news.volyx.in

Tell HN: Namecheap gave my account to an unverified third party

498 points by Thrashed · 35 days ago · 177 comments on HN

Article summary

The author, a 13-year Namecheap customer, had their account compromised when a third party convinced Namecheap support to change the account password and email address without verification. The third party was able to do this by calling Namecheap support and claiming ownership of a domain registered to the author. The author was able to regain access to their account and has since moved many of their domains to a different registrar. The incident highlights a potential security vulnerability in Namecheap's support process.

Main themes

  • Domain registrar security
  • Account compromise
  • Customer support issues
  • Private equity ownership
  • Registrar comparison

What commenters say

  • Namecheap's security measures are inadequate, allowing unauthorized access to accounts with minimal social engineering effort.
  • The company's support process is flawed, prioritizing convenience over security and verification.
  • Some commenters have had similar negative experiences with Namecheap, citing poor support and high prices, and have switched to alternative registrars.
  • Others defend Namecheap, citing their long history of satisfactory service, but acknowledge the need for vigilance and potential changes in the company's policies.
  • Domain privacy protection may not be sufficient to prevent account compromise, as it only hides email addresses from public records.
  • Two-factor authentication may not be effective in preventing password resets, which can bypass 2FA measures.
  • Some commenters suggest that private equity ownership may be a factor in Namecheap's declining quality of service and increasing prices.
  • Alternative registrars, such as Porkbun and Cloudflare, are recommended by some commenters as more secure and cost-effective options.