11 ms·
Namecheap announces support for TOTP-based 2FA
- EvanAnderson 8y agoIt's about time. This has been a wish list item for years. They had a proprietary 2FA option but that was a non-starter for me.
- philfrasty 8y agoAny idea why companies would choose a proprietary 2FA solution? I see this with European banks all the time.
- NamecheapCEO 8y agoHonestly, we seriously dropped the ball trying something new. It was a mistake on my part and a bad decision looking back. I posted about it on our blog here https://www.namecheap.com/blog/true-totp-2fa-and-u2f-are-coming/ https://www.namecheap.com/blog/true-totp-2fa-and-u2f-are-com...
- cbluth 8y agoI want to let you know that your previous 2FA was so awful that I had to turn it off. I had Project FI service, and ported my number back to google voice, which permanently locked me out of my namecheap account. I contacted support for help, but by the time they had responded, I had already lost my opportunity on responding to a gig. This is probably the worst place to air a grievance like this, but it seemed like my frustrations had fallen on deaf ears. I haven't bought a domain from namecheap since.
- NamecheapCEO 8y agoThanks for the feedback I appreciate it and I am very sorry to hear about your experience. While I can't go back and change what happened, I want to let you know we recognize the mistakes we've made and I can assure you we are committed to learn from them going forward. I hope one day you'll make it back.
- krrrh 8y agoI was one of the people who wrote long support requests to you guys detailing how much I disliked the system you had in place. I really respect your forthrightness here.
- NamecheapCEO 8y agoThank you, I need to explicitly call out our/my shortcomings if we want to improve as a company going forward. We are making big changes to the way we are doing things and a commitment to full transparency and having open and honest conversations with our customers are the biggest of those.
- Sambeckerst 8y agoThanks Richard for being honest, this is why I choose namecheap
- Fej 8y agoSorry for the thread hijack, but: Let's Encrypt. Ever going to roll it out? I plan to switch away from Namecheap soon unless it's implemented, it's really disappointing to me.
- NamecheapCEO 8y agoHello Fej, to be honest, we signed an exclusive contract with Comodo before Let's Encrypt even existed. The length of that contract is ten years. It's put us in a tough situation as far as what we can offer out of the box to our customers. While our customers can still install LE on our hosting services on their own, we can't actively do this for them. The only other option here is to break that contract which will cost us millions of dollars and it's something that I continue to consider.
- regecks 8y agoReally appreciate the transparency shown in this comment. I recently moved away from Namecheap after 10 years of it being my primary registrar (mainly because of the crappy 2FA) but this is certainly making me reconsider.
- deleted 8y ago[deleted]
- NamecheapCEO 8y agoThank you and I'm sorry to hear that you left us. Please do try and check back with us at some point. I believe you'll see a difference in our approach to how we do things and the decisions we make going forward.
- Flenser 8y agoSo we can expect it in 2024 then?
- chewyland 8y agoSorry for the low quality comment but what a nice thing to say. You guys are hosting my email and I couldn't be happier.
- spiderpug 8y agoI requested this multiple times in surveys you presented me. Thank you for finally implementing it! I feel like my input was actually worth it!
- franga2000 8y agoI don't know about Namecheap, but I'd suspect the banks use proprietary solutions for the standard 2 reasons: 1) Something expensive feels more secure. The 50yo farts in suits are the ones making the decisions, not the devs who actually know why open standards are inherently more secure. 2) They have someone to blame when something goes wrong. If they implement TOTP insecurely and data gets stolen, they're on the hook. If RSA (or whoever else) screws up, the bank can point their finger at them since their programmers are usually the ones who do the integration.
- philtar 8y agoTheir old one was so bad I actually learned how to use route 53 just to migrate out of it. Their CEO is just pretending to be forthright here. I have a tweet where he replied to me from February 2014 that said Google Auth support is coming in a couple of months. This all happened because I got locked out of my namecheap account when THEIR system wouldn't sms me the code and they had problems with the voice calling. So I emailed support. They called me 5 hours later to ask me a bunch of questions. Here's the funny part: they called me on the number I had used for 2FA. Isn't the fact that I answered that number proof enough that I had it? Everything they do is half assed including their Frankenstein panel that's a mix of their old interface and their new one. Anyway. Good riddance. Only use namecheap if you can't afford the $1 it costs to host your dns on route53.
- guitarbill 8y agoAgreed, there was a big issue with the communication about 2FA. And then the proprietary app was rolled out, in what seemed more like a checkbox ticking exercise. At that point I also migrated and haven't looked back. Why a checkbox ticking exercise? Even the Oct 2018 post by the CEO [1] says "[...] our proprietary app, was not well-received by many of you and did not serve you in the way many of you preferred to use 2FA." Apart from being such bullshit corpo speak, how was one single second factor device per person sufficient for critical infrastructure? What was I supposed to do, buy two phones? If a place is so clueless about 2FA, run. You can almost be sure they don't use 2FA internally. (While I'm here, allow me to name and shame Patreon, who used to support TOTP, but removed that option and now only have SMS [2]) [1] https://www.namecheap.com/blog/true-totp-2fa-and-u2f-are-coming/ https://www.namecheap.com/blog/true-totp-2fa-and-u2f-are-com... [2] https://support.patreon.com/hc/en-us/articles/206538086-How-Do-I-Set-Up-Two-Factor-Authentication- https://support.patreon.com/hc/en-us/articles/206538086-How-...
- NamecheapCEO 8y agoNo excuses, you're right, we made a bad decision then and losing customers like you was the consequence of that. I apologize for that and any other negative experiences you may have had with us due to this.
- londons_explore 8y agoTOTP is far too easily phishable. User studies have shown that in any large organisation, some small percentage of even the most technical staff will enter an OTP into a phishing page. You might think 'I'm not that dumb', but study after study shows you are! The future is hardware U2F tokens. They can securely check the web-origin of a request and only give the token to the correct origin.
- manquer 8y agoDepends on your threat model, not everyone is going to pay for a hardware U2F . Not every application needs that high security. TOTP is an option definitely better than just plain password, which is what most services use today
- r1ch 8y agoI hated having to use a proprietary app for this (even if it was based on the Authy SDK), so this is a nice improvement. I'd really like to see U2F support though as well, domains are very valuable assets and deserve the strongest protection possible.