't change, you're done.
If you have a high value domain, you might want to look for a corporate registrar, like MarkMonitor or CSC, or anyone else who can do Registry locks (which are very different than registrar locks and are rather inconvenient, but potentially very useful); but know it's going to be expensive. I also had a good corporate experience with register.eu, they've got a lot of ability to satisfy foreign presence needs for restricted TLDs, if that's something you need/want. If it's a low value domain (like my personal domains), I don't have strong feelings, except for the love of whatever you hold dear, don't use Network Solutions; they were a fine choice when they were the only choice, but ever since we had options, they should have been used. A lot of registrars are really pushy with upsells and what not, so I've tried to go with no fuss registrars over the years.
In terms of DNS services, I don't have any particular recommendations; I personally run my primary DNS on my hosted machine and secondary with Hurricane Electric, which is free for my usage. There are (or were) several free secondary DNS services out there, but the one I used to use stopped maintaining their website (TLS 1.0 only, certificate issued 2014, expired 2015) and I already had an account with HE's tunnel broker, so it seemed like a reasonable choice. I still have a domain I host for a friend that uses that old service, because I can't get my friend to update the glue records at her registrar; the service still works enough, I guess.
You do realize that many companies will prosecute people just "following through and testing it", right?
Though the person you did say it to very likely has an international warrant out for them anyway for pissing off the DoD, so I guess it's all water under the bridge.
https://www.techtimes.com/articles/271004/20220125/apple-rew...
https://www.pcgamer.com/security-researchers-aka-hackers-mak...
So the challenge is either giving attackers permission to hack accounts of strangers, or requires the attacker to engage in potentially illegal behaviour. Neither of which is acceptable.
I assume this is just badly phrased, and what was actually intended was a requirement that the victim doesn't collude with or help the attacker.
Otherwise, they prefer you hit test or personal accounts rather than paying customers...
ha. Did anything "good" (or bad) come of this?
> Davis publicly posted his Social Security number as part of a 2007 ad campaign to promote the company's identity theft protection services. However, Davis was a victim of 13 cases of identity theft between 2007 and 2008.
https://en.wikipedia.org/wiki/LifeLock#:~:text=Davis%20publi....
Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing.
This is why legal departments exist, you cannot just say this as a CEO without consulting to your advisors.
> Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing.
Why do you think so? You don’t lose out on any legal protections without explicitly stating that.
Company can't encourage/allow security researchers to access private data of the users, at best this is against GDPR but it can also cause monetary damage to users which can be far worse.
As data controller, namecheap has the following duty "the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject." (GDPR 28.1)
Of course, if that tweet is treated as empty boasting, then there are no consequences - but if you take it at face value, namecheap is granting permission to access data without a proper limiting contract, and it is explicitly illegal for namecheap to do so (GDPR 28.3 - "Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller"); they have a duty to ensure that any subcontractors or licensees or partners or whatever accessing the data do so only in a strictly controlled manner.
This is why every proper external pentest in EU will have explicit GDPR clauses about the limitations of personal data handling if the pentester/auditor has any chance of accessing systems with such data - it's not acceptable for a company to hire external auditors without such restrictions, they can't simply grant access to other peoples' data to third parties.
And before someone says "...but terms&conditions..", no, terms and conditions can't override law, these restrictions apply no matter what namecheap has contracted with the individuals whose data they're storing. There are some clauses of GDPR which state "don't do X without informing the data subject" (in which case the T&C might inform the customer that you'll be doing X) but that's not the case for these requirements.
I’m not sure that’s a credible interpretation, the CEO betting against you being able to work around their data protection measures does not turn you into a processor.
If it does not (which IMHO is a reasonable interpretation), there is no issue and that's just empty boasting. But if it does, that's a violation - GDPR prohibits namecheap to allow anyone outside of company to handle that data without a proper controller-processor contract.
Not being a processor is a bad thing in this case, because being a processor is the only way how this can proceed legally. If you're not a processor, it's a violation for namecheap to give you that data; and if you're not a processor, it's a violation for you to process that data since you're also not a controller, you did not legally obtain this from the data subject, this is also not a purely household activity, no other exceptions seem to apply so the default condition applies i.e. that it's illegal for you to handle that data as you have no legal basis permitting it. (GDPR is a deny-by-default law; processing of private data is lawful if and only if specific conditions listed in GDPR are met. If some private data 'fell out of a truck', you can't legally do stuff with it).
The gain is quite a bit higher than $10k for the right domain. Give me a break.
My strategy for things is to use a unique username and email address (and password..) for critical services, that way any hacks/leaks of other sites don't reveal my entire web presence. It may be that your email was found in another dump, or from a domain whois lookup.
I guess this makes sense. On the other hand such actions might have had legal implications before. I mean until the CEO actively allowed / awarded them.
You will still be in trouble if you deface some random Namecheap customers website to claim this bounty.
They are the Linode of the domain space.
So many deranged folks on Twitter these days.
He doesn't even want to know how you did it.
https://twitter.com/ReneReh1/status/1564349884106477573
There's at least one customer name in there.
This is Namecheaps second blunder this year in terms of being a reliable service provider.
First engaging in politically cheap racial discrimination (their ban on Russia seemingly having hit anyone who ever in their history used a Russian IP adress and demanding evidence of a users current location before lifting it), now giving hackers carte blanche to screw with existing customers.
Extremely unreliable.
What unreliable pieces of shit. How dare they?
Cutting off Russia on it's own already subjects a bunch of probably already very stressed out Ukranians to the stress of dealing with angry Russians, most of whom have nothing to do with the war in Ukraine. These customers mind you, used Namecheap to host content the Russian regime disapproves of; they were pretty much the only reputable registrar offering domains to Russian customers that wasn't ran by the state. Getting rid of those customers pushes those people to Russian state registrars, who will gladly come knocking for contact details if someone hosts something that the Kremlin disapproves of.
Adding to that, the actual methodology used was basically the dumbest method. It seems they targeted everyone who ever had Russian bank details in their account, anyone who ever accessed the site over a Russian IP address and anyone who had a Russian last name. This included hitting several thousands of people who fled the regime over a decade ago, who upon contacting Namecheap support were told to hand over proof of their permanent housing outside of Russia, people who used their account over a VPN, people in neighboring countries because GeoIP isn't an accurate science and people who have Russian roots but haven't even set foot in the country.
The only way to prove this was to send fairly specific details of your housing to Namecheap support (reports at the time even indicated that affected customers had to send photographs of their own house to remain a client), something which can be very sensitive for some people, wrt OPSEC and it's also data they could easily verify with existing KYC data, but they categorically refused to do that.
Like, the methods employed and the complete lack of perspective on what Russians used Namecheaps domains for are what make it racial discrimination, the decision itself is justifiable enough, many companies dropped Russia after the invasion.
I know for a fact that this isn’t true.
>anyone who had a Russian last name.
I seriously doubt this too, but maybe my last name just isn’t Russian enough.
Some Australian companies that used a VPN service that had a Russian exit node got hit with termination notices. There were a couple of reports from people in the UK and the US as well with similar patterns.
> I seriously doubt this too, but maybe my last name just isn’t Russian enough.
Admittedly that is one of the shakier ones, but there was at least one report from France that had a customer who had nothing to do with Russia beyond a very distant family member that caused them to have a Russian last name being hit with a termination notice.
Sorry for not having any references, this all was like... 6 months ago. I found the decision awfully shortsighted and made very ad-hoc rather than properly thought through. (Hell, the termination itself was ludicrously short-notice; people had less than a week to find a new registrar for their domains. Most companies give you at least the time to sit out your renewal period/contract expiration before they tell you to shove it.)
That's why I moved most of my Domains to Porkbun too.
Namecheap cut ties with a country (Russia), not a race.
Namecheap has no ban on Russians outside of Russia using their service, and they very likely employ Russians, since so many Ukrainians have Russian backgrounds.